Huntress Insider Allegations Explained: What Businesses Should Learn From the DevMan Ransomware Controversy

Huntress Insider Allegations Explained: What Businesses Should Learn From the DevMan Ransomware Controversy

Cybersecurity companies are supposed to protect businesses from criminals.

That is why this Huntress story is getting so much attention.

A former Huntress security operations analyst, Ben Folland, has publicly accused the company of mishandling a serious internal issue involving communication between a Huntress employee and a ransomware actor known as DevMan. According to reporting from The Register, Folland claims that another employee shared information connected to U.S. law enforcement communications with DevMan, a ransomware operation that reportedly emerged in 2025 using modified DragonForce code.

Huntress strongly disputes the idea that this was an “insider threat” situation. But the company has acknowledged that one employee used poor judgment by telling a threat actor that law enforcement had reached out about that actor. Huntress CEO Kyle Hanslovan said the disclosure was not illegal, but it was inappropriate.

So what does this actually mean?

Let’s break it down clearly.

What Happened?

The drama started publicly after Huntress disclosed that it was one of many customers affected by the Klue supply-chain incident. Huntress presented that disclosure as part of its commitment to transparency.

Folland, who left Huntress in February 2026, responded on social media with a Pinocchio GIF and clown emoji. His point was not about the Klue incident itself. Instead, he used the moment to raise separate concerns about an earlier internal matter.

Folland claims that in December 2025, he discovered that another Huntress employee had passed information from U.S. law enforcement to DevMan, a ransomware actor. He also claimed Huntress tried to keep the matter quiet and that the employee involved remained at the company.

Those are serious claims. But they are still allegations from a former employee, not proven facts in court.

What Huntress Says

Huntress CEO Kyle Hanslovan has responded publicly.

His position is that security researchers sometimes communicate with threat actors as part of intelligence gathering, research, and investigations. That part is normal in cybersecurity. However, he acknowledged that one exchange crossed a line.

According to Hanslovan, a current Huntress employee disclosed to a threat actor that law enforcement had contacted them about that actor. He described it as poor judgment, but said Huntress has not found evidence of illegal conduct, insider activity, or additional disclosures.

That difference matters.

Folland is framing the issue as a possible insider threat.

Huntress is framing it as a bad decision during threat actor communication, not malicious insider activity.

Why This Story Matters

This is not just social media drama.

It raises a bigger issue for every cybersecurity company, managed service provider, and business that depends on outside security vendors.

Cybersecurity work often involves sensitive information:

  • Law enforcement requests
  • Threat actor communications
  • Customer incident details
  • Internal investigation notes
  • Ransomware intelligence
  • Employee access to private systems

When the people trusted with that information make mistakes, the damage can be bigger than one bad message. It can affect customer trust, law enforcement coordination, and the company’s reputation.

The Bigger Lesson for Businesses

The biggest takeaway is simple:

Trust is not a cybersecurity strategy. Controls are.

Even security companies need strong internal rules around who can communicate with threat actors, what can be shared, who approves it, and how those communications are logged.

A company can have brilliant analysts and still need strict guardrails.

For businesses using cybersecurity vendors, this story is a reminder to ask better questions:

  • Does your vendor have clear policies for threat actor communication?
  • Are sensitive law enforcement communications restricted?
  • Are employee actions logged and reviewed?
  • Is there a formal insider-risk process?
  • What happens when an employee raises a serious concern?
  • How does the company communicate incidents to customers?

These questions are not about paranoia. They are about governance.

Aqyreon Take

This story is messy because both sides may be holding pieces of the truth.

Folland may be raising a legitimate concern about dangerous communication with a ransomware actor. Huntress may also be correct that the full context cannot be shared publicly because of law enforcement, employee privacy, and legal constraints.

But one thing is clear: once a cybersecurity company admits that an employee disclosed law enforcement contact to a threat actor, customers are going to want more than “trust us.”

They will want process.

They will want accountability.

They will want proof that the same thing cannot happen again.

For cybersecurity companies, transparency is not just about publishing breach notices. It is about showing customers that internal mistakes are handled with seriousness, structure, and independent review.

For small businesses, the lesson is even simpler:

Do not only ask whether your security provider can detect ransomware.

Ask how they protect the sensitive information they collect while defending you.

Because in cybersecurity, the protector also has to be protected.

Ezra Vaughn
Written by

Ezra Vaughn

Ezra writes about cybersecurity, digital privacy, and online protection. His work helps readers understand modern threats, stay secure online, and navigate the evolving world of cyber risks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top