Former Huntress analyst alleges insider shared law-enforcement information with DevMan ransomware actor

A former Huntress employee publicly alleged that a current company insider passed information from U.S. law enforcement to a ransomware actor known as DevMan, potentially putting customers at risk. The claims center on an alleged December 2025 insider incident rather than Huntress's separate Klue-related exposure; Huntress said the matter involved an employee who showed poor judgment in communicating with a cybercriminal, and said it took the concerns seriously. The article does not provide technical indicators, affected customer count, or independent confirmation from law enforcement.
Why it matters: If true, this would be a serious insider-threat case at a security vendor, with possible exposure of investigative information and downstream risk to customers. Defenders should watch for confirmation, assess any Huntress notifications, and treat this as a potential trust and supply-chain concern rather than a proven breach at this stage.

Sources

Huntress CEO says threat hunter used 'poor judgment' in alerting ransomware crim about law enforcement probe
2026.06.30 95% relevant
This article updates the same underlying event by adding Huntress CEO Kyle Hanslovan's public response, confirming that a current employee disclosed law-enforcement outreach to the DevMan ransomware actor, while disputing that it amounted to insider activity and saying internal policy changes and administrative actions followed.
Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
2026.06.25 100% relevant
This article appears to be the first cited report surfacing the specific allegation of a Huntress insider sharing information with the DevMan ransomware operation, making it the anchor for a new tracked story.
← Back to all stories