Alleged Insider Threat at Huntress: Analyst Accuses Employee of Leaking US Law-Enforcement Communications to DevMan Ransomware Operator
Alleged Insider Threat at Huntress (TL-2026-0945), also tracked as Huntress insider threat allegation, is a high-severity tracked intrusion set, first published 2026-06-25. It is attributed to DevMan with low confidence, affects Huntress Huntress Managed Security Platform (EDR/MDR), maps to 18 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0945
- Threat ID
- TL-2026-0945
- Also known as
- Huntress insider threat allegation, Folland-Hanslovan dispute
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-06-25
- Last reviewed
- 2026-06-25
- Attribution
- DevMan
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, cybersecurity, managed-security-services, government, critical-infrastructure, healthcare, financial
- Target regions
- North America, Europe, Asia, Africa
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Alleged Insider Threat at Huntress
Malware and tooling: DEVMAN, WinLocker
Former Huntress SOC analyst Ben Folland publicly alleged that a current Huntress employee passed US law-enforcement communications to a cybercriminal tied to the DevMan ransomware operation (a modified-DragonForce, Conti-lineage RaaS that emerged April 2025). Huntress CEO Kyle Hanslovan acknowledged a teammate 'exercised poor judgment' communicating with a possible cybercriminal, framing such contact as intelligence-gathering, while FBI coordination and ongoing legal proceedings limit disclosure.
How Alleged Insider Threat at Huntress works
On 25 June 2026 The Register reported a public dispute in which Ben Folland, a former Huntress security operations analyst whose last day was 19 February 2026, alleged that a still-employed Huntress staffer had passed sensitive US law-enforcement communications to a cybercriminal associated with the DevMan ransomware operation. Folland said he first discovered the alleged insider activity in December 2025, that the employee was 'caught by the FBI' yet remained employed, and that he himself was subsequently targeted (including threats referencing his family). Folland further alleged Huntress prioritized an upcoming IPO over client security and used legal threats to silence him. The dispute surfaced publicly in June 2026 as Folland responded to Huntress's disclosure of the Klue Salesforce supply-chain compromise (Huntress was among hundreds of Klue victims; the Klue data theft was claimed by the 'Icarus' extortion group).
Huntress CEO Kyle Hanslovan responded that a teammate 'exercised poor judgment in communicating with a' potential cybercriminal, asserting that security researchers occasionally maintain such contact to gather intelligence, and that ongoing legal proceedings and FBI coordination constrained what the company could say publicly.
This record is an insider-threat / supply-chain-trust intelligence item, not a vulnerability: the source article reports no CVE, malware hashes, or network IOCs specific to the alleged leak itself. The threat significance is the human-trust failure at a widely-deployed security vendor (an EDR/MDR provider with privileged telemetry across customer estates), where an insider with access to law-enforcement-sensitive communications allegedly fed them to a ransomware operator. The counterparty, DevMan, is a well-documented threat: it emerged in mid-April 2025 as an affiliate of Qilin/Agenda and DragonForce, split to operate independently using a modified version of the leaked DragonForce builder (itself derived from leaked Conti source) in July 2025, and launched the 'DevMan 2.0' Ransomware-as-a-Service platform on 30 September 2025. DevMan exhibits Conti-derived Windows Restart Manager abuse, SMB/ADMIN$ lateral movement, three encryption modes (full, header-only, custom), a .DEVMAN extension, a hardcoded mutex, builder flaws (self-encrypting ransom notes; wallpaper change failing on Windows 11), and Russian-language / CIS-Serbian affiliate ties. The DevMan-side malware and infrastructure IOCs in this record are documented from public ANY.RUN and Analyst1 reporting and are included to support hunting and attribution; the insider-leak allegation itself remains unproven and under legal/FBI process.
MITRE ATT&CK techniques used in TL-2026-0945
Collection
T1005 Data from Local System; T1213 Data from Information Repositories
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal
Execution
T1053 Scheduled Task/Job; T1204 User Execution
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship
Discovery
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement; T1657 Financial Theft
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities
Affected products and versions in Alleged Insider Threat at Huntress
- Huntress — Huntress Managed Security Platform (EDR/MDR)
Vulnerable versions: organizational / personnel-trust scope - DragonForce — DragonForce / DevMan ransomware builder (leaked, Conti-derived)
Vulnerable versions: DevMan modified DragonForce variant; DevMan 2.0 RaaS
Remediation for Alleged Insider Threat at Huntress
Immediate actions
- Treat the allegation as unverified pending FBI/legal process; do not act on attribution claims as fact.
- For organizations using Huntress or similar privileged-access security vendors, review what telemetry, communications, and law-enforcement-sensitive data third parties can access.
- Block known DevMan .onion infrastructure and Tox/Session contact identifiers at egress and in DLP/insider-risk monitoring.
- Hunt for DevMan host artifacts: .DEVMAN extension, mutex 'hsfjuukjzloqu28oajh727190', and Restart Manager registry abuse under Session0000.
Workarounds
- Disable or scope down unused/legacy SaaS-integration credentials and OAuth tokens (lesson reinforced by the concurrent Klue/Salesforce breach affecting Huntress).
- Segment networks and restrict SMB/ADMIN$ access to limit DevMan-style lateral movement should ransomware follow an insider compromise.
Longer-term hardening
- Implement insider-threat program controls: least-privilege access to law-enforcement-sensitive and case-coordination communications, separation of duties, and access logging with anomaly alerting.
- Establish and enforce a documented, supervised policy governing analyst contact with suspected criminals for intelligence purposes (approval, logging, legal review).
- Apply UEBA/insider-risk analytics to detect anomalous exfiltration of sensitive communications by privileged staff.
- Vet and continuously monitor security-vendor supply-chain trust (least-privilege OAuth/SaaS integrations, as the parallel Klue compromise illustrates).
Weaknesses (CWE) in Alleged Insider Threat at Huntress
CWE-284, CWE-200, CWE-538, CWE-732, CWE-1265
Timeline of Alleged Insider Threat at Huntress
- DevMan ransomware operation emerges, initially operating as an affiliate of Qilin/Agenda and DragonForce using a modified version of the leaked (Conti-derived) DragonForce builder.
- ANY.RUN publishes forensic analysis of the DevMan DragonForce variant; DevMan transitions to independent operations and stands up its own infrastructure.
- DevMan provides a security researcher pre-launch access to its new Ransomware-as-a-Service platform, five days before public announcement.
- DevMan 2.0 Ransomware-as-a-Service platform launches publicly, recruiting non-CIS affiliates with a $10,000 deposit and proof-of-compromise requirements.
- Ben Folland later states he first discovered the alleged Huntress insider activity (passing law-enforcement communications to a DevMan-linked criminal) in December 2025.
- Ben Folland's last day as a security operations analyst at Huntress.
- Concurrent context: threat actor compromises Klue backend via a legacy active credential, pivoting to steal Salesforce OAuth tokens of Klue customers including Huntress.
- Huntress discloses the Klue Salesforce supply-chain data theft affecting its sales/CRM data; the extortion is later claimed by the 'Icarus' group.
- The Register reports Folland's public allegations and CEO Kyle Hanslovan's response that a teammate 'exercised poor judgment' contacting a possible cybercriminal for intelligence; FBI coordination and legal proceedings limit disclosure.
Sources cited for Alleged Insider Threat at Huntress
- Ex-Huntress analyst claims company insider fed info to a ransomware crim, social media drama ensues
- DEVMAN Ransomware: Analysis of New DragonForce Variant
- Devman's RaaS Launch: The Affiliate Who Aims to Become the Boss
- From Conti to Black Basta to DevMan: The Endless Ransomware Rebrand
- DEVMAN - a new DragonForce ransomware variant (Protection Bulletin)
- Ransomware Spotlight: DragonForce
- Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress
- Security shops among the 'hundreds' of Klue hack victims
Threats related to Alleged Insider Threat at Huntress
Detection coverage for TL-2026-0945
As of 2026-06-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0945 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.