general
Huntress, an Ex-Analyst and a Ransomware Crew on LinkedIn
2026-06-25

There is a peculiar argument running on LinkedIn and Reddit this week, involving the security firm Huntress, a former analyst called Ben Folland, and a ransomware operation that goes by DevMan. It began, very 2025 of it, with a Pinocchio GIF and a clown emoji.
Some context. Huntress recently disclosed that it was among the hundreds of customers swept up in the Klue supply-chain compromise, leaning hard on its line about radical transparency. Folland, who left the company in February, replied to that disclosure with the GIF and the emoji, and then went considerably further.
The allegations
In a string of posts, including what he says is a copy of his resignation letter, Folland alleged that a current Huntress employee had been passing information from US law enforcement to DevMan, a crew using modified DragonForce code that he claims has been targeting him and his family.
He says the colleague was caught by the FBI in December, still works at Huntress, and that the company has been quietly sitting on the incident to protect its upcoming IPO. Over the next fortnight he plans to publish supporting material, which he says includes FBI communications, internal memos, and recorded calls.
Huntress tells a different story
CEO Kyle Hanslovan has put a very different version on the record. In a written statement and a Reddit reply, he said a former employee had raised concerns about a teammate using poor judgement during conversations with a cybercriminal, and pointed out that researchers do sometimes need to speak with crooks to gather intelligence.
Hanslovan firmly rejected the insider framing, and the suggestion that the company was prioritising an IPO over customer safety. He also noted that ongoing law enforcement coordination limits what Huntress can say publicly, which is the part everyone watching from the outside will need to sit with for a while.
The bit worth holding on to
It will take time, and probably some of those promised documents, before anyone outside the room can judge who is closer to the truth. The dispute itself, though, is a useful prompt.
The people inside security companies are a high-value target in their own right. They have access to victim data, threat intel feeds, law enforcement contacts, and sometimes direct lines to the criminals they study. That makes them attractive for:
- Recruitment, where a ransomware crew dangles money or kudos at someone already inside the tent.
- Coercion, where the targeting of an analyst and their family is itself the leverage.
- Drift, where the line between researcher and informant blurs after enough late-night chats with the same handle on Telegram.
None of those scenarios are exotic. They are the predictable consequence of a job that involves talking to criminals for a living. The controls that matter, who can speak to whom, what gets logged, who reviews those logs, and how concerns get raised internally, apply just as much inside a SOC as they do at the client sites those SOCs defend.
Whatever shakes out of the Huntress story, that part is already worth taking seriously.