There is a lack of proof that the developer is linked to a sanctioned entity. Not saying it isn't, but The Verge should be at least trying to verify that IMHO (instead of taking the statement at face value); I'd even trust a "we verified it but won't publish to protect the developer".