A former data analyst contractor for Brightly Software, Cameron Curry, has been sentenced to two years in prison for an extortion scheme targeting his former employer. Curry, 27, also known by the alias "Loot," was found guilty in March of orchestrating the scheme, which involved stealing sensitive corporate and payroll data and then demanding a $2.5 million cryptocurrency ransom.
Brightly Software, a Software-as-a-Service (SaaS) company formerly known as SchoolDude, was acquired by Siemens in August 2022. The company provides asset management and maintenance software to over 12,000 clients globally and employs more than 700 people.
Curry's contract with Brightly ended on December 10, 2023. The day after, he began emailing dozens of Brightly employees from December 11, 2023, to January 24, 2024, using the "Loot" alias and the email address lootsoftware@outlook.com. In these messages, he threatened to leak the stolen information unless Brightly paid $2.5 million in cryptocurrency.
The extortion emails included threats to disseminate salary information starting January 1, 2024, and to report Brightly to the U.S. Securities and Exchange Commission (SEC) for failing to disclose a breach. Curry claimed that discrepancies in Brightly's books exceeded $16 million. He also stated that the ransom demand would increase by $100,000 each subsequent month.
To substantiate his threats, Curry attached screenshots of employees' personally identifiable information (PII), which included names, dates of birth, home addresses, and compensation details.
Brightly Software confirmed that it paid $7,540 in Bitcoin, transferring the funds to a cryptocurrency wallet controlled by Curry. The company subsequently reported the incident to law enforcement. On January 24, the FBI searched Curry's residence and seized electronic devices containing evidence linking him to the extortion.
In March, Brightly stated that it was aware of the U.S. Department of Justice's convictions of Cameron Curry and had fully cooperated with the FBI and DOJ in their investigation. The company deferred further questions to law enforcement authorities, citing ongoing proceedings.
This incident is separate from another data breach Brightly disclosed in May 2023, where attackers stole credentials and personal data, including names, email addresses, account passwords, and phone numbers, from nearly 3 million customers and users of its SchoolDude online platform.






