LIVE · cybersecurity feed
Live wire
patch

Prison for data analyst who tried to extort $2.5 million from his employer

When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion. Read more in my article on the Hot for Security blog.

zeroday.news ·

A former data analyst for Brightly Software, Cameron Curry, has been sentenced to 24 months in federal prison for attempting to extort $2.5 million from his employer after learning his contract would not be renewed. Curry, 27, of Charlotte, North Carolina, was convicted on six counts of transmitting interstate communications with intent to extort. In addition to his prison sentence, he will serve one year of supervised release and was ordered to forfeit $7,540.92, which was the amount of Bitcoin Brightly Software had paid him before his arrest.

Curry was employed as a data analyst by Brightly Software, a technology firm acquired by Siemens in 2022. This role provided him with legitimate access to sensitive company information, including corporate records and the personal and payroll data of employees. Evidence presented at his trial indicated that Curry misused this privileged access to steal sensitive corporate records.

After discovering his contract would not be renewed, Curry adopted the online alias "Loot." Between December 2023 and January 2024, he sent over 60 emails to Brightly Software employees and executives, threatening to publish the stolen sensitive information unless he received a cryptocurrency payment of $2.5 million. He further threatened to increase his demand by $100,000 for each month the company refused to pay.

To pressure the company, "Loot" attached screenshots of spreadsheets containing employees' names, home addresses, dates of birth, and salary information. Curry also threatened to report Brightly Software to the U.S. Securities and Exchange Commission (SEC) for failing to disclose a data breach and to expose pay disparities within the workforce.

Investigators were able to trace Curry through a series of digital breadcrumbs. Metadata embedded in the extortion emails and user information linked to the "lootsoftware@outlook.com" email account provided the FBI with sufficient grounds to execute a search warrant at his property on January 24, 2024, where computer equipment was seized.

Further investigation revealed that Curry had requested the ransom payment be made to a Coinbase account, which was linked to debit cards belonging to his mother and sister. A subsequent digital forensic analysis confirmed Curry as the individual behind the "Loot" alias.

The incident highlights the risks posed by disgruntled insiders who possess legitimate access to sensitive company data. Such individuals do not require advanced hacking skills but can leverage their existing privileges, a grievance, and poor judgment to cause significant harm.

This case underscores the importance for organizations to immediately revoke system access for contractors and employees whose tenure is ending. The period of departure, whether due to resignation, redundancy, or a non-renewed contract, is identified as a high-risk time when access to sensitive data should be most closely scrutinized. Insider threats are often underreported by businesses, but they can lead to substantial operational disruption and reputational damage.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI puts major frontier AI training run on hold over cyber risks

OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. “Our largest planned frontier RL run remains on hold while we conduct smaller-scale training and evaluations to assess model behavior, validate our safeguards, and establish more evidence of alignme

security

UK Fraud Cases Hit Record High in 2026

Cifas data finds account takeover and identity fraud are driving a surge in fraud cases

breach

50,000 Stripe Secrets Leaked in Public Code

Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research […]

security

Cyberattack forces UT San Antonio to delay start of fall semester

The University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. UT San Antonio is one of the largest universities in Texas, serving more than 42,000 students. According to a statement issued by Andrea Marks,

CVE-2026-33824

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchan

breach

CareCloud Data Breach Impact Grows to 3.7 Million Individuals

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact. The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on SecurityWeek.