A former data analyst for Brightly Software, Cameron Curry, has been sentenced to 24 months in federal prison for attempting to extort $2.5 million from his employer after learning his contract would not be renewed. Curry, 27, of Charlotte, North Carolina, was convicted on six counts of transmitting interstate communications with intent to extort. In addition to his prison sentence, he will serve one year of supervised release and was ordered to forfeit $7,540.92, which was the amount of Bitcoin Brightly Software had paid him before his arrest.
Curry was employed as a data analyst by Brightly Software, a technology firm acquired by Siemens in 2022. This role provided him with legitimate access to sensitive company information, including corporate records and the personal and payroll data of employees. Evidence presented at his trial indicated that Curry misused this privileged access to steal sensitive corporate records.
After discovering his contract would not be renewed, Curry adopted the online alias "Loot." Between December 2023 and January 2024, he sent over 60 emails to Brightly Software employees and executives, threatening to publish the stolen sensitive information unless he received a cryptocurrency payment of $2.5 million. He further threatened to increase his demand by $100,000 for each month the company refused to pay.
To pressure the company, "Loot" attached screenshots of spreadsheets containing employees' names, home addresses, dates of birth, and salary information. Curry also threatened to report Brightly Software to the U.S. Securities and Exchange Commission (SEC) for failing to disclose a data breach and to expose pay disparities within the workforce.
Investigators were able to trace Curry through a series of digital breadcrumbs. Metadata embedded in the extortion emails and user information linked to the "lootsoftware@outlook.com" email account provided the FBI with sufficient grounds to execute a search warrant at his property on January 24, 2024, where computer equipment was seized.
Further investigation revealed that Curry had requested the ransom payment be made to a Coinbase account, which was linked to debit cards belonging to his mother and sister. A subsequent digital forensic analysis confirmed Curry as the individual behind the "Loot" alias.
The incident highlights the risks posed by disgruntled insiders who possess legitimate access to sensitive company data. Such individuals do not require advanced hacking skills but can leverage their existing privileges, a grievance, and poor judgment to cause significant harm.
This case underscores the importance for organizations to immediately revoke system access for contractors and employees whose tenure is ending. The period of departure, whether due to resignation, redundancy, or a non-renewed contract, is identified as a high-risk time when access to sensitive data should be most closely scrutinized. Insider threats are often underreported by businesses, but they can lead to substantial operational disruption and reputational damage.






