LIVE · cybersecurity feed
Live wire
security

Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack

Cameron Curry stole corporate data and employee information, which he used to threaten the company as his six-month contract gig came to a close. He ultimately extorted the company for $7,540.92. The post Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack appeared first on CyberScoop.

zeroday.news ·

A former contractor for Brightly Software, Cameron Nicholas Curry, has been sentenced to two years in prison for an insider attack that involved data theft and extortion. Curry, also known as "Loot," was found guilty of six counts of extortion in March and received his sentence in August. Following his prison term, he will serve one year of supervised release.

Curry, a 27-year-old North Carolina resident, worked as a data analyst contractor for Brightly Software, an asset and maintenance management software provider owned by Siemens. His contract spanned from August to December 2023. During this period, he accessed the company's network and exfiltrated a significant amount of corporate data, including sensitive employee and compensation information.

Immediately after his last day of employment, Curry began sending threatening emails to Brightly Software employees and executives. Over a six-week period in late 2023 and early 2024, he sent more than 60 emails, demanding a ransom to prevent the leak and destruction of the stolen data. His initial demand was approximately $2.5 million.

In his communications, Curry threatened to disclose the company's payroll data, claiming it revealed significant pay inequity among the workforce. He attached screenshots of spreadsheets containing personally identifiable information of employees to some emails. He also warned he would provide instructions to employees on how to pursue pay discrimination claims through mediation, the Equal Employment Opportunity Commission, or a class-action lawsuit. Some threats were highly specific, such as a claim about a legal team member not receiving a bonus while many high-level employees did. Curry further threatened to report the data breach to the Securities and Exchange Commission, citing disclosure requirements for public companies.

Brightly Software, which is publicly traded, notified the FBI of the breach on December 14, 2023. In late January 2024, the company paid a sum of $7,540.92, which was less than one percent of Curry's initial ransom demand.

Authorities were able to identify and build a case against Curry relatively quickly due to several operational security errors he made. He used a Coinbase account for the ransom, which was established with personal and verifiable data, and linked two debit cards belonging to his mother and sister to the account. Weeks after the ransom payment, the FBI searched Curry's apartment, digital devices, and vehicle in Charlotte, North Carolina.

Curry's legal team argued that the case was prolonged due to prosecutorial errors, including affidavits that incorrectly stated Brightly Software's headquarters were in Washington, D.C. While Siemens' U.S. corporate headquarters are in Washington, Brightly Software is based in Cary, North Carolina. This discrepancy led to a change in trial venue and, according to Curry's lawyers, resulted in an unnecessarily lengthy pretrial restraint of nearly 31 months, including 17 months of full home confinement.

Brightly Software was identified as the victim in court records filed in the U.S. District Court for the Western District of North Carolina. The company has not publicly commented on the incident.

ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.