Cameron Nicholas Curry ultimately extorted the company for $7,540.92 in late January 2024, after a six‑week campaign in which he threatened to publish payroll and personnel records and demanded roughly $2.5 million, prosecutors said.
The theft and timeline
Prosecutors say Curry, a 27‑year‑old North Carolina man who worked as a data‑analyst contractor for Brightly Software, removed corporate data while he was on the company network between August and December 2023. Brightly Software, a Siemens‑owned asset and maintenance management software provider acquired by Siemens in 2022, became the named victim in court filings in the U.S. District Court for the Western District of North Carolina.
Officials say Curry began sending threatening emails immediately following his last day of employment and maintained an extortion campaign lasting roughly six weeks across late 2023 and early 2024. The publicly traded company notified the FBI of the breach on Dec. 14, 2023, and paid a fraction of the ransom demand — $7,540.92 — in late January 2024.
What Curry took and what he threatened
Prosecutors reported that Curry stole a trove of corporate data, including sensitive employee and compensation information. He sent more than 60 emails to Brightly employees and executives, attaching screenshots of spreadsheets that contained personally identifiable information and payroll details, and used those attachments to press his demands.
In those emails, Curry framed his actions as an effort to implement salary transparency, while also warning that he would give employees instructions on addressing alleged pay discrimination via mediation, the Equal Employment Opportunity Commission, or a class‑action lawsuit. Some messages singled out individuals by asserting unequal bonus practices, and he also threatened to report the breach to the Securities and Exchange Commission, citing rules that require public companies to disclose cyberattacks quickly.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildOperational mistakes that led to identification
Authorities say Curry made multiple operational security errors that accelerated identification. He created a Coinbase account to receive ransom payments and linked two debit cards that prosecutors tied to his mother and sister. Those personal, verifiable connections produced leads that investigators used to identify him.
Weeks after the ransom was paid, the FBI searched Curry’s apartment, his digital devices and his vehicle in Charlotte, North Carolina, according to prosecutors. Those investigative steps led to charges and a criminal case that moved through federal court.
Legal case, sentencing and defense claims
Curry was found guilty of six counts of extortion in March and faced a statutory maximum exposure of up to 12 years in prison. The Justice Department said he was sentenced to two years in prison, followed by one year of supervised release.
His lawyers argued the prosecution prolonged the case through errors in affidavits that misstated Brightly’s headquarters as Washington, D.C., rather than the company’s base in Cary, North Carolina. Prosecutors had identified the victim company as a subsidiary of an international parent with U.S. operations, and that apparent location discrepancy resulted in a change of venue. Defense counsel said the error imposed an "unnecessarily lengthy" pretrial restraint of almost 31 months on Curry, including 17 months of full home confinement.
What this means for contractors, employers, and recruitment firms
- Contractors placed into sensitive roles: The case underscores that contractors with network access can obtain payroll and personally identifiable information quickly; operational security missteps by an insider can leave a clear trail back to them.
- Employers that provide laptops and network privileges: Prosecutors and observers in the case point to the risk companies accept when contractors are allowed broad access to sensitive data on company‑owned devices.
- Third‑party recruitment companies: The story highlights how third‑party placements can complicate oversight and the importance of aligning access controls and monitoring with the employer’s data‑protection profile.
The episode closed with a criminal conviction and a prison sentence that was narrower than the statutory maximum, but the prosecution and defense both emphasized collateral consequences: a small ransom payment by the company, more than two years of pretrial restraint for the defendant, and a venue dispute tied to where a corporate parent is located. The record — theft of payroll spreadsheets, a string of threatening emails, Coinbase links to family debit cards, and an FBI search of a Charlotte apartment — leaves a concrete ledger of the risks companies accept when contractors retain expansive access to sensitive corporate data.




