Skip to main content
Emerging ThreatsMalware & Ransomware

Data Analyst Sentenced for Extorting Employer in $2.5 Million Cyber Scheme

A data analyst's workstation with laptop and papers on a plain surface, under scrutiny.

"We will commence the process of disseminating salary information starting January 1, 2024 in phases to all employees and will report you to the SEC after for not reporting the breach," one of the extortion messages read, according to court documents.

Cameron Curry's extortion messages and tactics

Cameron Curry, a 27-year-old North Carolina man who used the handle "Loot," was convicted in March of orchestrating an "extensive cyber extortion scheme" against his employer, Brightly Software. Court filings describe how Curry, working as a six-month data-analyst contractor, accessed the company's payroll information and corporate data and then stole sensitive documents when he learned his contract would not be extended.

One day after his contract ended on December 10, 2023, Curry began emailing dozens of Brightly employees from the alias Loot and the address lootsoftware@outlook.com. Between December 11, 2023 and January 24, 2024 he sent messages threatening to leak the stolen information unless Brightly paid a $2.5 million ransom in cryptocurrency. In his messages Curry attached screenshots of employees' personally identifiable information (PII) — including names, dates of birth, home addresses, and compensation information — and threatened to report Brightly to the U.S. Securities and Exchange Commission (SEC) for failing to disclose the breach.

What was taken: payroll data, PII, and claimed accounting discrepancies

The materials Curry displayed and referenced in his extortion messages centered on payroll and employee data. Beyond the payroll screenshots and PII, one message asserted that "Discrepancies in your books are currently over 16 million USD," and warned of escalating monthly fees should the company refuse the $2.5 million demand: "each subsequent month will incur a $100,000 USD increase."

Brightly is a Software-as-a-Service company (formerly SchoolDude) acquired by Siemens in August 2022. The company employs more than 700 people and provides asset management and maintenance software to over 12,000 clients worldwide — the context in which the exposed payroll and PII would have affected employees and corporate disclosure considerations.

Brightly's actions, the ransom payment, and law enforcement response

After receiving extortion messages, Brightly paid $7,540 in Bitcoin; the funds were transferred to a cryptocurrency wallet controlled by Curry. The company reported the incident to law enforcement. The FBI executed a search of Curry's residence on January 24, 2024 and seized electronic devices that, according to court documents, contained evidence linking him to the scheme.

Brightly told BleepingComputer in March: "We are aware of the U.S. Department of Justice's (DOJ) convictions of Cameron Curry for extortion. We have fully cooperated with the FBI and DOJ in this matter and appreciate their investigative efforts. Given that these proceedings are pending, we defer all questions to law enforcement authorities."

FBI seizure, conviction, and sentence

Following the investigation, Curry was found guilty in March of the extortion scheme. He has since been sentenced to two years in prison. The record presented in court materials ties the extortion emails, the cryptocurrency payment, and the seized devices together as evidence of his operation against Brightly.

What this means for technologists, regulators, and procurement leaders

  • Technologists and security teams: This case underscores risks tied to contractor access to payroll and corporate systems. The theft and public display of employee PII and compensation screenshots illustrate the immediate leverage an insider with valid credentials can exercise.
  • Regulators and corporate disclosure officers: Curry's threats to report the breach to the SEC highlight how attackers can weaponize regulatory reporting obligations in extortion attempts and raise questions about timing and disclosures tied to security incidents.
  • Procurement and HR leaders at service providers: Brightly's profile — a SaaS company with over 700 employees and 12,000 clients — shows how personnel decisions (contract nonrenewal) can intersect with access controls. The episode includes an operational cost (a $7,540 Bitcoin payment) and subsequent investigative and legal costs.

The case closes one chapter: a contractor used access to payroll systems and employee data to demand $2.5 million, received a smaller cryptocurrency payment, and has been convicted and sentenced. It leaves open concrete questions for organizations that grant elevated access to short-term contractors — how that access is revoked, monitored and audited — and how firms balance immediate incident response with preserving evidence for law enforcement. For Brightly, the event sits alongside an earlier, unrelated May 2023 disclosure in which attackers stole credentials and personal data of nearly 3 million customers and users from the SchoolDude platform, a reminder that data incidents can come from multiple vectors and actors.

Original reporting