Data analyst sent to prison for stealing data, extorting employer

A Data Analyst’s Descent into Extortion: Former Brightly Employee Sentenced to Prison for $2.5 Million Scheme

In a shocking case of betrayal, a former data analyst has been sentenced to two years in prison for orchestrating a massive extortion scheme against his employer, Brightly Software. Cameron Curry, also known as “Loot,” targeted the company’s sensitive information and used it to demand a staggering $2.5 million ransom in cryptocurrency.

Curry worked as a contractor for Brightly, a Software-as-a-Service (SaaS) provider that employs over 700 people and serves more than 12,000 clients worldwide. The 27-year-old North Carolina native was hired on a six-month contract, which ended abruptly on December 10, 2023. However, his tenure at the company was marked by a sinister motive: Curry had been secretly stealing sensitive documents and corporate data.

Once his contract expired, Curry began emailing dozens of Brightly employees using a pseudonym and an Outlook email address. He threatened to leak the stolen information unless he received the hefty ransom in cryptocurrency. In one of the emails, Curry claimed to have obtained sensitive documents, including salary information and personal identifiable data (PII), which he threatened to release publicly unless his demands were met.

Curry’s emails also hinted at reporting Brightly to the U.S. Securities and Exchange Commission (SEC) for allegedly failing to disclose the breach. The extortion scheme was carried out over several weeks, with Curry eventually receiving $7,540 in Bitcoin from the company as a token payment.

The investigation that followed led to a major breakthrough when FBI agents searched Curry’s residence on January 24, 2024, seizing electronic devices containing evidence of the extortion scheme. Brightly has since cooperated fully with law enforcement authorities and has expressed appreciation for their efforts.

This case highlights the dangers of insider threats and the importance of robust security measures within organizations. It also underscores the risks associated with cryptocurrency transactions, which can be difficult to track and recover. As cybersecurity professionals and enthusiasts, it’s essential to stay vigilant and recognize that even trusted employees can pose a threat when motivated by personal gain.

For individuals and businesses alike, this case serves as a stark reminder of the importance of maintaining robust security protocols and monitoring employee activity closely. In an era where data breaches are increasingly common, it’s crucial to prioritize cybersecurity awareness and education within organizations. By doing so, we can prevent similar cases of insider threats and protect sensitive information from falling into the wrong hands.


Source: Bleeping Computer — 2026-08-14