A former data analyst contractor for Brightly Software has been sentenced to two years in prison for orchestrating a $2.5 million extortion scheme targeting his employer. Cameron Curry, also known as “Loot,” was found guilty in March of stealing sensitive documents and using them to blackmail Brightly after learning that his six-month contract wouldn’t be extended.
Brightly is a Software-as-a-Service (SaaS) company that employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide. The extortion scheme was carried out through a series of threatening emails sent by Curry using the “Loot” alias and a fake email address. In these messages, Curry threatened to leak the stolen information unless he was paid a $2.5 million ransom in cryptocurrency.
The emails were particularly chilling, as Curry attached screenshots of employees’ personally identifiable information (PII), including their names, dates of birth, home addresses, and compensation information. He also threatened to report Brightly to the U.S. Securities and Exchange Commission (SEC) for failing to disclose the breach, which could have had serious consequences for the company’s stock price.
Despite these threats, Brightly refused to pay the full ransom, but did transfer $7,540 in Bitcoin to Curry’s cryptocurrency wallet. However, this decision ultimately led to Curry’s downfall, as the FBI was able to track the funds and seize evidence from his residence that linked him to the extortion scheme.
This case highlights the dangers of insider threats, where employees or contractors use their access to sensitive information for personal gain. It also underscores the importance of robust cybersecurity measures, including employee monitoring and incident response plans. While Brightly’s decision not to pay the full ransom may have seemed like a gamble at the time, it ultimately led to Curry’s conviction and imprisonment.
The case is also notable because it occurred just months after Brightly disclosed a separate data breach that affected nearly 3 million customers and users of its SchoolDude online platform. While the two incidents are unrelated, they both demonstrate the importance of robust cybersecurity measures in preventing and responding to data breaches.
For individuals and organizations, this case serves as a reminder of the importance of protecting sensitive information from insider threats. This can be achieved through regular security audits, employee education and training, and the implementation of robust incident response plans. By taking these steps, we can reduce the risk of insider threats and protect our sensitive information from those who would seek to exploit it for personal gain.
Source: Bleeping Computer — 2026-08-14