Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack

A tech contractor’s insider attack on Brightly Software has resulted in a two-year prison sentence, highlighting the risks companies face when entrusting sensitive data to third-party contractors. Cameron Nicholas Curry, also known as “Loot,” exploited his access to the company’s network to steal corporate data and extort $7,540.92 from Brightly Software.

Curry, who worked as a data analyst contractor for the Siemens-owned company between August and December 2023, used his access to remove sensitive employee and compensation information. He then sent threatening emails to various employees and executives over a six-week period, claiming he would disclose the data unless he received payment. Curry’s demands were masked as an effort to implement salary transparency, but in reality, it was an attempt at extortion.

The scheme involved sending more than 60 emails with attachments containing screenshots of spreadsheets listing personally identifiable information of company employees. Curry even went so far as to claim that one employee on the legal team wasn’t receiving a bonus while most high-level positions did receive bonuses. He also threatened to report the breach to the Securities and Exchange Commission, citing rules requiring public companies to disclose cyberattacks quickly.

Brightly Software, an asset and maintenance management software provider acquired by Siemens in 2022, was eventually forced to pay Curry $7,540.92 in January 2024 after receiving a number of threatening emails. The company notified the FBI on December 14, 2023, but it wasn’t until weeks later that authorities identified and built a case against Curry.

The swift resolution of the case can be attributed to multiple operational security mistakes made by Curry. He used personal data to establish a Coinbase account for the ransom payment, linking two debit cards belonging to his mother and sister to the account. The FBI was able to search his apartment, digital devices, and vehicle in Charlotte, North Carolina, weeks after the ransom was paid.

Curry’s sentence of two years followed by one year of supervised release is a fraction of the 12-year maximum he could have faced. His lawyers argued that the case against him was prolonged due to prosecutors’ errors, including affidavits that falsely stated Brightly Software was headquartered in Washington, D.C. The location discrepancy resulted in a change in venue for the trial and imposed an unnecessarily lengthy pretrial restraint on Curry.

This case highlights the risks companies face when entrusting sensitive data to third-party contractors or allowing them access to company-owned laptops. It’s crucial for organizations to implement robust security measures and monitor employee activity closely, particularly for those with contractor status. By doing so, they can mitigate the risk of insider attacks like this one and protect their employees’ sensitive information.


Source: CyberScoop — 2026-08-13