Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack

A Tech Contractor’s Elaborate Scheme Unravels: Insider Attack Exposes Dangers of Data Access and Extortion

In a brazen insider attack, Cameron Nicholas Curry, a 27-year-old data analyst contractor for Brightly Software, was sentenced to two years in prison after stealing sensitive corporate data and extorting the company for $7,540.92. The case highlights the risks companies face when employees or contractors have access to sensitive information on company-owned laptops.

Curry, also known as “Loot,” worked for Brightly Software between August and December 2023. During this time, he used his access to the company’s network to steal corporate data, including sensitive employee and compensation information. In a six-week period from late 2023 to early 2024, Curry sent threatening emails to various employees and executives, claiming that the stolen data would be leaked unless the company paid him a ransom.

The emails were carefully crafted to frame the data theft as an effort to implement salary transparency. Curry attached screenshots of spreadsheets listing personally identifiable information of company employees, along with warnings about potential consequences, including reporting the breach to regulatory agencies and triggering class-action lawsuits. The messages got personal at times, targeting specific individuals, such as a member of the legal team who was allegedly denied a bonus.

Brightly Software, an asset and maintenance management software provider acquired by Siemens in 2022, fell victim to Curry’s scheme despite having robust security measures in place. The company notified the FBI on December 14, 2023, and paid less than 1% of Curry’s ransom demand almost a month later.

What’s striking about this case is that authorities were able to quickly identify and build a case against Curry due to his operational security mistakes. He used personal and verifiable data to establish a Coinbase account for the ransom, linking debit cards belonging to his mother and sister to the account. The FBI searched Curry’s apartment, digital devices, and vehicle in Charlotte, North Carolina, weeks after the ransom was paid.

The case has significant implications for companies that rely on contractors or third-party recruitment agencies to access sensitive data. It highlights the importance of robust security measures, including multi-factor authentication, regular monitoring of network activity, and strict access controls to prevent insider attacks.

In practical terms, this case serves as a reminder to organizations to regularly review and update their access control policies, ensure that all employees and contractors undergo thorough background checks, and maintain robust incident response plans in place. By doing so, companies can mitigate the risks associated with insider threats and protect sensitive data from falling into the wrong hands.


Source: CyberScoop — 2026-08-13