Skip to content
Bleeping Computer

Data analyst sent to prison for stealing data, extorting employer


A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme.

Brightly is a Software-as-a-Service (SaaS) company formerly known as SchoolDude, which was acquired by Siemens in August 2022. Brightly employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide.

27-year-old North Carolina man Cameron Curry (also known as “Loot”) was found guilty in March of orchestrating an “extensive cyber extortion scheme” targeting his employer.

image

According to court documents, Curry stole sensitive documents after gaining access to the company’s payroll information and corporate data, which he later used to extort Brightly after learning that his six-month contract wouldn’t be extended.

One day after his contract ended on December 10, he emailed dozens of Brightly employees using the Loot alias and the lootsoftware@outlook.com email address between December 11, 2023, and January 24, 2024, threatening to leak the stolen information unless he was paid a $2.5 million ransom in cryptocurrency.

“We will commence the process of disseminating salary information starting January 1, 2024 in phases to all employees and will report you to the SEC after for not reporting the breach,” Curry said in one of the extortion messages.

“If you wish to reclaim your data, we recommend doing so promptly at 2.5 million USD in order to save your company and stocks, as each subsequent month will incur a $100,000 USD increase. Discrepancies in your books are currently over 16 million USD, posing a potential risk for retention issues, a hostile work environment, resentment, and more.”

Extortion email sample
Extortion email sample (U.S. Department of Justice)

​He also attached screenshots of employees’ personally identifiable information (PII), including their names, dates of birth, home addresses, and compensation information, and threatened to report Brightly to the U.S. Securities and Exchange Commission (SEC) for failing to disclose the breach.

​Following Curry’s many extortion emails, Brightly paid $7,540 in Bitcoin, transferring the funds to a cryptocurrency wallet controlled by Curry.

After the company reported the incident to law enforcement, the FBI searched Curry’s residence on January 24 and seized various electronic devices containing evidence that linked him to the extortion scheme.

“We are aware of the U.S. Department of Justice’s (DOJ) convictions of Cameron Curry for extortion,” Brightly told BleepingComputer in March.

“We have fully cooperated with the FBI and DOJ in this matter and appreciate their investigative efforts. Given that these proceedings are pending, we defer all questions to law enforcement authorities.”

In May 2023, Brightly also disclosed a data breach (unrelated to this case) after attackers stole credentials and personal data (including names, email addresses, account passwords, phone numbers) of nearly 3 million customers and users from the database of its SchoolDude online platform.

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report



Source link