Former Brightly Software contractor Cameron Nicholas Curry was sentenced to two years in prison and one year of supervised release for an insider cyber extortion scheme against the Siemens-owned company. Prosecutors said Curry abused his legitimate access as a data analyst between August and December 2023 after learning his contract would not be renewed, stealing sensitive corporate, payroll, compensation, and employee personally identifiable information and using the alias "Loot" to threaten staff and executives.
Investigators said Curry sent more than 60 extortion emails demanding about $2.5 million in cryptocurrency and warning that stolen data would be exposed if Brightly did not pay. The company ultimately transferred about $7,540 in Bitcoin before reporting the incident to the FBI in December 2023. Authorities later searched Curry's residence, seized electronic devices, and tied him to the campaign through operational security failures, including a Coinbase account allegedly funded with debit cards belonging to his mother and sister. He was convicted on six extortion counts in March.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Curry was found guilty in March on six counts of extortion for the scheme targeting Brightly Software. The conviction followed the federal investigation into his insider attack and ransom campaign.
On January 24, the FBI searched Curry's residence and seized electronic devices. Investigators found evidence on the devices linking him to the extortion scheme.
Brightly ultimately paid $7,540.92 in Bitcoin, less than 1% of Curry's original ransom demand. Prosecutors said the payment was made in late January 2024 and sent to a wallet Curry controlled.
Brightly Software notified the FBI about the insider extortion breach after receiving Curry's threats. This report triggered the federal investigation that quickly identified him through operational security mistakes.
Using the alias "Loot," Curry began emailing Brightly employees and executives with threats to leak stolen data unless the company paid $2.5 million in cryptocurrency. One source says he emailed dozens of employees between December 11, 2023, and January 24, 2024.
Prosecutors said Cameron Curry used his legitimate network access as a Brightly contractor between August and December 2023 to remove sensitive corporate, employee, and compensation data. The theft began after he learned his six-month contract would not be extended.
An unrelated Brightly/SchoolDude breach was disclosed in May 2023, exposing credentials and personal data from the SchoolDude platform database. The reporting notes this incident was separate from Cameron Curry's extortion case.
Siemens acquired Brightly Software, the SaaS company formerly known as SchoolDude. This corporate ownership context is cited in reporting on the later insider extortion case.
The U.S. Department of Justice announced that Cameron Curry was sentenced to two years in prison for the insider extortion attack against Brightly Software. He also received one year of supervised release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcecyberscoop.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.