Cameron Curry, a former data analyst contractor from Charlotte, North Carolina, was sentenced to 24 months in federal prison for a cyber extortion campaign against a Washington, D.C.-based international technology company identified in reporting as Brightly Software. Prosecutors said Curry abused legitimate insider access to steal sensitive corporate records and employee information after learning his contract would not be renewed, then used the alias "Loot" to send more than 60 extortion emails between December 2023 and January 2024 demanding $2.5 million in cryptocurrency.
The messages threatened to leak company and employee data, report the company to the SEC for failing to disclose a breach, and expose alleged pay disparities if payment was not made. A federal jury convicted Curry in March 2026 on six interstate extortion-related communications counts, and investigators tied him to the scheme through email metadata, account records, an Outlook address, and a Coinbase account linked to debit cards belonging to his mother and sister; an FBI search of his residence on January 24, 2024, led to the seizure of computer equipment and forensic evidence confirming he operated the "Loot" persona.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In March 2026, a federal jury convicted Cameron Curry on six counts of transmitting or causing interstate communications with intent to extort the victim company. The conviction followed evidence that he abused his insider access to obtain sensitive records and threaten their disclosure.
On January 24, 2024, the FBI executed a search warrant at Cameron Curry's residence and seized electronic devices and computer equipment. Subsequent forensic analysis tied Curry to the "Loot" alias used in the extortion scheme.
After learning his contract would not be renewed, Cameron Curry used the alias "Loot" to send more than 60 extortion emails to employees and executives of the victim technology company, demanding $2.5 million in cryptocurrency and threatening to leak sensitive corporate and employee data. The campaign ran from December 11, 2023, to January 24, 2024.
Cameron Curry was sentenced to 24 months in prison for the cyber extortion scheme, along with one year of supervised release and a $7,540.92 money judgment. Prosecutors said he targeted a Washington, D.C.-based international technology company where he had worked as a contractor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourcebitdefender.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.