Former Analyst Sentenced for Extorting Brightly Software
Data Breaches

Illustrative image generated with AI

Former Analyst Sentenced for Extorting Brightly Software

Cameron Curry sentenced to 2 years for extorting Brightly Software via insider data theft. Threats to disclose employee information led to FBI investigation.

Text generated by artificial intelligence, published without human review. AI transparency

Two-Year Prison Sentence for Extortion Campaign

Cameron Curry, 27, a North Carolina resident known online as “Loot,” has been sentenced to two years in prison for extorting Brightly Software, a SaaS company acquired by Siemens.

The sentence was reported on August 14, 2026. Curry was found guilty in March following an investigation by the FBI and the Department of Justice.

The case involved an insider attack carried out by a former contractor with legitimate access to corporate information. Curry worked for Brightly as a contract data analyst. His six-month engagement was not renewed.

After the contract ended on December 10, he allegedly began using data obtained during his employment to pressure the company.

Emails Signed “Loot” and the $2.5 Million Demand

Between December 11, 2023, and January 24, 2024, Curry allegedly sent numerous emails to Brightly employees. He used the alias “Loot” and the email address [email protected].

The messages demanded a $2.5 million ransom in cryptocurrency. In exchange, the perpetrator threatened not to publish documents stolen from the company and employees’ personal information.

The threats involved a staged disclosure. Curry claimed he would begin publishing salary data on January 1, 2024, and would gradually increase the amount of information released over time.

The extortion demand also included a penalty: the amount would increase by $100,000 for every month the payment was delayed. Curry also claimed to have identified accounting discrepancies exceeding $16 million and threatened to report Brightly to the U.S. Securities and Exchange Commission for allegedly failing to disclose the breach.

The emails included screenshots containing personally identifiable information. The data reportedly included names, dates of birth, home addresses, and compensation details.

Brightly eventually transferred $7,540 in Bitcoin to a wallet controlled by Curry. Although the payment was far below the initial demand, it still represented a transfer of funds to the extortionist.

It remains unknown whether the data was actually published or how many documents were stolen or accessed.

The Risk to Employees and the Company

The incident combines three distinct elements: abuse of legitimate access, theft of sensitive documents, and extortion based on the threat of disclosure.

For employees, the potential exposure involved personal, residential, and employment-related information. Compensation data can also facilitate targeted fraud, phishing campaigns, and impersonation attempts against staff.

For Brightly, the potential impact extended beyond privacy concerns. The threats could have led to reputational damage, litigation, and regulatory scrutiny. The alleged accounting discrepancies exceeding $16 million added further pressure, although the criminal case concerned extortion and data theft.

The incident also illustrates a common characteristic of insider threats: an attacker does not necessarily need to bypass authentication controls or exploit a software vulnerability. They may use permissions granted for legitimate work, collect information during their engagement, and retain it after the relationship ends.

Risk increases when access to payroll data is not restricted to essential business functions, or when account deprovisioning and monitoring of local copies are not performed promptly.

The Search and the Role of Law Enforcement

Following the complaint, the FBI searched Curry’s home on January 24 and seized several electronic devices. The devices contained evidence linking him to the extortion campaign.

The forensic seizure provided investigators with digital evidence that helped reconstruct the communications, the use of the “Loot” identity, and Curry’s possession of company documents.

Brightly said it had fully cooperated with the FBI and the Department of Justice. Publicly available information identifies the documented measures as filing the complaint, cooperating with investigators, and conducting forensic acquisitions of the devices.

Additional technical measures taken by the company in this specific case are not known. No public details have been provided regarding credential revocation, secret rotation, access segmentation, log retention, or dedicated monitoring of accounts used by the former contractor.

For organizations, responding to a similar incident should include at least preserving evidence, analyzing access activity, determining which data was copied, and assessing notification obligations. However, beyond its cooperation with authorities, these activities have not been publicly attributed to Brightly.

A Separate Incident from the SchoolDude Breach

Brightly Software provides asset management and maintenance tools to more than 12,000 customers worldwide and has over 700 employees. The company was formerly known as SchoolDude and was acquired by Siemens in August 2022.

The Curry case is unrelated to the breach Brightly disclosed in May 2023. In that incident, unidentified attackers stole credentials and personal data from the SchoolDude online platform database.

The affected information included names, email addresses, account passwords, and telephone numbers. The incident impacted nearly 3 million customers and users.

The two events were fundamentally different. The SchoolDude breach involved an attack by unidentified actors against an online database. The Curry investigation concerns an identified former contractor, the use of access obtained during employment, and a subsequent extortion demand.

For organizations handling sensitive data, the earlier incident reinforces a practical conclusion: protecting the external perimeter is not enough. Organizations must also control who can view, export, and retain internal information, particularly in systems that process payroll and personal data.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsextortioninsider threatdata theftCameron CurryBrightly SoftwareFBI investigationSaaS securityemployee privacy
Back to home