Former Brightly Software Contractor Sentenced for $2.5 Million Cyber Extortion Plot
A former data analyst contractor for **Brightly Software** has been sentenced to two years in prison for orchestrating a sophisticated cyber extortion scheme. **Cameron Curry**, also known as 'Loot,' targeted his former employer with threats to leak sensitive payroll and corporate data unless a $2.5 million ransom was paid in cryptocurrency. The case highlights the insider threat challenge and the serious consequences of digital extortion.
A North Carolina man, **Cameron Curry**, 27, has been sentenced to two years in federal prison for an extensive cyber extortion scheme against his former employer, **Brightly Software**. **Brightly**, a Software-as-a-Service (SaaS) company previously known as **SchoolDude** and acquired by **Siemens** in August 2022, provides asset management and maintenance software to over 12,000 clients globally.
### The Extortion Unfolds
Curry, who worked as a data analyst contractor for **Brightly**, was found guilty in March of orchestrating the scheme. Court documents reveal that after learning his six-month contract would not be extended, Curry accessed and stole sensitive corporate data, including payroll information and personally identifiable information (PII) of employees.
One day after his contract concluded on December 10, Curry began emailing dozens of **Brightly** employees using the alias 'Loot' and the email address `[email protected]`. Between December 11, 2023, and January 24, 2024, he threatened to disseminate the stolen information unless the company paid a $2.5 million ransom in cryptocurrency.
### Threats and Demands
In his extortion messages, Curry explicitly threatened to leak salary information in phases starting January 1, 2024. He also warned of reporting **Brightly** to the U.S. Securities and Exchange Commission (**SEC**) for failing to disclose the breach. The demands were clear, with a monthly increase of $100,000 USD for delays in payment.
"We will commence the process of disseminating salary information starting January 1, 2024 in phases to all employees and will report you to the SEC after for not reporting the breach," one email stated. "If you wish to reclaim your data, we recommend doing so promptly at 2.5 million USD in order to save your company and stocks, as each subsequent month will incur a $100,000 USD increase."
Curry further highlighted alleged financial discrepancies within the company, claiming, "Discrepancies in your books are currently over 16 million USD, posing a potential risk for retention issues, a hostile work environment, resentment, and more."

_Extortion email sample (U.S. Department of Justice)_
To prove his access and solidify his threats, Curry attached screenshots of employees' PII, including names, dates of birth, home addresses, and compensation details.
### Law Enforcement Intervention
Following the barrage of extortion emails, **Brightly** made a payment of $7,540 in Bitcoin to a cryptocurrency wallet controlled by Curry. The company subsequently reported the incident to law enforcement, leading to an FBI investigation.
On January 24, the FBI searched Curry's residence, seizing electronic devices that contained conclusive evidence linking him to the extortion scheme.
**Brightly Software** confirmed its full cooperation with the FBI and the U.S. Department of Justice (**DOJ**), deferring all further questions to law enforcement authorities due to the ongoing nature of the proceedings.
### Prior Data Breach
This incident is separate from another data breach **Brightly** disclosed in May 2023. In that unrelated event, attackers stole credentials and personal data, including names, email addresses, account passwords, and phone numbers, of nearly 3 million customers and users from the database of its **SchoolDude** online platform.