Data Analyst Sent to Prison for Data Theft and Extortion
A former data analyst contractor for Brightly Software received a two-year prison sentence for orchestrating a $2.5 million extortion scheme against their employer.
The Case Overview
Brightly, a Software-as-a-Service (SaaS) provider that rebranded from SchoolDude and was acquired by Siemens in August 2022, operates with over 700 employees and serves more than 12,000 clients globally.
The Defendant’s Actions
The defendant, 27-year-old Cameron Curry of North Carolina, also known as “Loot,” was convicted in March for targeting the company after his six-month contract was not renewed. Curry accessed payroll records and corporate data, leveraging the information to demand a ransom.
The Extortion Emails
Following the termination of his contract on December 10, he sent emails to multiple employees between December 11, 2023, and January 24, 2024, using the alias “Loot” and the email address lootsoftware@outlook.com. The messages threatened to release sensitive employee data, including personally identifiable information (PII) such as names, birth dates, addresses, and compensation details, unless a $2.5 million cryptocurrency payment was made.
The Payment and Investigation
Brightly paid $7,540 in Bitcoin to a wallet controlled by Curry, according to court records. After the company reported the incident, the FBI conducted a search of Curry’s residence on January 24, seizing electronic devices that provided evidence linking him to the scheme.
The Company’s Response
A spokesperson for Brightly stated in March that the company had fully cooperated with law enforcement and deferred further comments to authorities. The case follows a separate data breach disclosed by Brightly in May 2023, in which attackers stole credentials and personal data from nearly 3 million users of its SchoolDude platform.
The U.S. Department of Justice highlighted the extortion emails as part of the evidence presented during the trial. Curry’s actions align with broader trends of insider threats and cyber extortion, underscoring the risks associated with unauthorized access to sensitive corporate systems. The sentencing reflects the legal consequences for leveraging stolen data to demand ransom, particularly when involving financial and regulatory implications.
Conclusion
The case highlights the severe legal and operational risks of insider threats and cyber extortion, emphasizing the importance of robust data security measures and swift law enforcement responses.
