Published Security3 min read
A contractor, a payroll spreadsheet, and 60 emails: the Brightly insider case
Cameron Curry got two years for stealing HR and compensation data from a Siemens subsidiary and threatening its staff. He was placed there by a third-party recruiter and handed access to the data on a company laptop.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Cameron Nicholas Curry, also known as "Loot," a 27-year-old North Carolina man, committed a series of crimes while working as a data analyst contractor for Brightly Software, a Siemens-owned company, and was sentenced to two years in prison, the Justice Department said Thursday.
- Curry stole a trove of corporate data, including sensitive employee and compensation information, which he used to threaten various employees and executives over a six-week period in late 2023 and early 2024.
- CyberScoop wrote that the insider attack illustrates risks companies accept when employees, or contractors placed in roles by a third-party recruitment company, are allowed to access sensitive data on a company-owned laptop.
- Prosecutors said Curry used his access to the company's network to remove corporate data for extortion while he worked for the company between August and December 2023.
- Curry's employment window of August through December 2023 amounts to roughly five months of access.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A federal court sentenced Cameron Nicholas Curry, a 27-year-old North Carolina man who worked as a data analyst contractor, to two years in prison for stealing corporate data including employee and compensation information from Brightly Software and using it to threaten employees and executives [1][2]. The detail that moves this out of the compliance log and into the board packet is structural: Curry was the kind of contractor placed into a role by a third-party recruitment company and then allowed to reach sensitive data from a company-owned laptop [3].
Curry, who also went by "Loot," worked at the Siemens-owned company between August and December 2023, and prosecutors said he used his network access to remove corporate data for extortion during that period [1][4]. That is roughly five months of access [5]. The threatening emails started immediately after his last day, with a ransom demand in exchange for not leaking and destroying the data [6]. Over a six-week stretch spanning late 2023 and early 2024 he sent more than 60 emails threatening to disclose payroll data he claimed showed significant pay inequity, framing the theft as a push for salary transparency [2][7]. Attachments included screenshots of spreadsheets listing employee personally identifiable information [8]. He also said he would give employees instructions on pursuing pay discrimination through mediation, the Equal Employment Opportunity Commission, or a class-action suit [9], and threatened to report the breach to the Securities and Exchange Commission, citing the rules requiring prompt disclosure of cyberattacks by public companies [10]. Some of the emails were personal, including a claim that a member of the legal team had not received a bonus while most people in high-level positions did [11].
The economics were lopsided. Curry sought about $2.5 million [12] and was paid $7,540.92 in late January 2024, less than 1% of the demand [13][14] and closer to 0.3% [15]. The company notified the FBI on Dec. 14, 2023, roughly a month before that payment [14].
Attribution took very little work. According to CyberScoop, Curry made multiple operational security mistakes, including opening the Coinbase account for the ransom with personal, verifiable data and linking two debit cards belonging to his mother and sister [16]. The FBI searched his Charlotte apartment, digital devices, and vehicle weeks after the ransom was paid [17]. He was found guilty of six counts of extortion in March [18], faced up to 12 years, and received two years plus one year of supervised release [19].
The procedural aftermath is a reminder that a subsidiary incident does not stay tidy. Brightly, an asset and maintenance management software provider Siemens acquired in 2022, was named as the victim in filings in the U.S. District Court for the Western District of North Carolina earlier this month and did not immediately respond to CyberScoop's request for comment [20][21]. Curry's lawyers argued that prosecutors' affidavits falsely placed Brightly's headquarters in Washington, D.C., where Siemens' U.S. corporate headquarters sits, when the company is based in Cary, North Carolina [22][23]. That discrepancy forced a venue change and, the defense argued, produced almost 31 months of pretrial restraint including 17 months of full home confinement [24] - about seven months longer than the custodial sentence itself [25].
Worth watching: whether HR and compensation systems are inside the same egress monitoring scope as source code and customer data, how quickly entitlements for recruiter-placed contractors expire on the last working day, and how often the SEC disclosure clock now shows up as a lever inside the extortion note rather than a consequence after it [10].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cameron Nicholas Curry, also known as "Loot," a 27-year-old North Carolina man, committed a series of crimes while working as a data analyst contractor for Brightly Software, a Siemens-owned company, and was sentenced to two years in prison, the Justice Department said Thursday.
- [2]
Curry stole a trove of corporate data, including sensitive employee and compensation information, which he used to threaten various employees and executives over a six-week period in late 2023 and early 2024.
ReportedView cited source - [3]
CyberScoop wrote that the insider attack illustrates risks companies accept when employees, or contractors placed in roles by a third-party recruitment company, are allowed to access sensitive data on a company-owned laptop.
- [4]
Prosecutors said Curry used his access to the company's network to remove corporate data for extortion while he worked for the company between August and December 2023.
- [6]
Curry started sending threatening emails to Brightly Software employees immediately following his last day of employment, and demanded a ransom to not leak and destroy the data.
ReportedView cited source - [7]
Curry sent more than 60 emails threatening to disclose the company's payroll data, claiming it showed significant pay inequity across the workforce, and framed the data theft extortion attack as an effort to implement salary transparency.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cyberscoop.comMatt KapkoAug 13Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
Additional citations
- U.S. Justice Department via CyberScoop
- CyberScoop
- prosecutors
- officials
- Curry's lawyers



