Published Security3 min read
A contractor's six-month deal lapsed. The next day, a $2.5 million demand arrived
Cameron Curry got two years for extorting Brightly Software with stolen payroll data. The demand started one day after his contract ended, which is where the control gap sits.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- A former data analyst contractor for Brightly Software was sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme.
- Brightly is a SaaS company formerly known as SchoolDude, acquired by Siemens in August 2022; it employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide.
- Cameron Curry is a 27-year-old North Carolina man who also used the alias "Loot".
- Curry was found guilty in March of orchestrating an extensive cyber extortion scheme targeting his employer.
- According to court documents, Curry stole sensitive documents after gaining access to the company's payroll information and corporate data, which he later used to extort Brightly after learning that his six-month contract wouldn't be extended.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A former data analyst contractor at Brightly Software has been sentenced to two years in prison for a $2.5 million extortion scheme against the company that had just declined to extend him [1]. The timeline is the part worth copying into your own runbook: the six-month contract ended on December 10, and the first extortion email went out one day later [5][6].
Cameron Curry, 27, of North Carolina, operating as "Loot," was found guilty in March [3][4]. According to court documents cited by BleepingComputer, he stole sensitive documents after gaining access to Brightly's payroll information and corporate data, then used them to extort the company after learning his contract would not be extended [5]. Between December 11, 2023 and January 24, 2024 he emailed dozens of Brightly employees from [email protected] demanding $2.5 million in cryptocurrency [6]. That is a 45-day campaign against the company's own staff [15].
The messages were built to create internal pressure rather than technical fear. One threatened to begin "disseminating salary information starting January 1, 2024 in phases to all employees" and to report the company to the SEC for not disclosing the breach [7]. Another set the price at $2.5 million with a $100,000 monthly escalation, roughly four percent a month [8][16], and asserted that "discrepancies in your books are currently over 16 million USD" [8]. He attached screenshots of employee personally identifiable information including names, dates of birth, home addresses and compensation [9], and threatened the SEC referral over the undisclosed breach [10].
Brightly paid $7,540 in Bitcoin to a wallet Curry controlled [11], about three tenths of one percent of the demand [17] and under eight percent of a single month's escalation [18]. The company then reported the incident to law enforcement, and the FBI searched Curry's residence on January 24 and seized devices linking him to the scheme [12]. Brightly told BleepingComputer in March that it had fully cooperated with the FBI and DOJ and was deferring questions to law enforcement [13].
Read as an access-control story, this case is unremarkable. Brightly employs over 700 people and serves more than 12,000 clients [2]; a data analyst who can reach payroll and corporate records is doing the job as scoped. Nothing in the reported record establishes when the copying happened relative to the non-renewal decision, and nothing suggests the extortion required continued access: the emails came from a consumer Outlook account, and the data was already out [6][5]. That is the uncomfortable part. A privileged-access review answers who can reach payroll today. It does not answer who reached payroll last month and has just been told there is no month seven.
The window that matters opens when the renewal decision is made and closes when the engagement ends, and in most organisations that window is managed by a procurement calendar rather than by security. A non-renewal is not a termination, so it usually generates no incident, no interview, no review of what the departing account has recently exported. The contract simply runs down while the person knows it is running down.
Watch whether renewal and non-renewal decisions get routed to security as triggering events, with data-egress review over the notice period rather than a badge-off checklist on the last day. Watch also how the SEC-referral threat performs as extortion leverage now that it has been tried: Brightly had separately disclosed a breach in May 2023 involving nearly 3 million SchoolDude customers and users [14], so the threat was aimed at a company with a public disclosure history.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A former data analyst contractor for Brightly Software was sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme.
- [2]
Brightly is a SaaS company formerly known as SchoolDude, acquired by Siemens in August 2022; it employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide.
- [3]
Cameron Curry is a 27-year-old North Carolina man who also used the alias "Loot".
- [4]
Curry was found guilty in March of orchestrating an extensive cyber extortion scheme targeting his employer.
- [5]
According to court documents, Curry stole sensitive documents after gaining access to the company's payroll information and corporate data, which he later used to extort Brightly after learning that his six-month contract wouldn't be extended.
- [6]
One day after his contract ended on December 10, Curry emailed dozens of Brightly employees using the Loot alias and the [email protected] address between December 11, 2023 and January 24, 2024, threatening to leak the stolen information unless paid a $2.5 million cryptocurrency ransom.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comSergiu GatlanAug 14Data analyst sent to prison for stealing data, extorting employer
Additional citations
- BleepingComputer
- court documents, via BleepingComputer
- extortion message quoted by BleepingComputer
- Brightly Software statement to BleepingComputer



