Overview of the Extortion Case
A former contractor for Brightly Software has been sentenced to two years in federal prison following a targeted extortion scheme against the company. According to a report by BleepingComputer, 27-year-old North Carolina resident Cameron Curry, who operated under the alias “Loot,” orchestrated a campaign demanding $2.5 million in cryptocurrency. The incident underscores the severe risks posed by disgruntled former contractors and inadequate internal access controls within SaaS and enterprise environments.
Brightly Software, formerly known as SchoolDude and acquired by Siemens in August 2022, provides critical asset management and maintenance software to more than 12,000 clients worldwide. The company employs over 700 individuals. The security incident highlights how insider threats can bypass perimeter defenses by leveraging legitimate permissions granted during active contracts.
Technical Analysis of the Insider Attack
The attack unfolded shortly after Curry learned that his six-month contract as a data analyst would not be extended. Prior to his departure, Curry exfiltrated sensitive corporate documents after gaining unauthorized or abuse-of-access privileges to the company’s payroll systems and core corporate databases.
One day after his contract formally terminated on December 10, Curry initiated the extortion campaign. Between December 11, 2023, and January 24, 2024, he used the alias “Loot” via the email address lootsoftware@outlook.com to message dozens of Brightly employees. The communications included explicit threats to leak stolen internal records unless the monetary demands were met.
To substantiate his threats, Curry attached screenshots containing personally identifiable information (PII) belonging to Brightly employees. The leaked data included:
- Full employee names
- Dates of birth
- Residential home addresses
- Detailed compensation and salary structures
In his extortion messages, Curry threatened to stagger the release of salary information in phases beginning January 1, 2024. He also threatened to report Brightly to the U.S. Securities and Exchange Commission (SEC) for allegedly failing to disclose the data compromise promptly. Furthermore, the attacker demanded payment in cryptocurrency, warning that each subsequent month of non-compliance would incur an additional $100,000 penalty.
Under pressure from the ongoing threats, Brightly transferred $7,540 in Bitcoin to a cryptocurrency wallet controlled by Curry. The company subsequently reported the crime to law enforcement. On January 24, 2024, the Federal Bureau of Investigation (FBI) executed a search warrant at Curry’s residence, seizing electronic devices containing definitive forensic evidence linking him to the extortion emails and the exfiltrated database files. Curry was subsequently found guilty in March and received his two-year prison sentence.
Broader Implications for Enterprise Security
This incident illustrates the operational friction that occurs when technical preventative controls fail to account for post-employment access. Overall prevention scores can frequently obscure what happens after initial access is established, particularly when users possess valid credentials. Once an actor is authenticated within internal systems, perimeter security drops sharply, making behavior-based monitoring essential.
Organizations must recognize that insider threats extend beyond malicious actors infiltrating a network; they frequently originate from authorized personnel whose access permissions outlive their business justification. Security teams must ensure that offboarding procedures are tightly integrated with identity and access management (IAM) systems to revoke privileges instantaneously upon contract termination.
Actionable Recommendations and Mitigations
Defenders and IT administrators must prioritize several core strategies to defend against similar insider extortion schemes and data exfiltration attempts:
- Strict Offboarding Protocols: Automate the revocation of all active directory accounts, VPN access, database permissions, and SaaS credentials the exact moment a contractor’s agreement or employee’s tenure ends.
- Least Privilege Access: Implement role-based access control (RBAC) to restrict contractor visibility strictly to the specific assets required for their immediate tasks, preventing broad access to payroll and corporate PII.
- Behavioral Monitoring and Data Loss Prevention (DLP): Deploy advanced DLP solutions and User and Entity Behavior Analytics (UEBA) to detect abnormal data aggregation, massive file downloads, or unauthorized exfiltration attempts to external endpoints before contracts expire.
- Secure Credential Rotation: Regularly audit administrative accounts and service tokens to ensure that former personnel retain no lingering pathways back into corporate networks.
Related: Canadian Threat Actor Pleads Guilty in Snowflake Extortions, Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks