Skip to main content

Data Analyst Sentenced to Prison for Extorting Brightly Software

4 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • A former contractor targeted Brightly Software with an extortion scheme demanding $2.5 million in cryptocurrency after stealing sensitive internal data.
  • The affected organization is Brightly Software, a SaaS asset management company owned by Siemens that serves over 12,000 global clients.
  • Organizations must enforce strict internal access controls and monitor contractor accounts to mitigate malicious insider threats.

Advertisement

Overview of the Extortion Case

A former contractor for Brightly Software has been sentenced to two years in federal prison following a targeted extortion scheme against the company. According to a report by BleepingComputer, 27-year-old North Carolina resident Cameron Curry, who operated under the alias “Loot,” orchestrated a campaign demanding $2.5 million in cryptocurrency. The incident underscores the severe risks posed by disgruntled former contractors and inadequate internal access controls within SaaS and enterprise environments.

Brightly Software, formerly known as SchoolDude and acquired by Siemens in August 2022, provides critical asset management and maintenance software to more than 12,000 clients worldwide. The company employs over 700 individuals. The security incident highlights how insider threats can bypass perimeter defenses by leveraging legitimate permissions granted during active contracts.

Technical Analysis of the Insider Attack

The attack unfolded shortly after Curry learned that his six-month contract as a data analyst would not be extended. Prior to his departure, Curry exfiltrated sensitive corporate documents after gaining unauthorized or abuse-of-access privileges to the company’s payroll systems and core corporate databases.

One day after his contract formally terminated on December 10, Curry initiated the extortion campaign. Between December 11, 2023, and January 24, 2024, he used the alias “Loot” via the email address lootsoftware@outlook.com to message dozens of Brightly employees. The communications included explicit threats to leak stolen internal records unless the monetary demands were met.

To substantiate his threats, Curry attached screenshots containing personally identifiable information (PII) belonging to Brightly employees. The leaked data included:

  • Full employee names
  • Dates of birth
  • Residential home addresses
  • Detailed compensation and salary structures

In his extortion messages, Curry threatened to stagger the release of salary information in phases beginning January 1, 2024. He also threatened to report Brightly to the U.S. Securities and Exchange Commission (SEC) for allegedly failing to disclose the data compromise promptly. Furthermore, the attacker demanded payment in cryptocurrency, warning that each subsequent month of non-compliance would incur an additional $100,000 penalty.

Under pressure from the ongoing threats, Brightly transferred $7,540 in Bitcoin to a cryptocurrency wallet controlled by Curry. The company subsequently reported the crime to law enforcement. On January 24, 2024, the Federal Bureau of Investigation (FBI) executed a search warrant at Curry’s residence, seizing electronic devices containing definitive forensic evidence linking him to the extortion emails and the exfiltrated database files. Curry was subsequently found guilty in March and received his two-year prison sentence.

Broader Implications for Enterprise Security

This incident illustrates the operational friction that occurs when technical preventative controls fail to account for post-employment access. Overall prevention scores can frequently obscure what happens after initial access is established, particularly when users possess valid credentials. Once an actor is authenticated within internal systems, perimeter security drops sharply, making behavior-based monitoring essential.

Organizations must recognize that insider threats extend beyond malicious actors infiltrating a network; they frequently originate from authorized personnel whose access permissions outlive their business justification. Security teams must ensure that offboarding procedures are tightly integrated with identity and access management (IAM) systems to revoke privileges instantaneously upon contract termination.

Actionable Recommendations and Mitigations

Defenders and IT administrators must prioritize several core strategies to defend against similar insider extortion schemes and data exfiltration attempts:

  • Strict Offboarding Protocols: Automate the revocation of all active directory accounts, VPN access, database permissions, and SaaS credentials the exact moment a contractor’s agreement or employee’s tenure ends.
  • Least Privilege Access: Implement role-based access control (RBAC) to restrict contractor visibility strictly to the specific assets required for their immediate tasks, preventing broad access to payroll and corporate PII.
  • Behavioral Monitoring and Data Loss Prevention (DLP): Deploy advanced DLP solutions and User and Entity Behavior Analytics (UEBA) to detect abnormal data aggregation, massive file downloads, or unauthorized exfiltration attempts to external endpoints before contracts expire.
  • Secure Credential Rotation: Regularly audit administrative accounts and service tokens to ensure that former personnel retain no lingering pathways back into corporate networks.

Related: Canadian Threat Actor Pleads Guilty in Snowflake Extortions, Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks

Advertisement

Advertisement