Former Brightly Analyst Sentenced to Prison for Extorting Employer

Photo: BleepingComputer
Quick answer
A former Brightly Software analyst was convicted of cyber extortion after stealing corporate data, including salary details, and demanding $2.5M in cryptocurrency.
Former contract analyst at Brightly Software, Cameron Curry, has been sentenced to two years in prison for cyber extortion. The perpetrator, who worked at the company under a six-month contract, stole confidential data, including employee salary information and corporate documents, after learning his contract would not be renewed.
Following his dismissal, Curry sent threatening emails to dozens of Brightly employees, demanding $2.5 million in cryptocurrency to prevent the disclosure of the stolen data. In the emails, he threatened to report the company to the U.S. Securities and Exchange Commission (SEC) for concealing the data breach and to publish employees' personal details, including addresses and salary figures.
Brightly Software partially complied with the extortionist’s demands, transferring $7,500 in Bitcoin, but subsequently reported the incident to the FBI. During the investigation, law enforcement conducted a search of Curry’s home and seized electronic devices containing evidence. The company confirmed its cooperation with authorities and noted that the incident was unrelated to a previously reported data leak at its subsidiary platform, SchoolDude.
This case underscores the growing threat of insider risks to IT companies. Even temporary employees can gain access to critical data, necessitating stronger access control and monitoring measures.
Common questions
- What data did Cameron Curry steal from Brightly Software?
- Curry stole confidential information, including employee salary data, personal details (names, birth dates, addresses), and corporate documents. This data was used to blackmail the company.
- How did Brightly Software respond to the extortion?
- The company partially complied with the demands, transferring $7,500 in Bitcoin, but later reported the incident to law enforcement. The FBI conducted a search and seized evidence linking Curry to the crime.
- What security measures are recommended to prevent insider threats?
- Companies are advised to implement multi-factor authentication, restrict employee access to sensitive data, conduct regular security audits, and train staff on cybersecurity best practices.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml