Protect.Computer
NEWS

Data Analyst Gets 2 Years for $2.5M Extortion of Employer

· 1 min read · Data hijack
Data Analyst Gets 2 Years for $2.5M Extortion of Employer

A North Carolina man who used his access as a data analyst contractor to steal sensitive employee records and then demand $2.5 million in ransom has been sentenced to two years in federal prison. Cameron Curry, 27, of Charlotte — who operated online under the alias “Loot” — worked a six-month contract at Brightly Software, a Siemens-owned SaaS company that provides asset management tools to more than 12,000 organizations including schools and municipalities.

When Curry learned his contract would not be renewed, he exfiltrated payroll data and personal records for Brightly employees, including names, home addresses, dates of birth, and salary information. The day after his contract ended, he began sending extortion emails from the alias lootsoftware@outlook.com to employees and executives — more than 60 messages in total, sent between December 11, 2023 and January 24, 2024. In one email he threatened: “We will commence the process of disseminating salary information starting January 1, 2024 in phases to all employees and will report you to the SEC after for not reporting the breach.” He demanded $2.5 million in cryptocurrency with an additional $100,000 monthly escalation. Brightly paid $7,540 in Bitcoin before reporting the incident to the FBI. Federal agents searched Curry’s home and seized devices linking him to the scheme. He was convicted in March 2026 of six counts of transmitting interstate communications with intent to extort, and sentenced this week to 24 months in prison.

The case illustrates a recurring insider threat pattern: a privileged user who abuses data access obtained through a legitimate role. Brightly’s experience also shows that paying a ransomware or extortion demand, even partially, does not ensure attacker silence — Curry continued emailing employees after receiving the initial payment.

Sources

Related reading