Actor Profile
Cameron Curry (alias "Loot"), a 27-year-old North Carolina resident, was a former data analyst contractor for Brightly Software (formerly SchoolDude, acquired by Siemens in 2022). Motivated by retaliation after learning his six-month contract would not be extended, Curry orchestrated an extensive cyber extortion scheme against his former employer. He leveraged insider access obtained during his legitimate employment to steal sensitive corporate and payroll data, then demanded $2.5 million in cryptocurrency under threat of public disclosure and regulatory reporting. Curry was convicted in March 2026 and sentenced to two years in prison in August 2026.
TTPs (Tactics, Techniques, Procedures)
Curry's attack chain demonstrates classic insider threat TTPs. Initial access was achieved through legitimate credentials during his employment period (T1078 - Valid Accounts). He conducted data exfiltration (T1041 - Exfiltration Over C2 Channel) of sensitive payroll information, employee PII, and corporate documents prior to contract termination. Post-employment, he executed extortion via email (T1566 - Phishing, specifically spear-phishing for communication) using the alias "Loot" and email address lootsoftware@outlook.com between December 11, 2023, and January 24, 2024. He demanded cryptocurrency payment (T1486 - Data Encrypted for Impact conceptually similar, though focused on data theft/exposure rather than encryption), threatening public disclosure of salary information, PII exposure, and SEC reporting. Brightly paid $7,540 in Bitcoin to a wallet controlled by Curry before law enforcement intervention.
Targets & Patterns
The target was Brightly Software, a SaaS company providing asset management and maintenance software to over 12,000 clients worldwide with more than 700 employees. Curry specifically targeted his former employer in retaliation for non-renewal of his contract, focusing on high-value data assets including payroll records, employee PII (names, dates of birth, home addresses, compensation details), and corporate financial information. The threat actor claimed to have identified "$16 million USD in discrepancies" to amplify pressure. The targeting pattern reflects opportunistic insider threat behavior driven by personal grievance rather than broader strategic or financial objectives beyond immediate monetary gain. The choice of a SaaS company with sensitive client and employee data provided leverage for extortion through threats of reputational damage, regulatory exposure (SEC reporting), and workplace disruption.
Historical Context
This incident represents an isolated insider threat case with no known connection to broader threat actor groups or campaigns. Curry operated as a lone actor using the "Loot" alias. The case is unrelated to a separate data breach disclosed by Brightly in May 2023, where external attackers compromised the SchoolDude platform database and stole credentials and personal data of nearly 3 million customers. That earlier breach involved credential theft and database compromise, whereas Curry's scheme relied on insider access abuse. FBI investigation led to a search of Curry's residence on January 24, 2024, resulting in seizure of electronic devices containing incriminating evidence. His conviction in March 2026 and subsequent two-year prison sentence in August 2026 demonstrate law enforcement's capability to prosecute insider threat actors, particularly when victims cooperate fully with federal authorities.
Defensive Recommendations
- Implement robust offboarding procedures that immediately revoke all access credentials, VPN tokens, and system permissions upon contract termination or employee departure to prevent post-employment data access
- Deploy Data Loss Prevention (DLP) solutions with behavioral analytics to detect anomalous data exfiltration patterns, particularly bulk downloads of sensitive payroll or PII data by users approaching contract end dates
- Establish privileged access management (PAM) controls with just-in-time access provisioning for contractors and temporary employees, limiting access scope to only necessary systems and data
- Monitor for suspicious email communications originating from external domains that reference internal company information or contain extortion language, correlating with recently departed employees or contractors
- Implement cryptocurrency transaction monitoring and incident response procedures that include immediate law enforcement notification for extortion demands, as partial payment may encourage continued threats
