A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme.
Brightly is a Software-as-a-Service (SaaS) company formerly known as SchoolDude, which was acquired by Siemens in August 2022. Brightly employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide.
27-year-old North Carolina man Cameron Curry (also known as “Loot”) was found guilty in March of orchestrating an “extensive cyber extortion scheme” targeting his employer.
According to court documents, Curry stole sensitive documents after gaining access to the company’s payroll information and corporate data, which he later used to extort Brightly after learning that his six-month contract wouldn’t be extended.
One day after his contract ended on December 10, he emailed dozens of Brightly employees using the Loot alias and the lootsoftware@outlook.com email address between December 11, 2023, and January 24, 2024, threatening to leak the stolen information unless he was paid a $2.5 million ransom in cryptocurrency.
“We will commence the process of disseminating salary information starting January 1, 2024 in phases to all employees and will report you to the SEC after for not reporting the breach,” Curry said in one of the extortion messages.
“If you wish to reclaim your data, we recommend doing so promptly at 2.5 million USD in order to save your company and stocks, as each subsequent month will incur a $100,000 USD increase. Discrepancies in your books are currently over 16 million USD, posing a potential risk for retention issues, a hostile work environment, resentment, and more.”
He also attached screenshots of employees’ personally identifiable information (PII), including their names, dates of birth, home addresses, and compensation information, and threatened to report Brightly to the U.S. Securities and Exchange Commission (SEC) for failing to disclose the breach.
Following Curry’s many extortion emails, Brightly paid $7,540 in Bitcoin, transferring the funds to a cryptocurrency wallet controlled by Curry.
After the company reported the incident to law enforcement, the FBI searched Curry’s residence on January 24 and seized various electronic devices containing evidence that linked him to the extortion scheme.
“We are aware of the U.S. Department of Justice’s (DOJ) convictions of Cameron Curry for extortion,” Brightly told BleepingComputer in March.
“We have fully cooperated with the FBI and DOJ in this matter and appreciate their investigative efforts. Given that these proceedings are pending, we defer all questions to law enforcement authorities.”
In May 2023, Brightly also disclosed a data breach (unrelated to this case) after attackers stole credentials and personal data (including names, email addresses, account passwords, phone numbers) of nearly 3 million customers and users from the database of its SchoolDude online platform.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Man gets six years for hacking 750 women’s Snapchat accounts
Wesco confirms security incident after ExfilSquad claims data theft
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
Canadian pleads guilty to Snowflake cloud data-theft attacks
Ernst & Young data breach claimed by ShinyHunters extortion gang
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats
Overdue a password health-check? Audit your Active Directory for free
Stop AI slopsquatting attacks. Secure open source package ingestion before it hits your build.
Overdue a password health-check? Audit your Active Directory for free
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



