VYPR
breachPublished Aug 13, 2026· 1 source

Tech Contractor Sentenced to Two Years for Insider Attack and Extortion Against Brightly Software

A former contractor for Brightly Software has been sentenced to two years in prison for an insider attack where he stole sensitive employee data and attempted to extort the company.

Cameron Nicholas Curry, a former data analyst contractor for Brightly Software, has been sentenced to two years in prison for orchestrating an insider attack and extortion scheme against his former employer. The 27-year-old North Carolina man was found guilty of six counts of extortion in March, stemming from actions taken between August and December 2023.

Curry exploited his access to Brightly Software's network, which is owned by Siemens, to steal a significant amount of corporate data. This trove included sensitive employee and compensation information. He then leveraged this data to threaten various employees and executives over a six-week period in late 2023 and early 2024, demanding a ransom to prevent its public disclosure or destruction.

The extortion attempt escalated when Curry began sending threatening emails to Brightly Software employees shortly after his last day of employment. He demanded approximately $2.5 million, framing his actions as an effort to promote salary transparency by highlighting alleged pay inequities within the company. Attachments to these emails contained screenshots of spreadsheets detailing personally identifiable information of company employees.

Prosecutors detailed how Curry's threats became personal, even targeting individuals on the legal team and suggesting he would report the breach to the Securities and Exchange Commission, citing public company disclosure rules. He also offered advice on how employees could pursue legal action for pay discrimination.

Brightly Software notified the FBI of the breach on December 14, 2023, and ultimately paid less than 1% of Curry's ransom demand in late January 2024. The company, an asset and maintenance management software provider acquired by Siemens in 2022, did not immediately comment on the sentencing.

Authorities were able to identify and build a case against Curry relatively quickly due to several operational security missteps. Notably, he used personal and verifiable data to set up a Coinbase account for receiving ransom payments, linking it to debit cards belonging to his mother and sister. This direct link facilitated his swift identification by the FBI.

Following the FBI's investigation, Curry's apartment, digital devices, and vehicle in Charlotte, North Carolina, were searched. While he faced a potential sentence of up to 12 years, he was ultimately sentenced to two years in prison, followed by one year of supervised release. His defense team argued that prosecutorial errors, including inaccurate affidavits regarding the company's headquarters, prolonged the legal proceedings.

This insider attack serves as a stark reminder of the risks companies face when granting access to sensitive data, particularly to contractors or third-party personnel. The case highlights the importance of robust access controls, data monitoring, and swift incident response protocols to mitigate the impact of malicious insider threats.

Synthesized by Vypr AI