Tech Contractor Sentenced to Two Years for Insider Attack on Brightly Software

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

A tech worker has been sentenced to two years in prison for an insider attack on Brightly Software, where he attempted to extort the company for approximately $2.5 million. Cameron Nicholas Curry, a 27-year-old data analyst contractor for the Siemens-owned firm, was found guilty of six counts of extortion in March after stealing sensitive corporate data and threatening employees over a six-week period.

According to the Justice Department, Curry, also known as “Loot,” accessed the company’s network between August and December 2023, stealing sensitive employee and compensation information. Following his termination, he sent over 60 threatening emails to Brightly Software employees, demanding a ransom to prevent the disclosure of the stolen data, which he framed as an effort to promote salary transparency.

Brightly Software, which was acquired by Siemens in 2022, was named as the victim in court records filed in the U.S. District Court for the Western District of North Carolina. The company did not immediately respond to requests for comment. Curry ultimately extorted the company for $7,540.92 in late January 2024.

The case highlights the risks associated with granting employees or contractors access to sensitive data on company-owned devices. Curry’s operational security mistakes, including using personal data to create a Coinbase account linked to his family members’ debit cards, facilitated the investigation. The FBI conducted searches of his apartment and digital devices weeks after the ransom was paid.

Curry faced a potential sentence of up to 12 years but received a two-year sentence followed by one year of supervised release. His lawyers argued that the case was prolonged due to errors by prosecutors, including incorrect claims about the company’s headquarters, which led to a change in trial venue and extended pretrial confinement.

The incident underscores the importance of robust cybersecurity measures and the potential consequences of insider threats in organizations. For more details, see the full report by CyberScoop.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Meta’s AI Assistant Muse Exposed by Zero-Day Vulnerability, Prompting Amazon to Block Access

Meta's new AI assistant, Muse, has come under scrutiny following the discovery of a zero-day vulnerability that allows locally run applications and terminal commands...

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...

CrowdStrike’s SafeMind Enhances Cyber Defense with Advanced Offensive Techniques

Revolutionizing Cyber Defense: CrowdStrike's SafeMind System In the ever-evolving landscape of cybersecurity, the ability...