A former data analyst contractor has been sentenced to two years in prison after using sensitive company information to carry out an extortion scheme against his former employer Brightly Software. The man, 27-year-old Cameron Curry from North Carolina, was also known online as “Loot.” He was previously found guilty of six counts of transmitting or causing interstate communications with the intention of extorting the company. The case highlights the serious risks that can arise when trusted workers misuse legitimate access to sensitive business information.

Curry worked as a contracted data analyst for Brightly for around six months between August and December 2023. During his work, he had legitimate access to company systems containing corporate records, payroll information and sensitive employee details. According to court evidence, he copied confidential information and later used it as leverage after discovering that his contract would not be extended. The incident was therefore not based on breaking into the company from outside, but on abusing access he already had.
After his contract ended on December 10, 2023, Curry began contacting Brightly employees and executives under the name “Loot.” Between December 11 and January 24, he sent more than 60 threatening emails demanding $2.5 million in cryptocurrency. He warned that the stolen information would be released if the company refused to pay. The messages also threatened to expose sensitive corporate records and employee information, increasing pressure on the company to meet his demands.

The stolen material included highly sensitive employee information. Curry attached screenshots showing personally identifiable information such as names, dates of birth, home addresses and compensation details. He also threatened to report Brightly to the U.S. Securities and Exchange Commission, claiming the company had failed to properly disclose the incident. His messages presented the data theft as a way to pressure the company over salary differences, while still demanding millions of dollars to prevent the information from being released publicly.
Although Curry demanded $2.5 million, Brightly ultimately paid about $7,540.92 in Bitcoin to a cryptocurrency wallet controlled by him. The company had already reported the incident to the FBI, which moved to investigate the extortion attempt. On January 24, 2024, federal agents searched Curry’s residence and seized electronic devices. Investigators later examined the devices and found evidence connecting him to the extortion campaign and the online “Loot” identity used in the threatening communications.

Curry was eventually prosecuted and found guilty in March 2026 after a federal jury convicted him on six extortion-related counts. At the time of his conviction, each charge carried a maximum sentence of two years in prison, meaning he faced up to 12 years if the sentences were imposed consecutively. The case was investigated by the FBI, including its Washington and Charlotte field offices. Prosecutors presented evidence showing how Curry used information obtained through his legitimate employment to pressure the company after his contract ended.
The latest development came in August 2026, when Curry was sentenced to two years in federal prison followed by one year of supervised release. The sentence brings a legal conclusion to a case that began with the misuse of authorized workplace access. Investigators also found that Curry made operational security mistakes while handling the cryptocurrency payment and used personally identifiable information when setting up a Coinbase account. These mistakes helped investigators connect the financial activity to him.

The incident is a clear example of the insider threat problem faced by modern organizations. Companies can have strong external security defenses and still face serious risks when employees or contractors misuse legitimate access to confidential information. Sensitive data should therefore be protected through strict access controls, monitoring, data loss prevention and timely removal of access when contracts or employment end. The case also shows that stealing data for financial gain can result in serious criminal consequences, even when the person originally had authorized access.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news