Contractor Jailed Two Years After $2.5M Extortion Attempt Against Brightly Software

Cameron Curry stole payroll data on his way out the door, then threatened to report his ex-employer to the SEC unless it paid up.

ThreatVectr Newsdesk· 4 min read
Photoreal editorial image of a sleek modern server rack glowing with blue indicator lights, partially connected by old beige Ethernet cables and a vintage patch
Share

Key points

  • Cameron Curry, 27, of North Carolina was sentenced to two years in prison for extorting Brightly Software, his former employer, out of a demanded $2.5 million.
  • Curry sent extortion emails to dozens of Brightly staff between December 11, 2023 and January 24, 2024, one day after his six-month contract ended.
  • He threatened to leak stolen payroll data and report the company to the U.S. Securities and Exchange Commission for failing to disclose the breach.
  • Brightly paid $7,540 in Bitcoin before contacting law enforcement; the FBI searched Curry's home on January 24, 2024.
  • Brightly, owned by Siemens since August 2022, serves more than 12,000 clients worldwide.

A former contract data analyst at Brightly Software has been sentenced to two years in federal prison for a cyber extortion scheme that demanded $2.5 million from the company that had just declined to renew his contract.

Cameron Curry, 27, of North Carolina, was convicted in March. He used the alias "Loot" and the address lootsoftware@outlook.com to send threatening emails to Brightly staff, according to court filings from the U.S. Department of Justice.

Brightly is a Software-as-a-Service company, meaning it rents access to its programs over the internet rather than selling boxed software. Formerly known as SchoolDude, it was acquired by Siemens in August 2022 and sells asset and maintenance management tools to more than 12,000 customers.

What did the contractor actually do?

Curry copied sensitive payroll and corporate records while he still had access, then used them as leverage after his contract expired on December 10, 2023. One day later, the extortion emails began.

Between December 11, 2023 and January 24, 2024, he emailed dozens of Brightly employees demanding $2.5 million in cryptocurrency. Each month of delay, he warned, would add another $100,000 to the price.

He attached screenshots of employee personally identifiable information, known as PII, meaning data like names, dates of birth, home addresses and salaries. In one message he wrote that he would "commence the process of disseminating salary information starting January 1, 2024" and would "report you to the SEC after for not reporting the breach."

Brightly paid $7,540 in Bitcoin to a wallet later traced to Curry, then reported the matter to law enforcement. The FBI searched his home on January 24, 2024 and seized devices tying him to the scheme, as first reported by BleepingComputer.

Why bring up the SEC?

Curry was invoking the SEC's cybersecurity disclosure rule, which took effect on December 18, 2023, right in the middle of his extortion campaign. Under Item 1.05 of Form 8-K, public companies must disclose a "material" cybersecurity incident within four business days of determining materiality.

Brightly itself is a Siemens subsidiary, not a separately listed U.S. issuer, so the four-day trigger does not attach directly to it. Still, the threat shows how quickly extortionists have folded the new disclosure regime into their pressure tactics. Regulators warned about exactly this during the comment period on the proposed rule in 2022.

The SEC has since taken enforcement action against companies it viewed as misleading investors about intrusions, so the reputational lever is real even where the strict filing obligation is not.

Timeline of the case

Date Event
Aug 2022 Siemens acquires Brightly Software
Dec 10, 2023 Curry's six-month contract ends
Dec 11, 2023 First extortion email sent under the "Loot" alias
Jan 24, 2024 FBI searches Curry's residence; extortion campaign ends
March 2025 Curry convicted of cyber extortion

Is there anything customers need to do?

Brightly customers do not appear to be affected by this case. The data Curry took was internal payroll and corporate information about employees, not customer records.

A separate incident, disclosed by Brightly in May 2023, exposed names, email addresses, hashed account passwords and phone numbers for nearly 3 million users of the SchoolDude platform. Anyone who used SchoolDude before that date should still make sure the password is not reused elsewhere.

© 2026 Threat Vectr