Contractor Jailed Two Years After $2.5M Extortion Attempt Against Brightly Software

Cameron Curry stole payroll data on his way out the door, then threatened to report his ex-employer to the SEC unless it paid up.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A corporate office hallway with security personnel and law enforcement personnel walking through, file boxes being carried out, representing the aftermath of th
Share

Key points

  • Cameron Curry, 27, of North Carolina was sentenced to two years in prison for extorting Brightly Software with a demand of $2.5 million.
  • Curry sent extortion emails to dozens of Brightly staff between December 11 and January 24, 2024, one day after his six-month contract ended.
  • He threatened to leak stolen payroll data and report the company to the SEC for failing to disclose the breach.
  • Brightly paid $7,540 in Bitcoin before contacting law enforcement; the FBI searched Curry's home on January 24, 2024.
  • The stolen data was internal employee records, not customer data; a separate 2023 breach affected nearly three million SchoolDude users.

A former contract data analyst at Brightly Software has been sentenced to two years in federal prison for a cyber extortion scheme demanding $2.5 million from the company that had just declined to renew his contract.

Cameron Curry, 27, of North Carolina was convicted in March 2025. He used the alias "Loot" and the address lootsoftware@outlook.com to send threatening emails to Brightly staff, according to court filings from the U.S. Department of Justice.

Brightly is a Software-as-a-Service company, meaning it rents access to its programs over the internet rather than selling boxed software. Formerly known as SchoolDude, it was acquired by Siemens in August 2022 and sells asset and maintenance management tools to more than 12,000 customers.

What did the contractor actually do?

Curry copied sensitive payroll and corporate records while he still had access, then used those files as a weapon after his contract expired on December 10, 2023. The emails started the very next day.

Between December 11, 2023 and January 24, 2024, he emailed dozens of Brightly employees demanding $2.5 million in cryptocurrency, warning that each month of delay would add $100,000 to the price. He attached screenshots of employee personally identifiable information, known as PII: names, dates of birth and compensation details. In one message he wrote that he would "commence the process of disseminating salary information starting January 1, 2024" and would "report you to the SEC after for not reporting the breach."

Brightly paid $7,540 in Bitcoin to a wallet later traced to Curry. The company then reported the matter to law enforcement, and the FBI searched Curry's home on January 24, 2024, seizing devices that tied him to the scheme.

Why bring up the SEC?

Curry was invoking the SEC's cybersecurity disclosure rule, which took effect in December 2023, right in the middle of his campaign. Under Item 1.05 of Form 8-K, public companies must disclose a "material" cybersecurity incident within four business days of determining materiality.

Brightly itself is a Siemens subsidiary, not a separately listed U.S. Issuer, so the four-day trigger doesn't attach directly to it. That gap didn't stop Curry from using the threat. Extortionists learn the rules faster than most people expect, and the SEC has since taken enforcement action against companies it viewed as misleading investors about intrusions, so the reputational lever is real even where the strict filing obligation isn't. We covered a related pattern of post-breach pressure in our Analog Devices story on 30 July, where a separate extortion group claimed to hold 570,000 records after an intrusion.

Timeline of the case

Date Event
Aug 2022 Siemens acquires Brightly Software
Dec 10, 2023 Curry's six-month contract ends
Dec 11, 2023 First extortion email sent under the "Loot" alias
Jan 24, 2024 FBI searches Curry's residence; extortion campaign ends
March 2025 Curry convicted of cyber extortion

Is there anything customers need to do?

Brightly customers don't appear to be affected by this case. The data Curry took was internal payroll and corporate information about employees, not customer records.

A separate incident disclosed by Brightly in May 2023 exposed names, email addresses and phone numbers for nearly three million users of the SchoolDude platform, along with hashed account passwords. Anyone who used SchoolDude before that date should confirm that password isn't reused elsewhere.

© 2026 Threat Vectr