GoFirm
Back to Blog
Case Studies·3 min read

Nobody confirmed the payroll export a Brightly Software contractor later held for $2.5 million ransom.

By GoFirm

Brightly Software, the asset and maintenance management provider formerly known as SchoolDude and acquired by Siemens in 2022, employs more than 700 people and serves over 12,000 clients worldwide. Between August and December 2023, Cameron Nicholas Curry, a 27-year-old North Carolina man working as a data analyst contractor, used his legitimate access to the company's payroll information and corporate data to remove a trove of sensitive files, including employees' names, dates of birth, home addresses and compensation records. His six-month contract ended on 10 December 2023. It was not renewed.

The following day, Curry began emailing dozens of Brightly employees under the alias "Loot," using the address lootsoftware[@]outlook.com. Over six weeks, he sent more than 60 messages threatening to leak the stolen payroll data unless Brightly paid $2.5 million in cryptocurrency, with the demand rising by $100,000 for every month of delay. He attached screenshots of employees' personal data as proof, claimed the figures showed "discrepancies... currently over 16 million USD," framed the theft as an act of "salary transparency," and threatened to report Brightly to the Securities and Exchange Commission for failing to disclose a breach.

Brightly reported the extortion to the FBI on 14 December 2023, four days after Curry's contract ended and three days into the email campaign. A month later, the company paid $7,540 in Bitcoin, less than one third of one percent of the amount demanded, to a wallet controlled by Curry. That wallet was the mistake that ended the scheme: Curry had linked two debit cards belonging to his mother and sister to the Coinbase account used to receive the funds, giving investigators a direct path to his identity. The FBI searched his residence on 24 January 2024 and seized the devices that confirmed his involvement.

Curry was convicted in March on six counts of transmitting extortionate communications and was sentenced on 13 August 2026 to two years in prison, followed by a year of supervised release. He faced up to twelve years. The financial loss to Brightly was small. The exposure was not: a publicly traded, Siemens-owned software vendor serving thousands of institutional clients spent six weeks fielding threats to leak employee compensation data and report itself to a federal regulator, over an export nobody at the company had approved or even noticed while it was happening.

The defences that failed here were not weak by conventional standards. Curry was a vetted contractor issued a company laptop, working within systems he was authorised to use. No password was stolen, no vulnerability exploited, no perimeter breached. The entire scheme worked because access and authority were treated as the same thing. Once Curry could reach the payroll files, nothing in Brightly's systems distinguished between him viewing a record he needed for his job and him copying the company's entire compensation dataset for reasons no one had asked about.

A bulk export of payroll and personally identifiable data is an execution event, regardless of who initiates it or how long they have held their access. Before a contractor, employee, or any other authorised user can pull sensitive HR or financial data out of a system at scale, a confirmation request should go to a named authority, such as an HR director or data protection officer, on their registered device, requiring biometric confirmation before the export completes. No confirmation, no export. It does not matter whether the requester is an outside attacker with a stolen password or an insider with a valid badge and six months of tenure.

An insider with legitimate access, however trusted, cannot produce a biometric confirmation from a named authority who was never asked. The execution boundary holds regardless of how much access the person requesting it already has.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.


References
1. Kapko, M. 2026. Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack. CyberScoop, 13 August 2026.
2. Gatlan, S. 2026. Data analyst sent to prison for stealing data, extorting employer. BleepingComputer, 14 August 2026.
3. U.S. Department of Justice, Western District of North Carolina. 2026. Charlotte Man Sentenced For Cyber Extortion Scheme That Targeted International Technology Company. 13 August 2026.

Share this article