Cameron Curry, 27, of North Carolina, has been sentenced to two years in prison after a guilty verdict in March 2026.

He had worked as a data analyst at Brightly Software — formerly SchoolDude, a SaaS firm with 700+ employees serving 12,000+ clients. His contract ended on 10 December 2023.

The extortion emails began on 11 December.

What he took, and what he asked for

Payroll information, corporate data, and employee personal data — names, dates of birth, home addresses and compensation details.

Between 11 December 2023 and 24 January 2024 he emailed dozens of employees from lootsoftware@outlook.com, using the alias Loot, demanding $2.5 million in cryptocurrency. He threatened to release salary data and to report the company to the SEC.

If you wish to reclaim your data, we recommend doing so promptly at 2.5 million USD in order to save your company and stocks, as each subsequent month will incur a $100,000 USD increase.

Note the escalation clause. This is ransomware negotiation language written by someone who has read ransomware negotiations, applied to a spreadsheet of colleagues' salaries.

Note also who he emailed: dozens of employees, not the executive team. Extorting a company through its own staff — people who can see their own home address in the leak — is a pressure tactic that does not need any infrastructure at all.

The company paid, then reported

Brightly paid $7,540 in Bitcoin to Curry's wallet before reporting the incident.

Two things about that number.

It is 0.3% of the demand. This looks like a partial or test payment rather than a settlement — the sort of thing done to verify a channel or buy time.

And it was traceable. Reporting followed, and the FBI searched Curry's residence on 24 January 2024, seizing devices that carried the evidence. Six weeks from first email to search warrant.

The offboarding question

His contract ended on the 10th. He had the data on the 11th.

Nothing in the reporting says how it left, and we are not going to guess. But the shape is the same one in Apple's complaint against OpenAI, where an engineer allegedly kept a company laptop after leaving and downloaded confidential documents from it: the gap between the last day and the moment access actually ends.

That gap is where insider incidents live, and it is almost always procedural rather than technical:

  • Contractor accounts disabled on a schedule rather than on the day
  • Data exports that were legitimate while employed and never reviewed after
  • Personal devices that synced a share and were never wiped
  • A laptop return that nobody chased

A data analyst has bulk access to exactly the data that makes a good extortion package. That is the job.

Two years, and what it says

Two years for a $2.5 million demand against 700 employees' personal data is a light sentence by the standards of external ransomware prosecutions — but external ransomware operators are rarely in a jurisdiction where prosecution is possible at all.

We wrote about the €30m Commerzbank fraud that took three years to reach arrests across four countries. This one took six weeks to a search warrant, because the offender was a former employee in the same country, using an Outlook address, receiving Bitcoin to a wallet he controlled.

Insider cases get solved. That is the one genuinely reassuring thing here, and it is worth telling staff.

What to actually change

  • Revoke on the last day, not the next cycle. Contractors especially — they are the ones whose end date is a calendar entry rather than an HR process.
  • Alert on bulk export in the notice period. Not to accuse anyone; to have a record.
  • Chase the device. An unreturned laptop is an open door with a timestamp on it.
  • Decide now who takes an extortion email. Brightly's staff received these directly. Whether an employee forwards it, replies, or panics is determined by whether they were ever told what to do.
  • Do not pay to test the channel. The $7,540 bought nothing and is now a line in a court record.