The Containment Era is here. →Explore

Executive Summary

In December 2023, Cameron Curry, a 27-year-old data analyst contractor at Brightly Software, exploited his access to the company's payroll and corporate data to steal sensitive employee information. Upon learning that his contract would not be extended, Curry initiated an extortion scheme, demanding $2.5 million to prevent the release of the stolen data. He sent over 60 emails to Brightly employees, threatening to disclose personal identification information (PII) unless his demands were met. The company reported the incident to the FBI, leading to Curry's arrest and subsequent conviction in March 2026.

This case underscores the persistent threat posed by insider attacks, particularly when employees or contractors misuse their access to sensitive information. Organizations must remain vigilant, implementing robust access controls and monitoring mechanisms to detect and prevent such insider threats.

Why This Matters Now

The Brightly Software incident highlights the critical need for organizations to enforce stringent access controls and continuously monitor for insider threats, especially as remote work and contractor engagements become more prevalent. Proactive measures are essential to safeguard sensitive data and maintain trust.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed deficiencies in access control and monitoring, highlighting the need for stricter policies to prevent unauthorized data access by insiders.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is relevant to this incident as it could have constrained the unauthorized data exfiltration and extortion activities by implementing strict segmentation and controlled egress policies, thereby reducing the attacker's ability to access and exfiltrate sensitive data.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The CNSF would likely have limited Curry's access to sensitive data by enforcing strict identity-based policies, reducing the risk of unauthorized data access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust Segmentation would likely have restricted Curry's ability to access sensitive employee information beyond his role's requirements, limiting data exposure.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-West Traffic Security would likely have monitored and restricted any unauthorized internal data transfers, limiting potential lateral movement.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud Visibility & Control would likely have identified and constrained unauthorized external communications, reducing the risk of successful extortion attempts.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress Security & Policy Enforcement would likely have constrained unauthorized data exfiltration attempts, reducing the risk of sensitive data being transferred out of the network.

Impact (Mitigations)

The implementation of Aviatrix Zero Trust CNSF controls would likely have constrained the attacker's ability to exfiltrate sensitive data, thereby reducing the potential impact of extortion attempts.

Impact at a Glance

Affected Business Functions

  • Human Resources
  • Payroll Management
  • Corporate Communications
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $7,540

Data Exposure

Personal identification information (PII) of employees, including names, dates of birth, home addresses, and compensation details.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized data access.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound data transfers, mitigating unauthorized exfiltration.
  • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual data access patterns indicative of insider threats.
  • Establish Multicloud Visibility & Control to maintain comprehensive oversight of data access and movement across cloud environments.
  • Regularly review and update access controls and permissions to ensure they align with current roles and responsibilities, reducing the risk of insider threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image