Executive Summary
In December 2023, Cameron Curry, a data analyst contractor at Brightly Software, exploited his access to sensitive corporate data, including employee compensation information, to orchestrate an extortion scheme. After his contract ended, Curry sent over 60 threatening emails to Brightly's employees and executives, demanding approximately $2.5 million to prevent the release of the stolen data. The company reported the incident to the FBI on December 14, 2023, and ultimately paid $7,540.92 in ransom. Curry was arrested and, in March 2026, convicted on six counts of extortion, leading to a two-year prison sentence. This case underscores the significant risks associated with insider threats, particularly when contractors or employees have access to confidential information. Organizations must implement stringent access controls, continuous monitoring, and robust incident response plans to mitigate such risks. The incident also highlights the importance of promptly reporting breaches to authorities to facilitate swift legal action.
Why This Matters Now
The Brightly Software incident highlights the persistent and evolving threat of insider attacks, emphasizing the need for organizations to reassess and strengthen their internal security measures to protect sensitive data from malicious insiders.
Attack Path Analysis
Cameron Curry, a contractor at Brightly Software, exploited his authorized access to collect sensitive corporate data, including employee compensation information. He then exfiltrated this data, likely using removable media or personal devices, and subsequently attempted to extort the company by threatening to disclose the information unless a ransom was paid.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Curry, as a contractor, was granted authorized access to Brightly Software's internal systems and sensitive data.
MITRE ATT&CK® Techniques
Valid Accounts
Data from Cloud Storage
Exfiltration Over Web Service
Data Encrypted for Impact
Inhibit System Recovery
Command and Scripting Interpreter
Application Layer Protocol
File and Directory Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Limit Access to System Components and Cardholder Data
Control ID: 7.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Insider threats targeting software companies face elevated risks from contractor access to sensitive data, requiring enhanced zero trust segmentation and egress security controls.
Information Technology/IT
IT sector contractors with privileged access pose significant insider threat risks, necessitating robust threat detection, anomaly response, and multicloud visibility controls.
Outsourcing/Offshoring
Third-party contractor arrangements face heightened insider threat exposure, requiring strict access controls, encrypted traffic monitoring, and comprehensive policy enforcement mechanisms.
Staffing/Recruiting
Staffing firms placing contractors at client sites must implement enhanced vetting and monitoring to prevent insider threats and data exfiltration attacks.
Sources
- Tech contractor for Brightly Software sentenced to 2 years in prison for insider attackhttps://cyberscoop.com/cameron-curry-insider-attack-brightly-software-sentenced/Verified
- North Carolina Man Convicted in Cyber Extortion Scheme That Targeted D.C.-based Tech Companyhttps://www.justice.gov/usao-dc/pr/north-carolina-man-convicted-cyber-extortion-scheme-targeted-dc-based-tech-companyVerified
- Federal Jury Convicts Charlotte Man For Cyber Extortion Scheme That Targeted International Technology Companyhttps://www.justice.gov/usao-wdnc/pr/federal-jury-convicts-charlotte-man-cyber-extortion-scheme-targeted-internationalVerified
- North Carolina tech worker found guilty of insider attack netting $2.5M ransomhttps://cyberscoop.com/cameron-curry-insider-attack-washington-tech-company/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the contractor's ability to access, move laterally, and exfiltrate sensitive data, thereby reducing the potential blast radius of the breach.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The contractor's access to sensitive systems and data could have been limited to only what was necessary for his role, reducing the risk of unauthorized data collection.
Control: Zero Trust Segmentation
Mitigation: The contractor's ability to aggregate sensitive data could have been constrained, limiting his access to only the data necessary for his specific tasks.
Control: East-West Traffic Security
Mitigation: The contractor's ability to move laterally within the network could have been restricted, reducing the risk of unauthorized access to various internal systems.
Control: Multicloud Visibility & Control
Mitigation: The contractor's ability to retain and misuse exfiltrated data could have been limited, reducing the risk of data being used for extortion.
Control: Egress Security & Policy Enforcement
Mitigation: The contractor's ability to exfiltrate sensitive data could have been restricted, reducing the risk of data leaving the organization's control.
The potential impact of the extortion attempt could have been mitigated, reducing the risk of sensitive data exposure and financial loss.
Impact at a Glance
Affected Business Functions
- Human Resources
- Legal Compliance
- Executive Management
Estimated downtime: N/A
Estimated loss: $2,500,000
Personally identifiable information (PII) of employees, including compensation details.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit data access based on user roles.
- • Deploy Egress Security & Policy Enforcement to monitor and control data transfers, preventing unauthorized exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous data access and transfer activities.
- • Apply Threat Detection & Anomaly Response mechanisms to identify and mitigate insider threats in real-time.
- • Establish comprehensive identity governance policies to manage and monitor contractor access to sensitive data.



