Executive Summary

In December 2023, Cameron Curry, a data analyst contractor at Brightly Software, exploited his access to sensitive corporate data, including employee compensation information, to orchestrate an extortion scheme. After his contract ended, Curry sent over 60 threatening emails to Brightly's employees and executives, demanding approximately $2.5 million to prevent the release of the stolen data. The company reported the incident to the FBI on December 14, 2023, and ultimately paid $7,540.92 in ransom. Curry was arrested and, in March 2026, convicted on six counts of extortion, leading to a two-year prison sentence. This case underscores the significant risks associated with insider threats, particularly when contractors or employees have access to confidential information. Organizations must implement stringent access controls, continuous monitoring, and robust incident response plans to mitigate such risks. The incident also highlights the importance of promptly reporting breaches to authorities to facilitate swift legal action.

Why This Matters Now

The Brightly Software incident highlights the persistent and evolving threat of insider attacks, emphasizing the need for organizations to reassess and strengthen their internal security measures to protect sensitive data from malicious insiders.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed deficiencies in access controls and monitoring mechanisms, allowing a contractor to exfiltrate sensitive data without detection.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the contractor's ability to access, move laterally, and exfiltrate sensitive data, thereby reducing the potential blast radius of the breach.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The contractor's access to sensitive systems and data could have been limited to only what was necessary for his role, reducing the risk of unauthorized data collection.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The contractor's ability to aggregate sensitive data could have been constrained, limiting his access to only the data necessary for his specific tasks.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The contractor's ability to move laterally within the network could have been restricted, reducing the risk of unauthorized access to various internal systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The contractor's ability to retain and misuse exfiltrated data could have been limited, reducing the risk of data being used for extortion.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The contractor's ability to exfiltrate sensitive data could have been restricted, reducing the risk of data leaving the organization's control.

Impact (Mitigations)

The potential impact of the extortion attempt could have been mitigated, reducing the risk of sensitive data exposure and financial loss.

Impact at a Glance

Affected Business Functions

  • Human Resources
  • Legal Compliance
  • Executive Management
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $2,500,000

Data Exposure

Personally identifiable information (PII) of employees, including compensation details.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege access and limit data access based on user roles.
  • Deploy Egress Security & Policy Enforcement to monitor and control data transfers, preventing unauthorized exfiltration.
  • Utilize Multicloud Visibility & Control to detect and respond to anomalous data access and transfer activities.
  • Apply Threat Detection & Anomaly Response mechanisms to identify and mitigate insider threats in real-time.
  • Establish comprehensive identity governance policies to manage and monitor contractor access to sensitive data.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image