Executive Summary
In December 2023, Cameron Curry, a former data analyst contractor for Brightly Software, exploited his access to the company's payroll and corporate data to steal sensitive employee information. After his contract ended, Curry initiated an extortion scheme, sending over 60 emails to Brightly employees between December 11, 2023, and January 24, 2024, demanding a $2.5 million ransom in cryptocurrency. He threatened to release the stolen data and report the company to the SEC for failing to disclose the breach. Brightly paid $7,540 in Bitcoin before involving law enforcement. The FBI's investigation led to Curry's conviction in March 2026 on six counts of cyber extortion, resulting in a two-year prison sentence. This incident underscores the significant risks posed by insider threats, especially when individuals with authorized access misuse their privileges. Organizations must implement robust access controls, continuous monitoring, and employee training to mitigate such risks. The case also highlights the importance of swift incident response and collaboration with law enforcement to address cyber extortion attempts effectively.
Why This Matters Now
The rise in insider threats, as demonstrated by this case, emphasizes the urgent need for organizations to strengthen internal security measures and foster a culture of cybersecurity awareness to prevent similar incidents.
Attack Path Analysis
The attacker, a former data analyst contractor, exploited his existing access to Brightly Software's payroll and corporate data to steal sensitive information. He then escalated his actions by exfiltrating this data to his personal devices. Subsequently, he initiated an extortion scheme, demanding $2.5 million in cryptocurrency to prevent the release of the stolen data. The exfiltration of sensitive employee information posed significant risks to the company's reputation and compliance status. The extortion attempt aimed to coerce the company into paying a ransom to avoid public disclosure and potential regulatory penalties.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
The attacker, a former data analyst contractor, exploited his existing access to Brightly Software's payroll and corporate data to steal sensitive information.
MITRE ATT&CK® Techniques
Valid Accounts
Data from Cloud Storage
Automated Exfiltration
Exfiltration Over Web Service
Financial Theft
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Protect stored cardholder data
Control ID: 3.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data Protection
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
SaaS companies face critical insider threat exposure with privileged data access, requiring enhanced egress security and zero trust segmentation for contractor management.
Information Technology/IT
IT services handling client data vulnerable to contractor-based extortion schemes, necessitating robust data loss prevention and anomaly detection for privileged users.
Financial Services
Payroll and compensation data theft creates SEC reporting obligations and regulatory compliance risks, demanding encrypted traffic monitoring and access controls.
Higher Education/Acadamia
Educational institutions using asset management platforms face PII exposure risks from insider threats, requiring multicloud visibility and threat detection capabilities.
Sources
- Data analyst sent to prison for stealing data, extorting employerhttps://www.bleepingcomputer.com/news/security/data-analyst-sent-to-prison-for-stealing-data-extorting-employer/Verified
- Charlotte Man Sentenced for Cyber Extortion Scheme that Targeted International Technology Companyhttps://www.justice.gov/usao-wdnc/pr/charlotte-man-sentenced-cyber-extortion-scheme-targeted-international-technologyVerified
- North Carolina Man Convicted in Cyber Extortion Scheme That Targeted D.C.-based Tech Companyhttps://www.justice.gov/usao-dc/pr/north-carolina-man-convicted-cyber-extortion-scheme-targeted-dc-based-tech-companyVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to exploit existing access, move laterally, and exfiltrate sensitive data, thereby reducing the potential blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to access sensitive data would likely have been constrained, limiting unauthorized data retrieval.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to access data beyond his role's requirements would likely have been constrained, limiting unauthorized data retrieval.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally across systems would likely have been constrained, limiting unauthorized access to multiple systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish control over exfiltrated data would likely have been constrained, limiting unauthorized data management.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely have been constrained, limiting unauthorized data transfer.
The attacker's ability to leverage stolen data for extortion would likely have been constrained, limiting the potential impact of the extortion scheme.
Impact at a Glance
Affected Business Functions
- Human Resources
- Payroll Management
- Corporate Communications
Estimated downtime: N/A
Estimated loss: $7,540
Employee PII including names, dates of birth, home addresses, and compensation information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized data access.
- • Deploy Egress Security & Policy Enforcement to monitor and control data transfers to external devices.
- • Utilize Multicloud Visibility & Control to detect and respond to unauthorized data exfiltration activities.
- • Apply Threat Detection & Anomaly Response to identify and mitigate insider threats in real-time.
- • Establish comprehensive access controls and regular audits to ensure compliance with data protection policies.



