Executive Summary

In December 2023, Cameron Curry, a former data analyst contractor for Brightly Software, exploited his access to the company's payroll and corporate data to steal sensitive employee information. After his contract ended, Curry initiated an extortion scheme, sending over 60 emails to Brightly employees between December 11, 2023, and January 24, 2024, demanding a $2.5 million ransom in cryptocurrency. He threatened to release the stolen data and report the company to the SEC for failing to disclose the breach. Brightly paid $7,540 in Bitcoin before involving law enforcement. The FBI's investigation led to Curry's conviction in March 2026 on six counts of cyber extortion, resulting in a two-year prison sentence. This incident underscores the significant risks posed by insider threats, especially when individuals with authorized access misuse their privileges. Organizations must implement robust access controls, continuous monitoring, and employee training to mitigate such risks. The case also highlights the importance of swift incident response and collaboration with law enforcement to address cyber extortion attempts effectively.

Why This Matters Now

The rise in insider threats, as demonstrated by this case, emphasizes the urgent need for organizations to strengthen internal security measures and foster a culture of cybersecurity awareness to prevent similar incidents.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Organizations can implement strict access controls, conduct regular security audits, provide employee cybersecurity training, and establish clear policies to detect and prevent insider threats.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to exploit existing access, move laterally, and exfiltrate sensitive data, thereby reducing the potential blast radius.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to access sensitive data would likely have been constrained, limiting unauthorized data retrieval.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to access data beyond his role's requirements would likely have been constrained, limiting unauthorized data retrieval.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally across systems would likely have been constrained, limiting unauthorized access to multiple systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish control over exfiltrated data would likely have been constrained, limiting unauthorized data management.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data would likely have been constrained, limiting unauthorized data transfer.

Impact (Mitigations)

The attacker's ability to leverage stolen data for extortion would likely have been constrained, limiting the potential impact of the extortion scheme.

Impact at a Glance

Affected Business Functions

  • Human Resources
  • Payroll Management
  • Corporate Communications
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $7,540

Data Exposure

Employee PII including names, dates of birth, home addresses, and compensation information.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized data access.
  • Deploy Egress Security & Policy Enforcement to monitor and control data transfers to external devices.
  • Utilize Multicloud Visibility & Control to detect and respond to unauthorized data exfiltration activities.
  • Apply Threat Detection & Anomaly Response to identify and mitigate insider threats in real-time.
  • Establish comprehensive access controls and regular audits to ensure compliance with data protection policies.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image