Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Data analyst tried to extort his former employer for $2.5 million

0
Medium
Published: 08/20/2026 (08/20/2026, 12:43:40 UTC)
Source: Reddit Cybersecurity

Description

A former data analyst at Brightly Software, Cameron Curry, misused his legitimate access to sensitive employee and corporate data to extort his employer for $2.5 million in cryptocurrency. After learning his contract would not be renewed, he exfiltrated personal identifiable information (PII), payroll data, and internal records, then sent threatening emails under a fake identity demanding ransom. He was caught due to operational security mistakes linking the ransom payments to family members' debit cards. Curry was sentenced to 24 months in federal prison and ordered to repay the partial ransom amount already paid. This case highlights the insider threat risk during employee offboarding and the importance of timely access revocation.

Reddit Discussion

r/cybersecurity·posted by u/Syncplify
00

Guy named Cameron Curry was a data analyst at Brightly Software (acquired by Siemens). When he found out his contract wasn't getting renewed, instead of just updating his resume like a normal person, he used his access to pull employee PII, payroll data, and internal records before he lost access, then spent weeks emailing execs under a fake identity threatening to leak everything unless he got paid in crypto.

He got caught because he used his mom's and sister's debit cards linked to the Coinbase wallet he wanted the ransom sent to. 24 months in federal prison, plus he has to hand back the $7,500 they'd already paid him.

Barely any "hacking" involved though. He already had legitimate access. No exploit, no phishing, just someone who was already trusted deciding to weaponize it on the way out the door.

Feels like most companies are way more focused on external threats than what happens in that window between "someone knows they're leaving" and "their access actually gets revoked." Anyone dealt with something like this, or work somewhere that actually handles offboarding well?

Source.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 12:52:16 UTC

Technical Analysis

Cameron Curry, a data analyst at Brightly Software (acquired by Siemens), exploited his legitimate access to sensitive employee and corporate data after learning his contract would not be renewed. He exfiltrated PII, payroll, and internal records, then sent over 60 extortion emails under the alias "Loot" demanding $2.5 million in cryptocurrency, threatening to leak data and report the company to the SEC. Investigators traced the extortion to Curry through email metadata and links to Coinbase accounts connected to his family. He was convicted on six counts of transmitting interstate communications with intent to extort and sentenced to 24 months in federal prison plus supervised release and restitution. The incident underscores the risk of insider threats during the window between notification of termination and access revocation.

Potential Impact

The impact was primarily reputational and operational for Brightly Software, involving exposure of sensitive employee PII and payroll data. The extortion attempt could have led to significant financial loss if the ransom had been paid in full. The incident demonstrates the risk posed by trusted insiders with legitimate access who misuse data before losing access. No external hacking or exploitation was involved, but the insider's actions caused legal and financial consequences for both the individual and the company.

Defensive Guidance

The key mitigation is immediate revocation of access rights upon notification of contract non-renewal or termination to prevent data exfiltration by disgruntled insiders. Organizations should implement strict offboarding procedures that include disabling credentials and monitoring for unusual data access during the employee exit window. Since this incident involved no technical exploit, focusing on access control and insider threat detection is critical. No patch or technical fix applies. Awareness and training on insider threat risks and rapid response to suspicious activity are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a86f874acd9273b499fe8f1

Added to database: 08/20/2026, 12:52:04 UTC

Last enriched: 08/20/2026, 12:52:16 UTC

Last updated: 08/20/2026, 14:51:58 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses