A former data analyst contractor at Brightly Software has been sentenced to two years in prison for orchestrating a $2.5 million cyber extortion scheme targeting his former employer.
Brightly Software is a software-as-a-service (SaaS) company formerly known as SchoolDude. Siemens acquired the company in August 2022. Brightly employs more than 700 people and provides asset management and maintenance software to over 12,000 customers worldwide.
Cameron Curry, a 27-year-old North Carolina resident who used the alias “The Predator,” was convicted in March for carrying out what prosecutors described as a “massive cyber extortion scheme” against Brightly.
According to court documents, Curry accessed Brightly’s payroll systems and corporate data before stealing confidential files. He allegedly used the information to blackmail the company after learning that his six-month contract would not be renewed.
One day after his contract ended on December 10, 2023, Curry began emailing Brightly employees. Between December 11, 2023, and January 24, 2024, he reportedly used the alias “Loot” and the email address [email protected] to demand a $2.5 million cryptocurrency ransom in exchange for not publishing the stolen information.
“Starting January 1, 2024, we will begin the process of gradually distributing payroll information to all employees, and any failure to report violations will then be reported to the SEC,” Curry wrote in one extortion email.
“If you want to recover your data, we recommend that you do so quickly for $2.5 million to protect your company and stock, with an increase of $100,000 each month thereafter. Bookkeeping discrepancies are now over $16 million, creating potential risks such as retention issues, hostile work environments, and grudges,” the message continued.

The emails included screenshots containing personally identifiable information (PII), such as employees’ names, dates of birth, home addresses, and compensation details. Curry also threatened to report Brightly to the U.S. Securities and Exchange Commission (SEC), claiming the company had failed to disclose alleged violations.
After receiving multiple extortion emails, Brightly paid $7,540 in Bitcoin. The cryptocurrency was transferred to a wallet controlled by Curry.
Brightly reported the incident to law enforcement. On January 24, the FBI searched Curry’s residence and seized several electronic devices that allegedly contained evidence connecting him to the cyber extortion operation.
“We are aware that the U.S. Department of Justice (DOJ) has convicted Cameron Curry of racketeering charges,” Brightly told BleepingComputer in March.
“We are cooperating fully with the FBI and the Department of Justice on this matter and appreciate their investigative efforts. Given these proceedings are pending, we defer all questions to law enforcement authorities,” the company added.
Brightly disclosed a separate data breach in May 2023 that was unrelated to Curry’s extortion case. In that incident, attackers reportedly stole the credentials and personal information of nearly 3 million customers and users from the SchoolDude online platform, including names, email addresses, account passwords, and phone numbers.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




