Full Report
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]
Analysis Summary
# Incident Report: Insider Threat Extortion of Brightly Software
## Executive Summary
A former data analyst contractor, Cameron Curry (alias "Loot"), executed a cyber extortion scheme against Brightly Software after his contract was not renewed. Curry exfiltrated sensitive corporate and payroll data, demanding a $2.5 million cryptocurrency ransom to prevent the leak of employee PII and reports to the SEC. The incident resulted in a federal investigation, a small ransom payment by the company for tracking purposes, and the eventual sentencing of the perpetrator to two years in prison.
## Incident Details
- **Discovery Date:** December 11, 2023
- **Incident Date:** December 2023 – January 2024
- **Affected Organization:** Brightly Software (a Siemens company, formerly SchoolDude)
- **Sector:** Technology / SaaS (Asset Management)
- **Geography:** North Carolina, USA
## Timeline of Events
### Initial Access
- **Date/Time:** Prior to December 10, 2023
- **Vector:** Internal Access (Authorized Contractor)
- **Details:** As a data analyst contractor, Curry used his legitimate corporate access to retrieve sensitive payroll and corporate files before his contract expired.
### Lateral Movement
- **Details:** Curry leveraged his existing permissions to navigate to internal databases containing employee PII and compensation data. No unauthorized privilege escalation was explicitly reported, suggesting excessive or unmonitored permissions.
### Data Exfiltration/Impact
- **Details:** Stole sensitive documents including employee names, dates of birth, home addresses, and compensation details. He also claimed to have identified $16 million in "book discrepancies."
### Detection & Response
- **Detection:** December 11, 2023 (One day after contract termination), via an extortion email sent to dozens of employees.
- **Response:** Brightly alerted the FBI; a controlled payment of $7,540 in Bitcoin was made to a wallet controlled by Curry to facilitate tracking.
- **Law Enforcement:** FBI searched Curry's residence on January 24, 2024, seizing electronic evidence.
## Attack Methodology
- **Initial Access:** Valid Contractor Credentials.
- **Persistence:** Not applicable (extortion occurred post-employment).
- **Privilege Escalation:** Likely none; utilized existing data analyst permissions.
- **Defense Evasion:** Use of alias ("Loot") and external encrypted email (Outlook).
- **Credential Access:** Not applicable (utilized legitimate access).
- **Discovery:** Internal reconnaissance of payroll and financial records.
- **Lateral Movement:** Accessing corporate data repositories.
- **Collection:** Gathering PII and financial spreadsheets.
- **Exfiltration:** Transferring data to personal storage prior to contract end.
- **Impact:** Financial extortion ($2.5M demand) and reputational threat (SEC reporting threat).
## Impact Assessment
- **Financial:** $7,540 paid in Bitcoin (recovery status unknown); potential legal and forensic costs.
- **Data Breach:** Compromise of PII for multiple employees (names, DOB, addresses, salaries).
- **Operational:** Disruption due to mass extortion emails sent to "dozens" of staff members.
- **Reputational:** Threat of SEC reporting and public dissemination of internal financial discrepancies.
## Indicators of Compromise
- **Network indicators:** lootsoftware@outlook[.]com
- **File indicators:** Screenshots of internal payroll spreadsheets.
- **Behavioral indicators:** Large data downloads by a contractor nearing the end of their contract period.
## Response Actions
- **Containment:** Coordination with law enforcement to identify the source of the emails.
- **Eradication:** Termination of all legacy access (though the breach occurred while access was active).
- **Recovery:** Prosecution of the offender and seizure of devices by the FBI.
## Lessons Learned
- **Key Takeaway:** Insider threats are particularly dangerous during "offboarding" periods or when a contract is non-renewed.
- **Visibility Gaps:** The company lacked sufficient file integrity monitoring or data loss prevention (DLP) alerts to flag a contractor downloading sensitive payroll data.
## Recommendations
- **Implement DLP:** Deploy Data Loss Prevention tools to alert on bulk downloads of sensitive PII or financial data, especially by contractors.
- **Least Privilege:** Ensure data analysts only have access to the specific datasets required for their tasks, excluding sensitive payroll/HR information unless necessary.
- **Offboarding Protocols:** Implement "High-Risk" monitoring for employees/contractors during their final 30 days of service.
- **Zero Trust:** Apply strict access controls and session logging for users interacting with sensitive corporate databases.