Full Report
Cameron Curry stole corporate data and employee information, which he used to threaten the company as his six-month contract gig came to a close. He ultimately extorted the company for $7,540.92. The post Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack appeared first on CyberScoop.
Analysis Summary
# Incident Report: Insider Threat and Extortion of Brightly Software
## Executive Summary
A contract data analyst, Cameron Nicholas Curry (alias “Loot”), abused his authorized access to steal sensitive corporate data and employee personally identifiable information (PII). Following the conclusion of his contract, Curry attempted to extort the company for approximately $2.5 million by threatening to leak payroll and compensation data. The incident resulted in a small ransom payment and the eventual conviction and two-year prison sentencing of the perpetrator.
## Incident Details
- **Discovery Date:** December 14, 2023
- **Incident Date:** August 2023 – January 2024
- **Affected Organization:** Brightly Software (a Siemens subsidiary)
- **Sector:** Asset and Maintenance Management Software / Technology
- **Geography:** Cary, North Carolina, USA
## Timeline of Events
### Initial Access
- **Date/Time:** August 2023
- **Vector:** Authorized Insider Access
- **Details:** Curry was hired as a contractor via a third-party recruitment agency and provided a company-owned laptop with legitimate credentials to the corporate network.
### Lateral Movement
- Curry utilized his legitimate permissions as a data analyst to browse and access sensitive HR and payroll directories not strictly necessary for his immediate tasks.
### Data Exfiltration/Impact
- **August – December 2023:** While still employed, Curry removed corporate data, including spreadsheets containing employee PII, salary information, and bonus structures.
- **December 2023:** Immediately following his last day of employment, Curry began an extortion campaign.
### Detection & Response
- **December 14, 2023:** Brightly Software notified the FBI after receiving threatening emails.
- **January 2024:** The company paid a "nuisance" ransom of $7,540.92 (less than 1% of the initial demand) to facilitate the investigation.
- **Early 2024:** FBI identified Curry via Coinbase account records and executed search warrants on his residence and vehicle.
## Attack Methodology
- **Initial Access:** Valid contractor credentials and company-issued hardware.
- **Persistence:** Not applicable; the attacker relied on data exfiltrated during his period of authorized access.
- **Privilege Escalation:** Likely "policy violation" access (using standard privileges to access sensitive files that lacked sufficient internal restrictions).
- **Defense Evasion:** Attempted to anonymize communications via 60+ extortion emails; however, failed to secure financial endpoints (Coinbase).
- **Credential Access:** Authorized use of own credentials.
- **Discovery:** Searched for sensitive compensation spreadsheets and payroll data.
- **Lateral Movement:** Accessed file shares and databases within the scope of the corporate network.
- **Collection:** Gathering spreadsheets listing PII and compensation details.
- **Exfiltration:** Transferring data from a company-owned laptop to personal storage/cloud before his contract ended.
- **Impact:** Extortion, reputational risk regarding pay equity, and unauthorized disclosure of employee PII.
## Impact Assessment
- **Financial:** $7,540.92 ransom paid; additional undisclosed costs for legal counsel, forensics, and incident response.
- **Data Breach:** Compromise of employee PII and highly sensitive compensation/payroll data.
- **Operational:** Limited; the attack targeted data confidentiality rather than system availability.
- **Reputational:** Potential internal friction due to the attacker’s claims of pay inequity and threats to notify the SEC.
## Indicators of Compromise
- **Network indicators:** Multiple extortion emails sent to executives and employees from external accounts.
- **File indicators:** Screenshots of internal payroll spreadsheets attached to extortion emails.
- **Behavioral indicators:** Unusual data access patterns by a contractor nearing the end of their contract term.
## Response Actions
- **Containment:** Termination of all network access at the end of the contract (though exfiltration had already occurred).
- **Eradication:** FBI seizure of Curry’s digital devices and deletion of stolen data.
- **Recovery:** Cooperation with law enforcement to identify the perpetrator and pursue criminal charges.
## Lessons Learned
- **Contractor Over-Privileging:** A contractor had excessive access to sensitive HR/Payroll data that was irrelevant to his role as a data analyst.
- **Offboarding Gaps:** While technical access was cut off after his contract, the data had been exfiltrated slowly over the preceding months without triggering alerts.
- **OPSEC Failures:** The attacker was quickly identified because he linked a ransom-collection account to personal debit cards belonging to family members.
## Recommendations
- **Principle of Least Privilege (PoLP):** Restrict access to sensitive HR and payroll folders to only essential personnel; contractors should not have broad access to PII.
- **Data Loss Prevention (DLP):** Implement DLP tools to monitor and block the transfer of large spreadsheets or files containing PII to external drives or personal cloud storage.
- **User and Entity Behavior Analytics (UEBA):** Deploy monitoring to flag "lame duck" behavior—increased data downloading or unusual file access by employees/contractors nearing a termination or contract end date.
- **Third-Party Risk Management:** Vet the access levels provided to recruitment agency contractors more rigorously.