When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume.

But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion.

And this week, he learnt that that wasn't the best idea he had ever had - as he was sentenced to 24 months in a federal prison, after being convicted on six counts of transmitting interstate communications with intent to extort.

Curry was hired as a data analyst by Brightly Software, a technology firm that was acquired by Siemens in 2022. The role gave Curry legitimate access to sensitive company information, corporate records, and the personal and payroll data of employees.

At his trial evidence was presented that Curry misused his privileged access to steal sensitive corporate records, which he was able to exploit when he learnt his contract would not be renewed.

Curry adopted an online identity, "Loot", and sent more than 60 emails to his fellow employees and executives between December 2023 and January 2024, threatening to publish sensitive information unless he received a cryptocurrency payment worth US $2.5 million.

"Loot" threatened to increase his demand by US $100,000 for every month his former employer refused to pay, and increased pressure on the firm by attaching screenshots of spreadsheets that listed employees' names, their home addresses, dates of birth, and salary information.

He further threatened to report Brightly to the SEC for failing to disclose that it had suffered a data breach, and threatened to expose pay disparities acros the workforce.

Unfortunately for Curry, he had left a trail that pointed investigators towards him. Metadata in the emails he had sent, and user information linked to the lootsoftware@outlook.com email account gave the FBI good reason to execute a search warrant at his property on January 24, 2024, seizing computer equipment.

The fact that he had asked for the ransom payment to be made to a Coinbase account, linked to debit cards belonging to his mother and sister, suggest that Curry should have stuck to a life analysing data rather than committing cybercrime.

A subsequent digital forensic analysis confirmed that Curry was the person behing the mysterious "Loot" alias.

Too many organisations underestimate the threat posed by disgruntled insiders. An internal attacker doesn't have to spend months probing a company's defences. Trusted contractors and employees are given legitimate credentials to access precisely the same data that can later be weaponised.

Instead of hacking skills, Curry just needed opportunity, a grudge, and an unhealthy serving of poor judgement.

The lesson for businesses from incidents like this is clear. When a contractor or employee's time with the business comes to an end, their access to its systems should be revoked immediately. Because the moment that someone realises they may be on their way out is when their access to sensitive data should be examined most closely.

For that reason, the risk is highest at the moment of departure - resignations, redundancies, or in this case, a contract not being renewed.

Insider threats are consistently underreported by businesses, often because they are too embarrassed to admit that a once-trusted employee has caused damage. But that doesn't mean that they cannot cause significant disruption to the running of a company or damage to a firm's reputation.

In addition to a 24 month prison sentence, Curry has been ordered to serve one year of supervised release, and hand over US $7,540.92 (the exact Bitcoin ransom amount Brightly had paid him before his arrest) - quite a lot less than the US $2.5 million he had been hoping to pocket.

tags