Insider Contractor Steals Data, Extorts Employer for $7,500
Cameron Curry, a tech contractor with privileged access to Brightly Software's systems, exploited that access to steal sensitive corporate and employee data and then attempted to extort the company for millions. This case highlights the critical risk posed by third-party contractors who are granted excessive or poorly monitored access to sensitive systems. Organizations often extend trust to contractors without applying the same rigorous access controls and oversight used for full-time employees. The FBI was able to build a case largely because Curry made operational security mistakes, underscoring that insider threats are often detectable when proper logging and monitoring are in place.
Tactical Insight
Immediate actions
- Audit and revoke all contractor access credentials immediately upon contract termination or suspicion of misconduct.
- Review current contractor permissions to ensure they follow the principle of least privilege, limiting access to only what is strictly necessary for their role.
Long-term improvements
- Implement a formal offboarding process for contractors that includes systematic deprovisioning of all accounts, VPN credentials, and data access.
- Enforce data loss prevention (DLP) controls to detect and block unauthorized bulk downloads or transfers of sensitive corporate and employee data.
- Establish contractual security obligations and background check requirements for all third-party contractors before granting system access.
Detection measures
- Deploy user and entity behavior analytics (UEBA) to flag anomalous access patterns, such as large data transfers or after-hours system access by contractors.
- Maintain comprehensive audit logs of all privileged user activity and review them regularly for signs of data exfiltration or policy violations.
- Set up automated alerts for unusual data movement or access to sensitive employee records by non-employee accounts.