Contractor jailed for two years after trying to extort the company that hired him

Cameron Curry, 27, has been sentenced to two years in prison and one year of supervised release. A jury convicted him on six counts of transmitting interstate communications with intent to extort. According to the prosecutors' press release he had spent around six months as a contractor at an international technology company based in Washington, D.C., and during that period he had access to personnel files and other sensitive corporate information. After learning that his contract would not be renewed, he sent more than 60 emails to employees and executives under the alias Loot, between December 2023 and January 2024. The messages threatened to publish company records and employees' personal information unless a demand for 2.5 million dollars in cryptocurrency was paid.

What happens technically

It is worth establishing what did not happen here. No vulnerability was exploited and no barrier was broken. What was misused was the access he had already been granted as part of the engagement, to personnel files and to other sensitive corporate information. This is precisely what makes insider cases hard to detect. The actions look like work right up until something else exposes them, and here the exposure came from outside, in the form of more than 60 emails to employees and executives. The press release does not say whether any documents were in fact taken out of the company systems.

The alias is the second part of the mechanism. Curry used the name Loot, and an alias holds only for as long as nobody can tie it to a person. The FBI seized electronic devices from his home in January 2024, and prosecutors state that forensic analysis of those devices connected him to the Loot identity and to the extortion. Which traces the analysis rested on, the press release does not say. As a general matter an alias rarely lives entirely on its own, because it usually shares a machine, a network connection, working hours or a way of writing with the person behind it, and a seized machine makes such connections far easier to document in court. How much of that applied in this case is not known. The charges concerned an attempt, and the source does not say that the company paid.

What this means for you if you control contractor access

If you use contractors, this case is about how an engagement ends, not about intrusion. Berigo assesses that the risk rises the moment the news that an engagement will not be renewed goes out, and that this is often the one event nobody has defined as a security event. Do you know who receives that news first, and what happens to the access rights the same day? In many organisations access simply stays in place until somebody remembers to ask for its removal, and the person who has to ask is often the one who just delivered the news.

You should also look at what the contractor could actually read. Here it was personnel files, and the threat concerned employees' personal information. That makes this a data protection matter as much as a security matter, and under the GDPR it is you as controller who has to explain why a contractor had access to that kind of information at all. Berigo assesses that the question of what a person could have taken with them is far easier to answer before an engagement starts than after it has ended. Under NIS2 article 21 both access control and supplier related risk belong to what has to be documented.

Berigo recommends

  • Write down which systems and folders each contractor is to have access to, before the engagement begins.
  • Make the end of an engagement a defined event, with a deadline for when the access rights are gone.
  • Coordinate the news that an engagement will not be renewed with the removal of access, so the order is agreed in advance.
  • Log access to personnel files and other collections of personal data, and keep those logs long enough for them to be useful.
  • Decide in advance who handles a payment demand and who contacts the police, so the choice is not made under pressure.

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch