The Scam Exposed

Data Analyst's Cyber Extortion Scheme Ends in Prison

· Published · Updated · 5 min read
Data Analyst's Cyber Extortion Scheme Ends in Prison

Cameron Curry, 27, used access from a data analyst job to run a cyber extortion scheme, taking sensitive company information and threatening to expose it unless he received $2.5 million in cryptocurrency. He now has a 24-month federal prison sentence.

The Charlotte, North Carolina, man was also ordered to serve one year of supervised release and pay a $7,540.92 money judgment. The case shows how a trusted worker with access to private records can turn that access into an extortion threat.

Key takeaways

  • Cameron Curry, a contract data analyst, used legitimate work access to threaten a company with exposing sensitive records unless he was paid $2.5 million in cryptocurrency.
  • He got a 24 month federal prison sentence, a year of supervised release, and a $7,540.92 money judgment.
  • The threats came from inside the company after his contract was not renewed, not from an outside hacker, which is why it took longer to separate from normal business activity.
  • Federal investigators say paying an extortion demand does not make the problem go away, reporting it and preserving evidence gives them an actual path to the person responsible.

How the Scheme Started

Curry worked as a contract data analyst for about six months at a D.C.-based international technology company. His job gave him access to company data, personnel information, and other sensitive corporate records.

The case changed after Curry learned that his contract would not be renewed. According to trial evidence, he misused information he had accessed through his work and used it as leverage against the company, turning routine access into a full cyber extortion scheme.

This was not a typical outside hacking attack. The access came from inside the company, which made the incident harder to separate from normal business activity.

Curry Used the Name "Loot"

Between December 11, 2023, and January 24, 2024, Curry sent more than 60 emails to company employees and executives while identifying himself online as "Loot."

The emails threatened to expose sensitive corporate information and employee data, including personally identifiable information. Curry demanded $2.5 million in cryptocurrency and threatened further public disclosure if the company did not pay.

The threats were aimed at more than money. The messages also warned that the company could suffer reputational damage if the information was made public.

The FBI Traced the Person Behind the Alias

Using an online alias did not keep Curry hidden.

On January 24, 2024, the FBI executed a search warrant at his residence and seized electronic devices. A forensic review of the evidence connected Curry to the "Loot" identity and the extortion campaign.

Earlier court records also showed that investigators used digital evidence connected to the emails and cryptocurrency wallet to identify the person behind the threats.

That is an important warning for anyone who thinks a fake name or cryptocurrency payment address automatically provides anonymity in a cyber extortion scheme.

The Case Ended With a Federal Conviction

In March 2026, a federal jury convicted Curry on six counts involving interstate communications made with the intent to extort the victim company. At that stage, he faced up to two years in prison on each count.

The later sentencing resulted in 24 months in federal prison, followed by one year of supervised release. Curry was also ordered to pay a $7,540.92 money judgment.

The punishment is far removed from the $2.5 million he demanded.

What Companies Can Take From This Case

The biggest lesson is that data protection cannot stop at the network perimeter. A worker may already have legitimate access to sensitive information, so companies also need controls around what that person can access, copy, and retain.

Offboarding also matters before the final day arrives. When a contract is ending, access to sensitive records should be reviewed rather than assuming everything will remain normal until the account is finally disabled.

Companies can reduce the risk of a cyber extortion scheme by:

Limit sensitive access: Give workers access only to the records they need for their job.

Watch unusual data activity: Large downloads, unusual searches, or sudden access to personnel files can deserve review.

Review departing workers: Increase attention to sensitive access when an employee or contractor is leaving.

Preserve evidence: Keep relevant logs and records so investigators can trace suspicious activity if a problem appears.

These controls have a cost. More monitoring can create extra work for security teams and may flag legitimate activity, so companies need clear rules for deciding what deserves investigation.

Why This Case Matters

Curry's case is a reminder that insider threats do not always look like sophisticated hacking. Sometimes the person already has the keys.

The sensitive information in this case was reportedly accessed through Curry's work. The alleged payoff came from threatening to expose that information. That combination can create serious risks for both a company and the employees whose personal information is stored inside it.

The FBI investigation and federal prosecution also show why companies facing a cyber extortion scheme should not assume that paying a demand will make the problem disappear. Reporting the incident and preserving evidence can give investigators a path to identify the person responsible.

Cases like this are worth tracking because they show how a scheme actually worked, what made it possible, and where the warning signs were, which is more useful than a generic warning.

Source: U.S. Department of Justice, U.S. Attorney's Offices for the District of Columbia and Western District of North Carolina. U.S. Department of Justice case report

What Do You Think?

No one has commented yet. If this happened to you as well, say so below. Knowing that other people had the same call makes it far easier for the next person to trust their instincts.

Add Your Comment

Every comment is read by a person before it appears, so it will not show up straight away. Never post your phone number, address, or bank details here.

This one question keeps the automatic spam out.

You're Safe Here. Let's Fix This Now.

If you already sent money or shared information, act fast. Follow these steps in order.

1

Call Your Bank or Card Company Immediately

Use the number on the back of your card, not any number the caller gave you. Ask them to freeze the transaction or account.

2

Call the National Elder Fraud Hotline

Free help, Monday to Friday, 10:00 a.m. to 6:00 p.m. Eastern Time.

Call 1-833-372-8311
3

Report It to the Government

File a free report at the Federal Trade Commission so they can investigate.

Go to reportfraud.ftc.gov