Independent consumer resource. Always free, no sign up.
Text size: Family alerts
The Scam Exposed
Share
Elder Safety

He demanded $2.5 million in crypto. Then the FBI came

· · Updated · 4 min read
He demanded $2.5 million in crypto. Then the FBI came

Cameron Curry, 27, used access from a data analyst job to take sensitive company information and threaten to expose it unless he received $2.5 million in cryptocurrency. He now has a 24-month federal prison sentence.

The Charlotte, North Carolina, man was also ordered to serve one year of supervised release and pay a $7,540.92 money judgment. The case shows how a trusted worker with access to private records can turn that access into an extortion threat.

How the scheme started

Curry worked as a contract data analyst for about six months at a D.C.-based international technology company. His job gave him access to company data, personnel information, and other sensitive corporate records.

The case changed after Curry learned that his contract would not be renewed. According to trial evidence, he misused information he had accessed through his work and used it as leverage against the company.

This was not a typical outside hacking attack. The access came from inside the company, which made the incident harder to separate from normal business activity.

Curry used the name “Loot”

Between December 11, 2023, and January 24, 2024, Curry sent more than 60 emails to company employees and executives while identifying himself online as “Loot.”

The emails threatened to expose sensitive corporate information and employee data, including personally identifiable information. Curry demanded $2.5 million in cryptocurrency and threatened further public disclosure if the company did not pay.

The threats were aimed at more than money. The messages also warned that the company could suffer reputational damage if the information was made public.

The FBI traced the person behind the alias

Using an online alias did not keep Curry hidden.

On January 24, 2024, the FBI executed a search warrant at his residence and seized electronic devices. A forensic review of the evidence connected Curry to the “Loot” identity and the extortion campaign.

Earlier court records also showed that investigators used digital evidence connected to the emails and cryptocurrency wallet to identify the person behind the threats.

That is an important warning for anyone who thinks a fake name or cryptocurrency payment address automatically provides anonymity.

The case ended with a federal conviction

In March 2026, a federal jury convicted Curry on six counts involving interstate communications made with the intent to extort the victim company. At that stage, he faced up to two years in prison on each count.

The later sentencing resulted in 24 months in federal prison, followed by one year of supervised release. Curry was also ordered to pay a $7,540.92 money judgment.

The punishment is far removed from the $2.5 million he demanded.

What companies can take from this case

The biggest lesson is that data protection cannot stop at the network perimeter. A worker may already have legitimate access to sensitive information, so companies also need controls around what that person can access, copy, and retain.

Offboarding also matters before the final day arrives. When a contract is ending, access to sensitive records should be reviewed rather than assuming everything will remain normal until the account is finally disabled.

Companies can reduce this type of risk by:

  • Limit sensitive access: Give workers access only to the records they need for their job.

  • Watch unusual data activity: Large downloads, unusual searches, or sudden access to personnel files can deserve review.

  • Review departing workers: Increase attention to sensitive access when an employee or contractor is leaving.

  • Preserve evidence: Keep relevant logs and records so investigators can trace suspicious activity if a problem appears.

These controls have a cost. More monitoring can create extra work for security teams and may flag legitimate activity, so companies need clear rules for deciding what deserves investigation.

Why this case matters

Curry's case is a reminder that insider threats do not always look like sophisticated hacking. Sometimes the person already has the keys.

The sensitive information in this case was reportedly accessed through Curry's work. The alleged payoff came from threatening to expose that information. That combination can create serious risks for both a company and the employees whose personal information is stored inside it.

The FBI investigation and federal prosecution also show why companies facing data extortion should not assume that paying a demand will make the problem disappear. Reporting the incident and preserving evidence can give investigators a path to identify the person responsible.

The Scam Exposed will continue tracking cases like this because scam and cybercrime warnings are most useful when they show how a scheme worked, what made it possible, and where the warning signs appeared.

Source: U.S. Department of Justice, U.S. Attorney’s Offices for the District of Columbia and Western District of North Carolina. U.S. Department of Justice case report

Related reading

What Do You Think?

No one has commented yet. If this happened to you as well, say so below. Knowing that other people had the same call makes it far easier for the next person to trust their instincts.

Add Your Comment

Every comment is read by a person before it appears, so it will not show up straight away. Never post your phone number, address, or bank details here.

This one question keeps the automatic spam out.

You're Safe Here. Let's Fix This Now.

If you already sent money or shared information, act fast. Follow these steps in order.

1

Call Your Bank or Card Company Immediately

Use the number on the back of your card, not any number the caller gave you. Ask them to freeze the transaction or account.

2

Call the National Elder Fraud Hotline

Free help, 7 days a week.

Call 1-833-372-8311
3

Report It to the Government

File a free report at the Federal Trade Commission so they can investigate.

Go to reportfraud.ftc.gov