A data analyst was told his contract would not be renewed. His logins still worked. According to security writer Graham Cluley, he used them to take employee payroll and personal records, adopted the online name "Loot," and demanded a cryptocurrency payment worth $2.5 million. He is now serving a sentence in federal prison.
The crime is not the interesting part. The gap is. The company had already decided this person was leaving, and his access was still switched on. That gap exists in most small and mid-sized businesses right now, and it costs nothing to close.
What happened
Every detail and figure below comes from Graham Cluley, writing on August 19, 2026 — an award-winning security researcher who has covered this industry since the early 1990s.
Cameron Curry, 27, of Charlotte, North Carolina, was hired as a data analyst by a software company. The job gave him legitimate access to corporate records and to the personal and payroll data of employees — the ordinary, boring access a data analyst needs to do the work.
Then he learned his contract would not be renewed. Cluley reports that Curry used that same access to copy sensitive records on his way out, and then went to work on his former employer:
- He created an online identity, "Loot," and sent more than 60 emails to employees and executives between December 2023 and January 2024.
- He threatened to publish the stolen information unless he was paid a cryptocurrency payment worth $2.5 million.
- He promised to raise the demand by $100,000 for every month the company refused.
- To prove he had the files, he attached screenshots of spreadsheets listing employees' names, home addresses, dates of birth and salaries.
- He also threatened to report the company to the Securities and Exchange Commission for failing to disclose a data breach, and to publish what the pay data showed about gaps between employees.
It did not hold up. Cluley writes that metadata in the emails, plus the account details behind the address "Loot" was sending from, gave the FBI enough to search Curry's property on January 24, 2024 and seize his computers. He had asked for payment to a Coinbase account linked to debit cards belonging to his mother and sister.
Curry was convicted on six counts of transmitting interstate communications with intent to extort. Per Cluley, he was sentenced to 24 months in federal prison and one year of supervised release, and ordered to hand over $7,540.92 — the exact amount of Bitcoin his former employer had already paid him before the arrest.
Nobody was hacked
There is no clever technical trick in this story. No stolen password, no phishing email, no software flaw. This is what security people call an insider threat — damage done by someone who was given the keys on purpose, because the job required it.
That is why it should get a business owner's attention. An outside attacker spends weeks finding a way in. A trusted contractor is handed a working login on day one and pointed at the payroll folder. As Cluley puts it, the risk peaks at the moment of departure — a resignation, a layoff, or in this case a contract that is not being renewed.
The trigger is not the last day on the calendar. It is the day the person finds out.
Why this matters to a business like yours
You do not need to be a large company to have this exposure. In a small business it is usually worse, for three reasons.
One person usually holds everything. The office manager who set up the accounting software, the freelance developer who built the website, the bookkeeper with banking access. In a large company those are separate people with separate permissions. In a ten-person company they are often one login shared by three people.
The file that hurts is the HR file, not the product file. Notice what Curry used as leverage: names, home addresses, birth dates, salaries. That data is about your people, and it creates a legal disclosure question, an angry-staff question and a reputation question at once — which is why it makes such effective pressure. Your ERP, CRM or payroll system holds the same kind of records.
Paying does not necessarily end it. Cluley reports that the company had paid $7,540.92 in Bitcoin before the arrest — a tiny fraction of the demand — and the matter still ended with an FBI search warrant. The schedule of $100,000 monthly increases shows why: someone who gets paid once has learned that the demand works.
Where leftover access hides
Most businesses treat offboarding as finished once the email account is shut off. Email is often the only thing that gets shut off. Here is where access survives a departure:
- Business systems with their own logins. Accounting, payroll, inventory, your ERP or CRM — bought at different times, each with its own password that nobody tracks in one place.
- Shared accounts. "office@", "admin@", the front-desk computer everyone signs into. Nobody owns them, so nobody changes them.
- Tools bought on a company card. The website host, the online store, the ad accounts, the e-signature service — often set up in a departing employee's personal name.
- Remote access. VPN, remote desktop, the camera system, building keycards and door codes.
- Synced copies. Company files still sitting in a personal cloud folder, on a home laptop, or on a phone that was never wiped.
- Password recovery paths. Their personal cell number or private email address still listed as the way to reset an account. Removing the login and leaving the reset path open changes nothing.
- Connections they built. Automations, integrations and API keys created under their own account, which keep running long after the person is gone.
What to do about it
None of this requires a security department or new software. It requires a list and a rule.
- Write down what each role can open. One page per role: contractor, bookkeeper, office manager, agency. If you cannot answer "what can this contractor reach?" in five minutes, that is the first job — and it is one afternoon's work.
- Make the decision day the access day. The moment you decide not to renew or to let someone go, set the cutoff. Cluley's own conclusion: access should end immediately when the relationship does, and be watched most closely from the moment the person realizes they may be on the way out.
- Cut at the source first. Disable the main identity account — the Microsoft 365 or Google Workspace login — because every tool that signs in through it goes dark at the same time. Then work down your list for anything with its own separate password.
- Change every shared password they knew. A password known by a former contractor is not a password anymore.
- Strip the recovery routes. Remove their phone number, personal email, authentication app and any administrator role. This is the step most businesses miss.
- Preserve, do not delete. Turn the mailbox into an archived or shared mailbox instead of erasing it. Email metadata is what identified the person in this case; deleted evidence only helps the other side.
- Watch for bulk exports. Ask whoever manages your systems to alert you when someone downloads an unusually large batch of HR, payroll or customer records. One person exporting the whole employee list is the signal worth catching.
- Limit standing access before you need to. Payroll and personnel files should be reachable by the handful of people whose work requires them, not by everyone who has an account. Ask for the report, not permanent access to the folder.
- Put it in the contract. Contractor agreements should say plainly that access ends on notice and that company data must be returned or destroyed. It costs one paragraph.
If someone does threaten you
Extortion messages are written to make you decide alone, immediately, and quietly. You do not have to.
- Do not quietly pay. A payment was made in this case and it did not end the matter.
- Keep everything. Save the emails in full, including the technical headers, and keep your system logs. That is the material investigators work from.
- Report it. In the United States, the FBI accepts reports of this kind at ic3.gov.
- Call your attorney before you answer. Curry's threat to report his employer to regulators for not disclosing a breach was built out of the company's own reporting duties. Know what yours are before you respond to anyone.
The rule worth keeping
Cut access the day you decide someone is leaving, not the day they go.
Every system in your business exists because somebody needed to get into it. Offboarding is the other half of that sentence, and the half that rarely gets written down. A list of what each role can open, and a rule about when it closes, would have made this story impossible.
More plain-language explanations of how AI and business systems help and hurt are in the AIWAS knowledge base, and short briefings are on X at @AIWASai.