A contractor at Brightly Software (owned by Siemens) used his legitimate access to steal sensitive employee and corporate data, then tried to extort the company for $2.5 million. Using the alias “Loot,” he sent dozens of threatening emails and attached screenshots of payroll-style spreadsheets to prove he had the data, demanding payment in cryptocurrency.
How the Attack Unfolded
A data analyst working as a contractor at Brightly Software, owned by Siemens, learned that his contract would not be renewed. Rather than simply departing, he used his legitimate access to copy sensitive corporate records, including employee payroll data containing names, home addresses, dates of birth, and salary information. He then adopted an online alias, "Loot," and began an extortion campaign against the company.
Over several weeks between December 2023 and January 2024, he sent more than 60 emails to employees and executives demanding a cryptocurrency payment of $2.5 million. To prove he had real data, he attached screenshots of the stolen spreadsheets directly to his messages. He escalated pressure by threatening to increase the ransom by $100,000 every month the demand went unpaid, and by threatening to report the company to the SEC over an alleged undisclosed breach and to expose internal pay disparities.
Why This Attack Succeeded
This was not a technical hacking exercise. It succeeded because the attacker already had authorized access to the systems and data he later weaponized. The exploitation happened at the human and process level rather than through malware or a compromised credential. Because the access existed before the contract ended, the theft could occur before anyone thought to revisit or restrict his permissions.
The extortion emails themselves relied on classic social engineering pressure: urgency created by escalating financial demands, credibility created by attached proof, and coercion amplified by threats of regulatory exposure and reputational damage.
Red Flags to Watch For
- Unsolicited demands for payment in cryptocurrency
- Threats of public disclosure or regulatory reporting used to manufacture urgency
- Screenshots or samples of sensitive internal data sent as "proof" of compromise
- Repeated contact from an anonymous or unfamiliar identity targeting multiple employees or executives at once
Building Organizational Resistance
Extortion attempts like this should be treated immediately as a security incident rather than a negotiation. Employees and executives who receive such emails should avoid engaging with the sender, preserve all evidence, and escalate directly to security and legal teams.
Insider risk is often highest during offboarding. Access to sensitive systems and data should be revoked as soon as a departure, whether voluntary or involuntary, becomes known, and unusual access patterns should be monitored closely from that point forward.
Finally, training for executives, HR, finance, and legal teams should specifically cover coercion tactics such as escalating deadlines, cryptocurrency payment demands, and threats of regulatory exposure, since recognizing these tactics early can prevent panic-driven decisions.
Key findings
- A data analyst misused legitimate access to steal sensitive corporate records and employee payroll/PII data after learning his contract would not be renewed.
- He used an alias (“Loot”) and sent 60+ emails to employees and executives threatening to publish data unless paid $2.5M in cryptocurrency.
- He applied pressure by attaching screenshots of spreadsheets listing employee names, home addresses, dates of birth, and salary information.
- He threatened to raise the ransom by $100,000 per month and also threatened to report the company to the SEC and expose pay disparities.
- Investigators traced him via email metadata and account-linked information; he requested payment to a Coinbase account tied to family debit cards.
Who’s being targeted
- Commonly targeted roles: Executives, HR, Finance, Legal, IT/Security Operations.
- Affected industries: Software/Technology.
- Attack channels: email.
- Impersonated: Anonymous insider using the alias “Loot”.
Red flags to watch for
- Unsolicited demand for payment in cryptocurrency
- Threats of public disclosure and regulatory reporting used to force urgency
- “Proof” provided via screenshots of sensitive spreadsheets sent over email
Frequently asked questions
What is an insider extortion attack?
It occurs when someone with legitimate access to company systems, such as an employee or contractor, uses that access to steal sensitive data and then threatens to release it publicly unless paid.
Why did this insider attack succeed?
The individual retained access to sensitive payroll and employee data after learning his contract would not be renewed, giving him the opportunity to exfiltrate records before access was revoked.
What should a company do if it receives an extortion email?
Treat it as a security incident immediately by not engaging with the sender, preserving all evidence, and escalating to security and legal teams rather than negotiating directly.
How can organizations reduce insider extortion risk?
Revoke system access immediately when a contractor or employee's departure is known, and closely monitor data access at the point someone learns they may be leaving.
Read the video transcript
Imagine this email: “I have your payroll data. Pay $2.5 million in crypto or I’ll publish it.” That actually happened. At Brightly Software, a contractor lost his job, kept his access, stole payroll spreadsheets, then, as “Loot,” fired off 60 extortion emails demanding crypto. His pressure tactic? Attach screenshots of real-looking payroll spreadsheets and threaten to raise the ransom by $100,000 every month and report the company to the SEC. If you ever see an email like this, don’t reply, don’t pay. Stop and forward it immediately to Security and Legal as an extortion incident.