A former data analyst contractor has been sentenced to two years in federal prison after pleading guilty to stealing sensitive data from his employer — Brightly Software — and attempting to extort the company for $2.5 million. The case is a stark reminder of the significant insider threat posed by contractors and employees with privileged data access.
The Case
The individual worked as a data analyst contractor for Brightly Software, a software company that provides asset management and operations solutions to government agencies, municipalities, K-12 schools, and higher education institutions. His role gave him access to sensitive company and customer data.
Prosecutors detailed a scheme in which the contractor:
- Exfiltrated sensitive data from Brightly Software's systems before leaving or being terminated from his position
- Contacted the company with extortion demands, threatening to publish or misuse the stolen data unless paid $2.5 million
- Was subsequently identified, arrested, and charged with computer fraud and extortion offenses
The defendant entered a guilty plea and was sentenced to two years in federal prison. The case was prosecuted federally, reflecting the seriousness with which authorities now treat insider data theft and extortion — particularly when it involves companies serving public-sector clients.
Why This Case Matters
Contractors Are Insiders Too
Organizations often apply stronger security controls to permanent employees than to contractors, subcontractors, and third-party workers — despite the fact that contractors routinely receive the same or greater levels of data access to perform their duties. This case illustrates that the insider threat does not end with the employee badge.
Data Access Without Need-to-Know
A data analyst position inherently involves access to large volumes of potentially sensitive data. When access is not scoped tightly to what is strictly necessary (the principle of least privilege), a malicious or disgruntled insider can accumulate significant leverage for extortion or monetization schemes.
The Growing Trend of Insider Extortion
Rather than selling stolen data on the dark web — which carries its own risks and typically lower returns — insider threat actors have increasingly attempted direct extortion of their former employers. This mirrors the playbook used by ransomware groups, but executed from the inside.
Lessons for Organizations
Access governance and offboarding:
- Revoke all access — including cloud, SaaS, VPN, and third-party integrations — immediately upon contractor departure
- Conduct access reviews regularly to identify accounts with excessive privileges
- Implement just-in-time access for sensitive data environments
Data loss prevention (DLP):
- Monitor for bulk data downloads, particularly in the days leading up to a contractor's last day
- Flag unusual access to data repositories outside the scope of a contractor's assigned work
- Log and alert on large file transfers to external destinations
Insider threat program:
- Maintain a formal insider threat program with behavioral analytics
- Ensure HR and security teams share information about employee/contractor departures, performance issues, or access disputes
- Train employees and managers to recognize early warning indicators of insider risk
Legal and incident response:
- Establish clear contractual obligations around data handling for all contractors
- Have a defined response plan for extortion attempts, including working with law enforcement
Sentence and Deterrence
The two-year federal prison sentence sends a clear message: insider data theft followed by extortion will be prosecuted aggressively and carries significant consequences. Similar cases in recent years have resulted in sentences ranging from probation to over a decade in prison, depending on the scale of harm and the sophistication of the scheme.
For organizations, this case reinforces that cybersecurity is not only a technical problem — it is also a people and process problem requiring ongoing attention to access controls, monitoring, and insider risk management.