A former infrastructure engineer at a New Jersey-based industrial company has been sentenced to 32 months in prison after launching a ransomware-style attack that locked thousands of devices on his former employer’s network.

Daniel Rhyne, 57, of Kansas City, Missouri, pleaded guilty to his role in an extortion scheme targeting the company where he previously worked. Prosecutors arrested him in August 2024 and later released him after his initial appearance in federal court.

According to court documents, Rhyne accessed the company’s network remotely without authorization between November 8 and November 25, using an administrator account. He then created scheduled tasks on a domain controller that changed the administrator account password, deleted 13 domain administrator accounts, and changed the passwords of 301 domain user accounts.

The attack used “TheFr0zenCrew!” for several accounts. Rhyne also created scheduled tasks that changed the passwords of two local administrator accounts, cutting off access to 254 servers. He changed the passwords of two additional administrator accounts, blocking access to another 3,284 workstations.

The former engineer also remotely shut down random servers and workstations across the company’s network over several days in December 2023.

On November 25, Rhyne sent employees a ransom email titled “Your Network Has Been Penetrated.” He claimed that the company’s server backups had also been deleted and threatened to shut down 40 random servers every day for the next 10 days unless the company paid 20 bitcoin, worth about $750,000 at the time.

READ
Meta Denies Muse AI Agent Read Private Messages Without Permission

Network administrators began receiving password reset notifications for a domain administrator account and hundreds of user accounts around 4 p.m. EST on November 25, according to the criminal complaint. Shortly afterward, administrators discovered that the remaining domain administrator accounts had been deleted, preventing them from accessing and managing the company’s network.

Investigators later found evidence that Rhyne had been preparing for the attack. On November 22, he used an account on a hidden virtual machine to search online for information about changing domain passwords, deleting domain accounts, and clearing Windows logs.

Investigators also found that about a week earlier, Rhyne had searched from his laptop for commands that could change local administrator passwords, remotely change administrator passwords, and remotely shut down computers using Windows command-line tools.

Rhyne’s case is another example of an insider using legitimate administrative access and knowledge of an organization’s infrastructure to disrupt company systems and attempt to force an extortion payment.

Earlier this year, 27-year-old North Carolina data analyst contractor Cameron Curry was sentenced to two years in prison after being found guilty of an extortion scheme targeting his employer, Brightly Software. Prosecutors said Curry attempted to extort the software company for $2.5 million.


Buy ExpressVPN with PayPal or Credit Card

Advertisement