NEWS

Engineer Sentenced for Locking Over 3,000 Devices on Employer Network

Daniel Rhyne, a former infrastructure engineer, got 32 months after locking out servers and workstations and demanding $750,000 in bitcoin.

Dylan H.

News Desk

October 6, 2026
4 min read
Engineer Sentenced for Locking Over 3,000 Devices on Employer Network

From Trusted Engineer to Extortionist

Daniel Rhyne, 57, of Kansas City, Missouri, a former core infrastructure engineer, has been sentenced to 32 months in prison for carrying out a ransomware-style extortion attack against his own employer — an industrial company headquartered in New Jersey. Rather than deploying malware, Rhyne used the administrator credentials and access his job already entrusted to him to systematically lock the company out of its own network, then demanded 20 bitcoin (roughly $750,000 at the time) to restore access.


Details

AttributeValue
DefendantDaniel Rhyne, 57, Kansas City, Missouri
RoleFormer core infrastructure engineer
EmployerIndustrial company headquartered in New Jersey
Attack WindowNovember 8 – 25, 2023
Devices Affected254 servers locked; 3,284 workstations locked out (3,000+ total)
Extortion Demand20 BTC (approx. $750,000)
ThreatShut down 40 servers daily over 10 days if unpaid
ArrestAugust 2024
OutcomeGuilty plea; sentenced to 32 months in prison

How the Attack Unfolded

Using administrator-level access, Rhyne remotely connected to his employer's network between November 8 and 25, 2023, and worked through a deliberate sequence of sabotage:

  • Changed the password on the administrator account to "TheFr0zenCrew!"
  • Deleted 13 domain admin accounts
  • Modified passwords on 301 domain user accounts
  • Changed local admin passwords to "PsPasswd," locking out 254 servers
  • Locked out an additional 3,284 workstations
  • Scheduled random server and workstation shutdowns that continued through December 2023

On November 25, Rhyne sent the company a ransom email demanding 20 bitcoin and threatening to shut down 40 servers a day over the following ten days if the demand went unpaid.

Premeditation, Not Improvisation

Investigators found Rhyne had researched the attack in advance. He searched a hidden virtual machine for information on changing domain user passwords, deleting domain accounts, and clearing Windows event logs, and searched his personal laptop for commands related to password changes and remote shutdowns — evidence prosecutors used to establish the attack was planned rather than a spur-of-the-moment act.

Arrest and Sentencing

Rhyne was arrested in August 2024 and subsequently pleaded guilty to the extortion plot targeting his employer. He has now been sentenced to 32 months in prison.


Why This Matters

  • Privileged access is the attack, not just the vector. Rhyne didn't need to write malware or find an exploit — his existing administrator credentials were sufficient to cripple over 3,000 devices.
  • Insider extortion mirrors ransomware without the malware. The playbook — mass credential/password resets, scheduled disruption, a bitcoin ransom demand, and an escalation threat — is functionally identical to a ransomware operation, but originated entirely from a trusted employee.
  • Log clearing and VM research are detectable prep signals. Rhyne's searches for log-clearing and password-reset commands on a hidden VM are the kind of pre-attack reconnaissance that insider-threat monitoring programs are specifically designed to catch.

Recommendations

For IT and Security Leadership

  • Enforce the principle of least privilege for infrastructure engineers — no single administrator account should be able to unilaterally reset credentials across the entire domain.
  • Require a second approver for bulk password resets, domain admin account deletions, or mass local-admin password changes.
  • Monitor for anomalous after-hours remote administrative access, especially from personal or unmanaged devices and virtual machines.

For Incident Response Teams

  • Maintain offline, access-isolated backups of domain controller configuration and admin credentials to enable rapid recovery from an insider-driven lockout.
  • Treat departing or disgruntled privileged users as a distinct risk category with accelerated access revocation timelines.
  • Log and alert on searches or tool usage associated with credential-dumping, log-clearing, or mass account modification on any company-issued or BYOD endpoint with administrative access.

Key Takeaways

  1. A former infrastructure engineer used legitimate administrator access to lock 254 servers and 3,284 workstations at his employer.
  2. The attack combined mass password resets, domain admin account deletion, and scheduled shutdowns with a $750,000 bitcoin extortion demand.
  3. Evidence of advance research into password-reset and log-clearing commands showed the attack was premeditated.
  4. Rhyne was sentenced to 32 months in prison after pleading guilty to the extortion plot.

Sources