From Trusted Engineer to Extortionist
Daniel Rhyne, 57, of Kansas City, Missouri, a former core infrastructure engineer, has been sentenced to 32 months in prison for carrying out a ransomware-style extortion attack against his own employer — an industrial company headquartered in New Jersey. Rather than deploying malware, Rhyne used the administrator credentials and access his job already entrusted to him to systematically lock the company out of its own network, then demanded 20 bitcoin (roughly $750,000 at the time) to restore access.
Details
| Attribute | Value |
|---|---|
| Defendant | Daniel Rhyne, 57, Kansas City, Missouri |
| Role | Former core infrastructure engineer |
| Employer | Industrial company headquartered in New Jersey |
| Attack Window | November 8 – 25, 2023 |
| Devices Affected | 254 servers locked; 3,284 workstations locked out (3,000+ total) |
| Extortion Demand | 20 BTC (approx. $750,000) |
| Threat | Shut down 40 servers daily over 10 days if unpaid |
| Arrest | August 2024 |
| Outcome | Guilty plea; sentenced to 32 months in prison |
How the Attack Unfolded
Using administrator-level access, Rhyne remotely connected to his employer's network between November 8 and 25, 2023, and worked through a deliberate sequence of sabotage:
- Changed the password on the administrator account to "TheFr0zenCrew!"
- Deleted 13 domain admin accounts
- Modified passwords on 301 domain user accounts
- Changed local admin passwords to "PsPasswd," locking out 254 servers
- Locked out an additional 3,284 workstations
- Scheduled random server and workstation shutdowns that continued through December 2023
On November 25, Rhyne sent the company a ransom email demanding 20 bitcoin and threatening to shut down 40 servers a day over the following ten days if the demand went unpaid.
Premeditation, Not Improvisation
Investigators found Rhyne had researched the attack in advance. He searched a hidden virtual machine for information on changing domain user passwords, deleting domain accounts, and clearing Windows event logs, and searched his personal laptop for commands related to password changes and remote shutdowns — evidence prosecutors used to establish the attack was planned rather than a spur-of-the-moment act.
Arrest and Sentencing
Rhyne was arrested in August 2024 and subsequently pleaded guilty to the extortion plot targeting his employer. He has now been sentenced to 32 months in prison.
Why This Matters
- Privileged access is the attack, not just the vector. Rhyne didn't need to write malware or find an exploit — his existing administrator credentials were sufficient to cripple over 3,000 devices.
- Insider extortion mirrors ransomware without the malware. The playbook — mass credential/password resets, scheduled disruption, a bitcoin ransom demand, and an escalation threat — is functionally identical to a ransomware operation, but originated entirely from a trusted employee.
- Log clearing and VM research are detectable prep signals. Rhyne's searches for log-clearing and password-reset commands on a hidden VM are the kind of pre-attack reconnaissance that insider-threat monitoring programs are specifically designed to catch.
Recommendations
For IT and Security Leadership
- Enforce the principle of least privilege for infrastructure engineers — no single administrator account should be able to unilaterally reset credentials across the entire domain.
- Require a second approver for bulk password resets, domain admin account deletions, or mass local-admin password changes.
- Monitor for anomalous after-hours remote administrative access, especially from personal or unmanaged devices and virtual machines.
For Incident Response Teams
- Maintain offline, access-isolated backups of domain controller configuration and admin credentials to enable rapid recovery from an insider-driven lockout.
- Treat departing or disgruntled privileged users as a distinct risk category with accelerated access revocation timelines.
- Log and alert on searches or tool usage associated with credential-dumping, log-clearing, or mass account modification on any company-issued or BYOD endpoint with administrative access.
Key Takeaways
- A former infrastructure engineer used legitimate administrator access to lock 254 servers and 3,284 workstations at his employer.
- The attack combined mass password resets, domain admin account deletion, and scheduled shutdowns with a $750,000 bitcoin extortion demand.
- Evidence of advance research into password-reset and log-clearing commands showed the attack was premeditated.
- Rhyne was sentenced to 32 months in prison after pleading guilty to the extortion plot.
Related Reading
- Manager of Botnet Used in Ransomware Attacks Gets 2 Years in Prison
- Ryuk Operator Pleads Guilty, BlackCat/ALPHV Conspirator Gets Nearly 6-Year Sentence
Sources
- Engineer Sentenced for Locking Over 3,000 Devices on Employer Network — BleepingComputer