NEWS

Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison

Former infrastructure engineer Daniel Rhyne, 59, gets 32 months for deleting admin accounts and demanding 20 bitcoin (~$750,000) from his ex-employer.

Dylan H.

News Desk

October 10, 2026
7 min read
Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison

Former Infrastructure Engineer Sentenced for Sabotaging Ex-Employer's Network

A former core infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging the computer network of his former employer — an industrial company headquartered in New Jersey — and attempting to extort it for 20 bitcoin, worth roughly $750,000 at the time. Daniel Rhyne, 59, of Kansas City, Missouri, pleaded guilty earlier this year to extortion and intentional damage to a protected computer after prosecutors showed he deleted domain administrator accounts, reset passwords on hundreds of accounts, and threatened to shut down dozens of servers a day until he was paid. U.S. District Judge Michael A. Shipp imposed the sentence on September 28, 2026, in federal court in Trenton, New Jersey.


Incident Details

AttributeValue
DefendantDaniel Rhyne, 59, of Kansas City, Missouri (a New Jersey resident at the time of the attack)
RoleFormer core infrastructure engineer
VictimAn industrial company headquartered in New Jersey, referred to as "Victim-1" in court filings; multiple outlets, including TechNadu, have identified it as Messer North America, a Bridgewater, NJ-based industrial gas supplier — not confirmed directly by the Justice Department
Attack dateNovember 25, 2023
MethodUnauthorized remote desktop sessions and scheduled tasks placed on the victim's domain controller
Damage caused13 domain administrator accounts deleted; passwords reset on 301 domain user accounts; two local administrator accounts changed, affecting 254 servers; two more local administrator accounts changed, affecting 3,284 workstations
Extortion demand20 bitcoin, worth approximately $750,000 at the time
Threat madeShut down 40 random servers per day for 10 days unless paid
Criminal complaint filedAugust 8, 2024, by FBI Special Agent Timothy Lee
ArrestAugust 27, 2024, in Kansas City, Missouri
Guilty pleaApril 1, 2026 — extortion involving a threat to damage a protected computer, and intentional damage to a protected computer
Sentence32 months in federal prison, imposed September 28, 2026
CourtU.S. District Court for the District of New Jersey (Trenton); Judge Michael A. Shipp
ProsecutionU.S. Attorney's Office, District of New Jersey (U.S. Attorney Robert Frazer)

What Happened

Setting the Trap

According to the Justice Department, Rhyne had worked as a core infrastructure engineer at the victim company, giving him deep familiarity with its Windows domain environment. In November 2023, prosecutors say he initiated unauthorized remote desktop sessions into the company's network and used that access to prepare a time-delayed sabotage mechanism rather than acting immediately. He placed scheduled tasks on the firm's domain controller configured to trigger automatically and cause cascading damage: deleting 13 domain administrator accounts, resetting the passwords of 301 domain user accounts to the string "TheFr0zenCrew!", and altering credentials on local administrator accounts that controlled 254 servers and 3,284 workstations. Investigators say Rhyne frequently relied on a hidden virtual machine to reach the company's network — the access channel forensic examiners later tied directly back to him.

The Ransom Email

On November 25, 2023, shortly after the scheduled tasks executed, employees at the victim company began receiving an email from an external address with the subject line "Your Network Has Been Penetrated." The message claimed administrator accounts had already been deleted or locked and backups removed, and it threatened to shut down 40 servers at random each day for 10 days unless the company paid 20 bitcoin — about $750,000 at November 2023 prices (the same amount of bitcoin would be worth well over $1.6 million at today's prices). The company did not pay.

How Investigators Tied It to Rhyne

Rather than negotiate, the victim company immediately launched an internal forensic investigation and correlated network logs against physical and remote access records, then brought in the FBI. Agents traced the unauthorized activity to a residential IP address in Warren County, New Jersey — Rhyne's home address at the time. From there, the digital trail compounded against him: forensic analysis of his laptop and the hidden virtual machine he used to reach the corporate network turned up a history of web searches related to planning the attack, and — in what multiple outlets have called a "rookie" operational-security failure — the external email account used to send the extortion message reused the same password, "TheFr0zenCrew!", that was hard-coded into his own attack scripts. FBI Special Agent Timothy Lee filed a criminal complaint on August 8, 2024, and Rhyne was arrested three weeks later, on August 27, 2024, in Kansas City, where he had since relocated. He pleaded guilty on April 1, 2026, and was sentenced on September 28, 2026.


Why This Matters

  1. Insider extortion is a growing substitute for ransomware-as-a-service. Rather than deploying encryption malware, Rhyne borrowed the ransomware playbook — mass credential destruction plus a timed-damage threat — using only legitimate administrative tools and access he already understood intimately from his job.
  2. Privileged offboarding and credential rotation remain a weak link. However he retained his remote access, the case underscores that former employees with deep infrastructure knowledge are a persistent risk until every credential, VPN profile, and remote-access path tied to them is fully revoked.
  3. Scheduled tasks are a blind spot for many detection stacks. Pre-staging the damage as domain-controller scheduled tasks let the attack fire well after the access session ended, which can defeat monitoring tuned only to catch activity during an active, suspicious login.
  4. Not paying — and preserving evidence — paid off. The victim company's decision to refuse the ransom and immediately correlate network logs with physical access records gave the FBI the forensic trail it needed, rather than funding further attacks with a six-figure bitcoin payment.
  5. Attacker OPSEC mistakes remain a critical defender advantage. Reusing a password from his own attack scripts for the extortion email account, and running searches from the same machine used to stage the intrusion, are the kind of self-inflicted errors that routinely unravel otherwise technically competent insider attacks.
  6. Federal prosecutors are treating insider sabotage as seriously as external ransomware crime. A 32-month sentence for extortion and intentional computer damage reinforces that insider attacks against critical industrial infrastructure draw the same prosecutorial weight as traditional cybercrime.

Recommendations

For IT and Security Teams

  • Enforce immediate, complete access revocation on employee separation — domain accounts, local admin credentials, VPN, remote desktop, and any virtual machines or jump boxes tied to the departing user
  • Monitor and alert on newly created or modified scheduled tasks on domain controllers and other Tier-0 assets, not just interactive logon anomalies
  • Require unique, randomly generated local administrator passwords per host (e.g., via LAPS) so a single compromised credential cannot cascade across thousands of workstations
  • Maintain offline, access-isolated backups that cannot be altered or deleted by any single compromised administrative account

For HR and Leadership

  • Treat departing employees with privileged infrastructure access as a formal offboarding risk category, with security sign-off required before final clearance
  • Establish a documented incident response and law-enforcement engagement plan for extortion attempts, including a clear no-negotiation default and evidence-preservation steps
  • Flag performance or conduct issues involving infrastructure staff to security teams promptly, given how often insider incidents trace back to known workplace friction

Sources