Ex-Engineer Gets 32 Months for Locking 3,000 Employer Devices

Daniel Rhyne, a former core infrastructure engineer, was sentenced to 32 months for locking over 3,000 devices at a New Jersey firm and demanding 20 bitcoin.
Table of Contents
    Add a header to begin generating the table of contents

    A federal court sentenced Daniel Rhyne, 57, of Kansas City, Missouri, to 32 months in prison for locking more than 3,000 devices on his employer’s network and demanding 20 bitcoin, worth about $750,000, in a ransomware-style extortion attempt. Rhyne, a former core infrastructure engineer, pleaded guilty. He was arrested in August 2024, and the sentence was announced on October 6.

    How Rhyne Used an Administrator Account to Take Over the Domain Controller

    The victim was an unnamed New Jersey-based industrial company, identified in court documents as “Victim-1.” Between November 8 and November 25, 2023, Rhyne used an administrator account to schedule tasks on the company’s domain controller. Through those tasks he changed the admin password to “TheFr0zenCrew!”, deleted 13 domain administrator accounts and reset the passwords of 301 domain user accounts.

    The changes blocked access to 254 servers and 3,284 workstations. Rhyne also shut down random machines through December 2023, extending the disruption well beyond the initial lockout. The tasks he scheduled on the domain controller did the work, and the 13 deleted domain administrator accounts left the company without the accounts that could have reversed the changes.

    Searches for Password Changes and Log Clearing Before the Attack

    Investigators found web searches from November 22 and earlier covering how to change passwords, delete accounts, clear Windows logs and shut down machines remotely. Those searches, which predate the ransom email, show the steps were researched before the lockout was complete.

    The “Your Network Has Been Penetrated” Ransom Email

    On November 25, 2023, the company received a ransom email titled “Your Network Has Been Penetrated.” The message claimed that backups had been deleted and threatened to shut down 40 random servers each day for 10 days unless the company paid 20 bitcoin. The extortion failed, and no payment is reported. The 20 bitcoin demand was worth about $750,000, and the threat to shut down servers applied only if the company did not pay. Rhyne was arrested in August 2024 and later pleaded guilty.

    The email read as if an outside intruder had written it, but Rhyne was an insider who already held the privileges needed to carry out the changes. A single account with domain controller access did the damage, with no external malware involved.

    Why the Case Matters for Privileged Access and Insider Risk

    The scale of the lockout, more than 3,000 devices across servers and workstations, came from a small number of administrative actions rather than from any exploit. Scheduled tasks on a domain controller ran with the same authority as the engineer who created them, and the deletion of 13 domain admin accounts removed the people who might have reversed the changes.

    The sentence of 32 months is a federal prison term for an act that failed to produce any ransom payment.

    The lockout ran across two phases. The first, from November 8 to November 25, centered on the domain controller changes that cut off access to servers and workstations. The second, after the ransom email, consisted of random machine shutdowns that continued through December 2023. Taken together, the activity stretched across roughly seven weeks of disruption at a major employer.

    Rhyne’s 32-Month Sentence Follows Guilty Plea and August 2024 Arrest

    Rhyne pleaded guilty, and the case went through federal prosecution. The lockout and the 20 bitcoin demand were part of the same attack, which makes it a ransomware-style extortion attempt carried out by an employee.

    The timeline of the case also stands out. From the November 2023 attack to an August 2024 arrest took about nine months, and sentencing came more than two years after the attack. The court record does not say how the company recovered its systems or how long the disruption lasted beyond the December 2023 shutdowns.

    Related Posts