Insider attack: Engineer jailed for locking 3,000+ devices
A former core infrastructure engineer has been sentenced to 32 months in prison for locking thousands of devices on his employer's network and demanding a bitcoin ransom to restore access.
Daniel Rhyne, 57, from Kansas City, Missouri, worked for an industrial company headquartered in New Jersey. He pleaded guilty to his role in the failed extortion plot. He was arrested in August 2024 and released after his initial appearance in federal court.
Court documents refer to the company only as "Victim-1."
Scheduled tasks on the domain controller
According to the court documents, Rhyne used an administrator account to access the company's network remotely and without authorization between November 8 and November 25, 2023. He did not rely on malware. He used the company's own Windows infrastructure, setting up scheduled tasks on the domain controller. In a Windows network, the domain controller is the server that handles logins and permissions.
Those tasks:
- changed the password of the administrator account to "TheFr0zenCrew!"
- deleted 13 domain admin accounts
- changed the passwords of 301 domain user accounts to "TheFr0zenCrew!"
He added more scheduled tasks to go after local administrator accounts. Two of them had their passwords changed to "PsPasswd," which cut off access to 254 servers. Passwords on two other admin accounts were also changed, locking out a further 3,284 workstations. Over several days, the tasks also shut down random servers and workstations on the network.
The ransom note
On November 25, Rhyne emailed coworkers a message titled "Your Network Has Been Penetrated." The email said server backups had been deleted so the data could not be recovered.
He threatened to shut down 40 random servers every day for the next ten days unless the company paid 20 bitcoin, worth roughly $750,000 at the time.
The criminal complaint describes how the attack showed up for the company's IT staff.
"On or about November 25, 2023, at approximately 4:00 p.m. EST, network administrators employed at Victim-1 began receiving password reset notifications for a Victim-1 domain administrator account, as well as hundreds of Victim-1 user accounts," the complaint reads.
"Shortly thereafter, the Victim-1 network administrators discovered that all other Victim-1 domain administrator accounts were deleted, thereby denying domain administrator access to Victim-1's computer networks."
A search history that gave him away
Rhyne's own search history played a central part in the case. On November 22, while planning the attack, he used his account on a hidden virtual machine to look up how to change domain user passwords, delete domain accounts and clear Windows logs.
A week before that, he had searched on his laptop for "command line to change local administrator password," "command line to remotely change local administrator password," and "how to remotely shutdown a computer usign cmd."
The virtual machine suggests he tried to hide what he was doing. The searches on his laptop left a clear record of his preparations, and investigators used it.
Not the only insider extortion case this year
This is the second insider extortion sentencing this year. In March, Cameron Curry, a 27-year-old data analyst contractor from North Carolina, received two years in prison. He was found guilty of trying to extort $2.5 million from his employer, Brightly Software, a Software-as-a-Service company previously known as SchoolDude.
Our Take
Rhyne did not need an exploit or a custom encryptor. He had legitimate administrative access and a good understanding of how the company's Windows domain worked. Scheduled tasks, password changes and account deletions are routine admin work. That routine nature makes this kind of attack hard to spot until the damage is done, and the case is a reminder that the most privileged accounts in a network are also its weakest point.
For defenders, the lessons are practical. Changes to domain admin accounts, new scheduled tasks on domain controllers and mass password resets should trigger alerts quickly, not after the fact. The claim that backups had been deleted also shows why offline or immutable backups should sit outside the reach of any single administrator.
The case also fits a wider concern about insider risk. Recent reports suggest criminals are actively recruiting insiders at large companies, so the threat is not limited to disgruntled staff acting alone.
Prosecutors are continuing to bring cybercrime cases to court, as the Ploutus ATM malware case also shows. It is worth watching whether sentences like Rhyne's 32 months deter other insiders, or whether companies rely more on separation of duties and closer monitoring of admin accounts.
