Cybersecurity

32 Months in Prison for Engineer Who Locked More Than 3,000 Devices on His Company’s Network

Daniel Rhyne was sentenced to 32 months in prison after pleading guilty to an insider attack that disrupted thousands of devices and accounts within his employer’s network and involved a ransom demand of 20 bitcoin.

2026-10-06
3 min read
17 views
certi.news Editorial Team
32 Months in Prison for Engineer Who Locked More Than 3,000 Devices on His Company’s Network

Daniel Rhyne, 57, was sentenced to 32 months in prison after pleading guilty to his role in a failed extortion attempt targeting an industrial company based in New Jersey. Rhyne exploited his former privileges as a critical infrastructure engineer to remotely access the company’s network and carry out an attack resembling a ransomware attack.

How Was the Network Disrupted?

Between November 8 and 25, Rhyne accessed the network without authorization using an administrative account. According to court documents, he created scheduled tasks that changed the administrator account password to TheFr0zenCrew!, deleted 13 domain administrator accounts, and changed the passwords of 301 domain user accounts to the same password.

Additional tasks were added to change the passwords of two local administrator accounts to PsPasswd, blocking access to 254 servers. The passwords of two additional administrator accounts were also changed, isolating another 3,284 workstations. Over several days in December 2023, Rhyne randomly shut down servers and workstations on the company’s network.

Ransom Demand and Threat of Repeated Disruption

On November 25, he sent his colleagues a message titled “Your Network Has Been Penetrated.” In it, he said that server backups had been deleted to make data recovery impossible, and demanded that the company pay 20 bitcoin, worth approximately $750,000 at the time. He also threatened to shut down 40 random servers daily for ten days if the ransom was not paid.

The criminal complaint explains that at around 4 p.m. Eastern Time, network administrators began receiving notifications to reset the passwords of a domain administrator account and hundreds of user accounts. They later discovered that all other domain administrator accounts had been deleted, depriving them of administrative privileges over the company’s networks.

What Matters to Security Teams?

The incident practically demonstrates the extent of the damage that an internal account with broad privileges can cause even without traditional file encryption. The attack focused on changing passwords, deleting accounts, disabling devices, and targeting backups—actions sufficient to cripple an enterprise environment and prevent response teams from quickly regaining control.

Investigators found that before carrying out the scheme, Rhyne had searched for ways to change domain users’ passwords, delete accounts, and clear Windows logs. He also searched for commands to change administrators’ passwords locally and remotely and to shut down computers using the command line. The details of the company’s defenses and activity-detection mechanisms remain unmentioned in the source material, so the effectiveness of its controls or the reason unauthorized access continued cannot be inferred.

The sentence follows Rhyne’s arrest in August 2024 and his release after his initial appearance before the federal court. The source also reported a separate sentence in March for a contract data analyst from North Carolina, who was sentenced to two years in prison after being convicted of extorting $2.5 million from his employer, Brightly Software.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

What you need to know

حُكم على المهندس السابق Daniel Rhyne بالسجن 32 شهراً بعد إقراره بتنفيذ هجوم داخلي عطّل آلاف الأجهزة والحسابات في شبكة شركة صناعية بولاية نيوجيرسي. استخدم صلاحيات إدارية لتغيير كلمات المرور وحذف الحسابات وتعطيل الأجهزة، ثم طالب بفدية قدرها 20 بيتكوين.

  • دخل Rhyne إلى شبكة الشركة دون تفويض بين 8 و25 نوفمبر باستخدام حساب إداري.
  • غيّر كلمات مرور 301 حساب مستخدم وحذف 13 حساباً من حسابات مديري النطاق.
  • أدى الهجوم إلى حجب الوصول إلى 254 خادماً وعزل 3,284 محطة عمل إضافية.
  • زعم Rhyne أن النسخ الاحتياطية حُذفت، وطالب الشركة بدفع 20 بيتكوين، أي نحو 750 ألف دولار في ذلك الوقت.
  • هدد بإيقاف 40 خادماً عشوائياً يومياً لمدة عشرة أيام إذا لم تُدفع الفدية.
  • توضح الواقعة أن إساءة استخدام حساب داخلي واسع الصلاحيات قد تشل بيئة مؤسسية حتى دون تشفير تقليدي للملفات.

FAQ

ما العقوبة التي صدرت بحق Daniel Rhyne؟

حُكم عليه بالسجن 32 شهراً بعد إقراره بالذنب في محاولة ابتزاز فاشلة استهدفت شركة صناعية.

كيف عطّل Rhyne شبكة الشركة؟

استخدم مهاماً مجدولة لتغيير كلمات المرور وحذف حسابات مديري النطاق وتعطيل الخوادم ومحطات العمل.

كم بلغت الفدية المطلوبة؟

طالب بدفع 20 بيتكوين، وقدرت قيمتها بنحو 750 ألف دولار وقت الطلب.

هل كان الهجوم برنامج فدية تقليدياً؟

اتخذ الهجوم نمطاً قريباً من هجمات الفدية، لكنه ركز على تغيير كلمات المرور وحذف الحسابات وتعطيل الأجهزة واستهداف النسخ الاحتياطية، وليس على تشفير الملفات التقليدي.

Explore this story

الموضوعات والجهات المرتبطة

In the same category

You may also like

View all news