Daniel Rhyne, 57, was sentenced to 32 months in prison after pleading guilty to his role in a failed extortion attempt targeting an industrial company based in New Jersey. Rhyne exploited his former privileges as a critical infrastructure engineer to remotely access the company’s network and carry out an attack resembling a ransomware attack.
How Was the Network Disrupted?
Between November 8 and 25, Rhyne accessed the network without authorization using an administrative account. According to court documents, he created scheduled tasks that changed the administrator account password to TheFr0zenCrew!, deleted 13 domain administrator accounts, and changed the passwords of 301 domain user accounts to the same password.
Additional tasks were added to change the passwords of two local administrator accounts to PsPasswd, blocking access to 254 servers. The passwords of two additional administrator accounts were also changed, isolating another 3,284 workstations. Over several days in December 2023, Rhyne randomly shut down servers and workstations on the company’s network.
Ransom Demand and Threat of Repeated Disruption
On November 25, he sent his colleagues a message titled “Your Network Has Been Penetrated.” In it, he said that server backups had been deleted to make data recovery impossible, and demanded that the company pay 20 bitcoin, worth approximately $750,000 at the time. He also threatened to shut down 40 random servers daily for ten days if the ransom was not paid.
The criminal complaint explains that at around 4 p.m. Eastern Time, network administrators began receiving notifications to reset the passwords of a domain administrator account and hundreds of user accounts. They later discovered that all other domain administrator accounts had been deleted, depriving them of administrative privileges over the company’s networks.
What Matters to Security Teams?
The incident practically demonstrates the extent of the damage that an internal account with broad privileges can cause even without traditional file encryption. The attack focused on changing passwords, deleting accounts, disabling devices, and targeting backups—actions sufficient to cripple an enterprise environment and prevent response teams from quickly regaining control.
Investigators found that before carrying out the scheme, Rhyne had searched for ways to change domain users’ passwords, delete accounts, and clear Windows logs. He also searched for commands to change administrators’ passwords locally and remotely and to shut down computers using the command line. The details of the company’s defenses and activity-detection mechanisms remain unmentioned in the source material, so the effectiveness of its controls or the reason unauthorized access continued cannot be inferred.
The sentence follows Rhyne’s arrest in August 2024 and his release after his initial appearance before the federal court. The source also reported a separate sentence in March for a contract data analyst from North Carolina, who was sentenced to two years in prison after being convicted of extorting $2.5 million from his employer, Brightly Software.