Engineer Sentenced for Locking 3,000 Devices in Ransomware Plot
Daniel Rhyne received a 32-month prison sentence following a ransomware-style extortion attempt targeting his employer, a New Jersey industrial company.

Sentencing of Former Infrastructure Engineer
A former core infrastructure engineer at a New Jersey-headquartered industrial company has been sentenced to 32 months in prison for carrying out a ransomware-style attack that locked thousands of devices on his employer's corporate network. According to details reported by [BleepingComputer], 57-year-old Daniel Rhyne of Kansas City, Missouri, previously [pleaded guilty] to his role in the failed extortion plot.
Rhyne's arrest took place in August 2024, after which he was released following an initial appearance in federal court. Investigators later detailed the full scope of the operational disruption, which targeted administrative controls and left internal teams locked out of vital network infrastructure.
Network Takeover and Administrative Lockout
As outlined in federal [court documents], Rhyne utilized an administrator account to remotely access the company's network without authorization between November 8 and November 25, 2023. During this period, he scheduled tasks on the domain controller to alter the primary administrator password to "TheFr0zenCrew!", deleted 13 domain admin accounts, and changed passwords for 301 domain user accounts to the same string.
Further malicious automation included scheduled tasks that modified local administrator credentials to "PsPasswd", effectively blocking access to 254 servers. Rhyne also altered credentials for two additional administrator accounts, blocking access to an extra 3,284 workstations, and proceeded to randomly shut down various servers and workstations over multiple days in December 2023.
The impact on internal operations was immediate. The criminal complaint notes that network administrators began receiving password reset notifications for a domain administrator account and hundreds of user accounts at approximately 4:00 p.m. EST on November 25, 2023. Shortly after, administrative teams discovered that all remaining domain administrator accounts had been deleted.
Ransom Demand and Investigation Findings
On November 25, Rhyne transmitted a ransom email to coworkers titled "Your Network Has Been Penetrated." The message asserted that server backups had been deleted to ensure data recovery was impossible, and threatened to shut down 40 random servers daily over a ten-day span unless the company paid a ransom of 20 bitcoin, which was valued at roughly $750,000 at the time.
Digital forensics investigators uncovered pre-attack planning activities. On November 22, Rhyne used a hidden virtual machine account to search the web for instructions on changing domain user passwords, deleting domain accounts, and clearing Windows event logs. One week prior, he utilized his laptop to search for specific command lines concerning local administrator password modifications and remote system shutdowns.
Broader Context in Insider Extortion Cases
Insider threats and corporate extortion schemes have drawn significant legal scrutiny in recent months. Earlier this year, in March, a separate high-profile case concluded when 27-year-old North Carolina data analyst contractor Cameron Curry was [sentenced to two years in prison] after being [found guilty of extorting his employer], Brightly Software, for $2.5 million.
The sentencing of Rhyne underscores the severe legal consequences faced by technical personnel who weaponize privileged access against their own organizations, reinforcing the importance of strict administrative monitoring and credential management across corporate enterprise networks.
Sources
- BleepingComputerEngineer sentenced for locking over 3,000 devices on employer network
Continue chronologically





