Former Engineer Gets 32 Months After Account Takeover Locked 3,538 Company Devices

Former engineer Daniel Rhyne got 32 months for hijacking admin accounts, locking 254 servers and 3,284 workstations, and demanding 20 bitcoin.

Former Engineer Gets 32 Months After Account Takeover Locked 3,538 Company Devices
Ransomware

Illustrative image generated with AI

A former core infrastructure engineer has been sentenced to 32 months in prison after pleading guilty to his role in an extortion attempt against the industrial company that employed him.

Daniel Rhyne, 57, of Kansas City, Missouri, remotely accessed the unnamed company’s network without authorization and used administrative privileges to disrupt access to 254 servers and 3,284 workstations. Together, those figures represent 3,538 devices—not 3,538 employees or other affected people.

The company is described as an industrial business headquartered in New Jersey. A report published on October 6, 2026 disclosed the sentence but did not say when it was imposed.

This was described as a ransomware-style operation, although the reported mechanism centered on account deletion, password changes and system shutdowns rather than file encryption.

Administrative changes caused the large-scale lockout

According to court documents, Rhyne used an administrator account to enter the company network remotely and without authorization. He then created scheduled tasks on a domain controller to make coordinated changes across privileged and ordinary accounts.

The tasks changed the password of a domain administrator account to TheFr0zenCrew! and deleted 13 other domain administrator accounts. This combination deprived the company’s network administrators of the credentials and surviving accounts needed for domain-level control.

The same password, TheFr0zenCrew!, was assigned to 301 domain user accounts.

Rhyne also changed the passwords for two local administrator accounts to PsPasswd. That action blocked access to 254 servers, according to the court records. Changes to two additional administrator accounts prevented access to another 3,284 workstations.

The reported impact was therefore not limited to a few targeted employees. Manipulating a small number of highly privileged accounts produced disruption across thousands of endpoints.

At approximately 4:00 p.m. EST on or about November 25, 2023, network administrators began receiving password-reset notifications involving a domain administrator account and hundreds of user accounts, the criminal complaint says. They subsequently discovered that the remaining domain administrator accounts had been deleted, leaving them without domain-administrator access to the company’s networks.

The extortion demand threatened continued shutdowns

On November 25, Rhyne sent colleagues an email carrying the subject line “Your Network Has Been Penetrated.” He demanded 20 bitcoin, valued at approximately $750,000 at the time.

The message threatened to shut down 40 randomly selected servers per day for ten days if the company refused to pay. Court records also describe random servers and workstations being shut down over several days in December 2023.

The email claimed that backups had been deleted to prevent recovery. That point remains an assertion contained in the extortion message: the cited reporting does not independently establish that the company’s backups were actually erased.

This distinction matters when assessing the incident’s technical scope. The documented account changes and loss of access are supported by court materials, while the backup claim came from the person making the ransom demand.

No specific malware, encryption tool or software vulnerability was identified. There is also no CVE or formal severity score associated with the case. The operational damage instead arose from unauthorized administrative access and the ability to distribute account changes through the domain environment.

Records describe planning searches before the disruption

Investigators linked the activity to searches conducted before the extortion attempt, according to the report.

On November 22, Rhyne allegedly used an account within a hidden virtual machine to look for instructions on changing domain-user passwords, deleting domain accounts and clearing Windows logs. The report does not provide a year for that search date.

It also says that one week earlier he had used his laptop to research methods for changing local administrator passwords and remotely shutting down a computer through command-line instructions. No year is supplied for those searches either.

Court documents describe unauthorized network activity between November 8 and November 25, but the relevant passage does not state a year. Those dates should not be automatically assigned to 2023 solely because the criminal complaint separately identifies password-reset alerts on or about November 25, 2023.

Rhyne was arrested in August 2024 and released following his initial appearance in federal court. He later pleaded guilty to his role in the extortion attempt. The October 6, 2026 report gives the 32-month prison term but not the sentencing date.

A privileged insider can bypass several perimeter defenses

The case illustrates a specific form of insider risk: a person familiar with core infrastructure allegedly used legitimate administrative functions for destructive purposes.

The reported actions did not require an unknown software exploit. Password-management capabilities, scheduled tasks, domain administration and remote shutdown commands can all have legitimate operational uses. Their risk changes sharply when access is unauthorized or when a privileged account is abused.

Centralized administration amplified the consequences. Changes involving only a handful of administrator accounts denied access to 254 servers and 3,284 workstations, while deletion of 13 domain administrator accounts obstructed the defenders’ ability to respond.

The available reporting does not explain how the company recovered access, whether it paid any money, or which technical controls were in place. It also does not provide security advisories or incident-specific remediation instructions.

For organizations reviewing their exposure to comparable activity, the most directly relevant defensive priorities are to limit standing administrative access, separate routine and privileged accounts, and closely monitor changes to domain administrators. Alerts should cover bulk password resets, deletion of privileged accounts, creation of unusual scheduled tasks on domain controllers and remote shutdown activity.

Administrative actions should also generate records that a single privileged user cannot easily alter or erase. Recovery credentials and backups need protections independent of the domain whose compromise they are intended to address. These are general defensive measures derived from the reported attack path, not mitigations issued in connection with the case.

Device totals do not measure the number of victims

The reported figures describe systems whose access was disrupted: 254 servers and 3,284 workstations. They should not be interpreted as a count of employees, customers or other individuals affected.

Likewise, the reset of 301 domain user accounts is an account count. The materials summarized in the report do not provide a corresponding number of people.

No named hardware or software vendor was tied to the disruption. The environment included a domain controller, servers, workstations, administrator and user accounts, Windows logs, a laptop and a hidden virtual machine, but the reporting does not identify exact products or versions.

A separate employer-extortion case provides context

The report also references a separate case involving Cameron Curry, a 27-year-old data-analyst contractor from North Carolina.

Curry was sentenced to two years in prison in March, described as earlier that year, after being found guilty of extorting his employer, Brightly Software. The software-as-a-service company was previously known as SchoolDude, and the reported demand was $2.5 million.

That case is separate from Rhyne’s prosecution. It does, however, offer another example of criminal proceedings involving workers or contractors accused of using their organizational access in attempts to extract money from their employers.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →