A former infrastructure engineer has been sentenced to 32 months in federal prison for orchestrating a sabotage and ransom scheme against his employer’s Windows network. The engineer, Daniel Rhyne, aged 59 from Kansas City, Missouri, was sentenced on September 28, 2026, in a federal court located in Trenton. Rhyne admitted to charges of extortion and intentional damage to a protected computer.
Details of the Cybercrime
The sentencing was handed down by U.S. District Judge Michael A. Shipp after Rhyne pleaded guilty to targeting a New Jersey-based industrial company. Rhyne, who served as a core infrastructure engineer and specialist for virtual machines, was implicated in the attack that involved creating an unauthorized virtual machine within the company’s network on November 9, 2023.
This virtual machine served as an entry point to the company’s domain controller, facilitating unauthorized access to a domain administrator account through numerous remote desktop sessions between November 10 and November 25, 2023.
Impact of the Network Attack
On November 25, at approximately 8:12 a.m., the compromised administrator account initiated 16 unauthorized scheduled tasks. Six of these tasks were executed that afternoon, which led to the deletion of 13 domain administrator accounts and password changes for 301 domain user accounts. The remaining tasks were intended to shut down several servers starting December 3.
The attack utilized Windows administration tools rather than deploying a file-encrypting payload. Domain account modifications were handled via the ‘net user’ utility, while Microsoft’s Sysinternals PsPasswd tool was used to change local administrator passwords. These actions impacted 254 servers and 3,284 workstations.
Ransom Demands and Investigation
Later that day, at approximately 4:00 p.m., administrators received alerts about password resets and discovered the deletion of other domain administrator accounts, which restricted their network access. Shortly after, employees received an email demanding 20 bitcoin, valued at about $750,000 at that time, with a payment deadline of December 2, 2023. The email threatened daily server shutdowns if the ransom was not paid and claimed backup deletions, though this was not independently verified.
Investigators linked the hidden virtual machine to Rhyne’s laptop and user account, corroborated by physical access records and security footage. Remote connections traced back to his home IP address, and further evidence was found through password reuse and related online searches.
This case underscores the critical importance of robust network security measures and vigilance against insider threats in safeguarding organizational data.
