Former engineer sentenced to 32 months for locking 3,000+ devices in employer extortion attack

Summary
A former infrastructure engineer was sentenced to 32 months in prison after pleading guilty to an extortion plot that locked thousands of devices on his employer’s network using unauthorized administrator access.
Key points
- Daniel Rhyne, a former core infrastructure engineer, pleaded guilty to targeting his New Jersey-based employer.
- He remotely accessed the company network without authorization using an administrator account.
- Scheduled tasks changed administrator and user passwords and deleted 13 domain administrator accounts, disrupting access to 254 servers and 3,284 workstations.
- He also shut down servers and workstations across the network over several days.
- Rhyne demanded 20 bitcoin and threatened further shutdowns; his ransom email claimed server backups had been deleted.
- He was sentenced to 32 months in prison.
Article Details
- Event Type
- Insider network disruption and extortion; criminal sentencing
- Impact
- Daniel Rhyne's password changes and account deletions blocked access to 254 servers and 3,284 workstations, changed passwords for 301 domain user accounts, and deleted 13 domain administrator accounts. He also shut down servers and workstations and demanded 20 bitcoin. His claim that backups had been deleted was not confirmed in the article.
MITRE ATT&CK
T1053.005 · Scheduled TaskRhyne used scheduled tasks on the domain controller to change passwords and delete accounts.T1529 · System Shutdown/RebootRhyne shut down servers and workstations on the company network.T1531 · Account Access RemovalPassword changes and deletion of domain administrator accounts denied access to company systems.