Engineer Sentenced to 32 Months for Bitcoin Extortion Plot Against Former Employer

1 hour ago 2 sources neutral

Key takeaways:

  • Insider-led Bitcoin extortion highlights custody and access-control risks for institutional crypto adopters.
  • Ransomware actors still prefer BTC, keeping regulatory scrutiny on Bitcoin's illicit-finance use cases.
  • Watch for stricter corporate Bitcoin policies as insider threats test crypto's enterprise security narrative.

Former core infrastructure engineer Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced to 32 months in prison for attacking his former employer's computer network and demanding a Bitcoin ransom, federal prosecutors announced.

Rhyne was sentenced on September 28 by U.S. District Judge Michael A. Shipp in Trenton, New Jersey. He pleaded guilty in April to extortion in relation to a threat to damage a protected computer and to intentional damage to a protected computer. The unnamed company, headquartered in Somerset County, New Jersey, serves industries ranging from biopharmaceuticals to oil and gas, where Rhyne had served as its core infrastructure engineer and subject matter expert on hosting virtual machines.

According to the FBI's criminal complaint, on November 25, 2023, at around 4 p.m., network administrators began receiving password reset notifications for hundreds of accounts. All other domain administrator accounts had been deleted. Forty-four minutes later, employees received an email headed "Your Network Has Been Penetrated," claiming IT administrators were locked out and backups deleted. It threatened to shut down 40 additional servers per day for 10 days unless 20 BTC—then worth approximately $750,000—was paid by December 2. The email set the ransom at €700,000, payable in Bitcoin.

Investigators traced the attack to an unauthorized virtual machine created on the company network on November 9, 2023. Its password was "TheFr0zenCrew!", the same password later set on the administrator account, on 301 user accounts, and on the email account used to send the ransom demand. A remote desktop session from that machine created scheduled tasks to delete 13 administrator accounts, change passwords affecting 254 servers and 3,284 workstations, and shut down dozens of servers beginning December 3.

The FBI linked the hidden machine to Rhyne through his company laptop: browsing on the laptop stopped whenever browsing occurred on the hidden machine, building access logs showed him entering headquarters minutes before his account logged in, and on the day of the attack his laptop connected from an IP address assigned to his home in Warren County, New Jersey. The machine's user had also searched for "how to clear all windows logs from command line" and "how to remotely shutdown a computer using cmd." Rhyne had faced a maximum of five years on the extortion count and 10 years on the intentional damage count.

Previously on the topic:
Sep 30, 2026, 4:50 p.m.
Ex-NCA Officer Ordered to Repay $2.4M for Stolen Bitcoin
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.