Former core infrastructure engineer Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced to 32 months in prison for attacking his former employer's computer network and demanding a Bitcoin ransom, federal prosecutors announced.
Rhyne was sentenced on September 28 by U.S. District Judge Michael A. Shipp in Trenton, New Jersey. He pleaded guilty in April to extortion in relation to a threat to damage a protected computer and to intentional damage to a protected computer. The unnamed company, headquartered in Somerset County, New Jersey, serves industries ranging from biopharmaceuticals to oil and gas, where Rhyne had served as its core infrastructure engineer and subject matter expert on hosting virtual machines.
According to the FBI's criminal complaint, on November 25, 2023, at around 4 p.m., network administrators began receiving password reset notifications for hundreds of accounts. All other domain administrator accounts had been deleted. Forty-four minutes later, employees received an email headed "Your Network Has Been Penetrated," claiming IT administrators were locked out and backups deleted. It threatened to shut down 40 additional servers per day for 10 days unless 20 BTC—then worth approximately $750,000—was paid by December 2. The email set the ransom at €700,000, payable in Bitcoin.
Investigators traced the attack to an unauthorized virtual machine created on the company network on November 9, 2023. Its password was "TheFr0zenCrew!", the same password later set on the administrator account, on 301 user accounts, and on the email account used to send the ransom demand. A remote desktop session from that machine created scheduled tasks to delete 13 administrator accounts, change passwords affecting 254 servers and 3,284 workstations, and shut down dozens of servers beginning December 3.
The FBI linked the hidden machine to Rhyne through his company laptop: browsing on the laptop stopped whenever browsing occurred on the hidden machine, building access logs showed him entering headquarters minutes before his account logged in, and on the day of the attack his laptop connected from an IP address assigned to his home in Warren County, New Jersey. The machine's user had also searched for "how to clear all windows logs from command line" and "how to remotely shutdown a computer using cmd." Rhyne had faced a maximum of five years on the extortion count and 10 years on the intentional damage count.