A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer’s network in a ransomware-style attack.
57-year-old Daniel Rhyne from Kansas City, Missouri, pleaded guilty to his role in a failed extortion plot targeting the New Jersey company that employed him after being arrested in August 2024 and released after his initial appearance in federal court.
According to court documents, he remotely accessed the company’s network without authorization using an administrator account between November 8 and November 25 and scheduled tasks on the domain controller that changed the password of the administrator account to “TheFr0zenCrew!”, deleted 13 domain admin accounts, and changed the passwords for 301 domain user accounts to “TheFr0zenCrew!”.
Rhyne also added scheduled tasks that changed the password for two local admin accounts to “PsPasswd” (blocking access to 254 servers), changed the password for two more admin accounts (blocking access to an additional 3,284 workstations), and shut down random servers and workstations on the company’s network over several days in December 2023.
On November 25, Rhyne sent coworkers a ransom email titled “Your Network Has Been Penetrated,” in which he said that server backups had also been deleted to make data recovery impossible and threatened to shut down 40 random servers daily over the next ten days unless the company paid a 20 bitcoin ransom (roughly $750,000 at the time).
“On or about November 25, 2023, at approximately 4:00 p.m. EST, network administrators employed at Victim-1 began receiving password reset notifications for a Victim-1 domain administrator account, as well as hundreds of Victim-1 user accounts,” the criminal complaint reads.
“Shortly thereafter, the Victim-1 network administrators discovered that all other Victim-1 domain administrator accounts were deleted, thereby denying domain administrator access to Victim-1’s computer networks.”
Investigators found that on November 22, while planning his extortion plot, Rhyne used his account on a hidden virtual machine to search the web for information on changing domain user passwords, deleting domain accounts, and clearing Windows logs.
One week earlier, he also searched on his laptop for “command line to change local administrator password,” “command line to remotely change local administrator password,” and “how to remotely shutdown a computer usign cmd.”
Earlier this year, in March, 27-year-old North Carolina data analyst contractor Cameron Curry was also sentenced to two years in prison after being found guilty of extorting his employer, Brightly Software (a Software-as-a-Service company previously known as SchoolDude) for $2.5 million.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.



