Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison
An industrial firm's former engineer was sentenced to prison for a cyber extortion plot against his employer.
Summary
Daniel Rhyne, a former core infrastructure engineer at an industrial firm, has been sentenced to 32 months in prison for intentionally damaging a protected computer and extortion. Rhyne used his access to delete admin accounts, reset hundreds of user passwords, and demanded 20 bitcoin (approx. $750,000) to prevent further system shutdowns. The FBI traced the attack back to Rhyne's IP address, leading to his arrest and conviction.
Full text
A Kansas City, Missouri man has been sentenced to 32 months in jail for crimes related to a ransom attack against his own company. The DOJ has announced the sentencing of Daniel Rhyne. He had already pleaded guilty to ‘extortion in relation to a threat to cause damage to a protected computer’ and ‘intentional damage to a protected computer’. Fifty-nine-year-old Rhyne had been a core infrastructure engineer at an industrial firm headquartered in Somerset County, New Jersey. The firm provides services to industries involved in aquaculture, biopharmaceuticals, chemistry, electronics, food and beverage, healthcare, hydrogen mobility, manufacturing and industrial processing, metals, oil and gas, and pulp and paper. In November 2023, Rhyne placed scheduled tasks on the firm’s domain controller that would delete 13 domain administrator accounts; change passwords to 301 domain user accounts; change passwords to two local administrator accounts that would impact 254 servers; and change passwords to two local administrator accounts impacting 3,284 workstations. The effect was to deny the firm access to its systems and data. Where passwords were changed, it was generally to ‘TheFr0zenCrew!’. The scheduled tasks were completed late afternoon on November 25. Within an hour, certain employees received an e-mail from an external address. The subject line said, “Your Network Has Been Penetrated”. It warned that administrators had been locked out or deleted, all backups had been deleted, and that, unless a ransom was paid, 40 random servers would be shut down each day over a ten-day period.Advertisement. Scroll to continue reading. Rhyne was demanding a payment of 20 bitcoin, worth at the time approximately $750,000. There is no suggestion that the victim firm paid any ransom. Rather, it immediately started its own internal forensic analysis of any network anomalies, and it correlated internal logs with physical access records. It involved the FBI, which tracked the unauthorized activity directly to Rhyne’s residential IP address in Warren County, New Jersey. This joint forensic investigation provided sufficient evidence for FBI Special Agent Timothy Lee to file a criminal complaint on August 8, 2024, leading to Rhyne’s arrest on August 27, 2024, in Kansas City, where he had subsequently moved. He pleaded guilty on April 1, 2026, in federal court in Trenton, New Jersey, before District Judge Michael A. Shipp. Rhyne was sentenced on September 28, 2026, to 32 months in federal prison for his role in the sabotage and extortion plot. Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon Related: US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks Related: Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison Related: Two Scattered Spider Hackers Sentenced to Jail in UK Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Formula Predicts When AI Chatbots Are at Risk of Turning BadSecurity Awareness Training Isn’t Dead, but It Needs a RethinkHadrian Raises $40 Million to Expand Autonomous Offensive Security PlatformSocial Engineering Detection Moves Into the Live ConversationSenate Passes Bipartisan Bill to Strengthen Healthcare Cybersecuritydoxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet MisadventuresmacOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD BackdoorZero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks Latest News OpenAI Fires 3 Safety Researchers in Dispute Over AI RisksIn Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 YearsGoogle Domains Impacted by Recent ccTLD HijacksUnpatched AhsayCBS Vulnerabilities Exploited in the WildPre-Baked Firmware Malware Hits Budget Android Devices in 150+ CountriesUS Disrupts Chinese State-Sponsored Hacking ToolsAnthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT SecurityCitrix Urges Immediate Patching of Critical NetScaler Vulnerability Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: AI Is Accelerating Risk. Can Your IT Operations Keep Up? October 14, 2026 Learn about Frontier Pace Governance: a practical approach to helping IT operations move at AI speed without sacrificing security, accountability, or operational discipline. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveRapid7 has named Rik Ferguson as VP of Security Intelligence.Cytactic has appointed Tim Brown as CSO.Scott Simkin has joined Vega as CMO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — TheFr0zenCrew!