Engineer Sentenced for Cybercrime: 3,000 Devices Locked on Employer Network

www.news4hackers.com-engineer-sentenced-for-cybercrime-3-000-devices-locked-on-employer-network-engineer-sentenced-for-cybercrime-3-000-devices-locked-on-employer-network

A former core infrastructure engineer at a New Jersey-based industrial company received a 32-month prison sentence for executing a ransomware-style attack that restricted access to over 3,000 networked devices.

Sentencing and Background

The individual, 57-year-old Daniel Rhyne from Kansas City, Missouri, admitted guilt in a case involving unauthorized network intrusions and extortion attempts against his former employer. Rhyne was arrested in August 2024 and released after his initial court appearance, with the sentencing occurring after a federal investigation uncovered his actions.

Details of the Unauthorized Network Lockdown

Court records detail that Rhyne gained unauthorized remote access to the company’s network using an administrator account between November 8 and November 25, 2023. He deployed malicious scheduled tasks on the domain controller to alter the administrator account password to \\”TheFr0zenCrew!\\” and erase 13 domain admin accounts, and reset the passwords of 301 user accounts to the same string. Additionally, he modified passwords for two local admin accounts to \\”PsPasswd,\\” which blocked access to 254 servers, and changed passwords for two other admin accounts, disrupting 3,284 workstations.

Over several days in December 2023, Rhyne also initiated random server and workstation shutdowns. On November 25, 2023, Rhyne sent a ransom demand titled \\”Your Network Has Been Penetrated,\\” claiming that server backups had been deleted to prevent data recovery. He threatened to disable 40 random servers daily for 10 days unless the company paid a 20 Bitcoin ransom, equivalent to approximately $750,000 at the time.

Investigation and Findings

Network administrators began receiving password reset alerts for domain admin accounts and user accounts around 4:00 p.m. EST on November 25. Subsequent investigations revealed the deletion of all domain admin accounts, effectively cutting off administrative access to the company’s systems. During the planning phase of the attack, Rhyne used a hidden virtual machine to search for methods to alter domain user passwords, remove domain accounts, and clear Windows logs. One week prior to the attack, he conducted searches on his personal laptop for commands to remotely change local admin passwords and shut down computers via the command line.

Related Case and Industry Context

In a separate case earlier this year, 27-year-old Cameron Curry, a data analyst contractor for Brightly Software, received a two-year prison sentence for extorting his employer with a $2.5 million demand. The investigation into Rhyne’s activities highlighted the use of specific password manipulation techniques, unauthorized access methods, and the deployment of scheduled tasks to escalate control over the network.

Implications and Conclusion

The case underscores the risks associated with insider threats and the potential for malicious actors to exploit privileged credentials for destructive purposes. Rhyne’s sentencing reflects the severity of his actions, which disrupted critical infrastructure and caused significant operational harm to the affected organization. The incident serves as a cautionary example of how compromised internal access can lead to large-scale network failures and financial repercussions.

According to court documents: \\”Your Network Has Been Penetrated.\\”


Blog Image

About Author

en_USEnglish