Cyber Extortion Insider Threat: Industrial Firm Engineer Sentenced to Prison

www.news4hackers.com-cyber-extortion-insider-threat-industrial-firm-engineer-sentenced-to-prison-cyber-extortion-insider-threat-industrial-firm-engineer-sentenced-to-prison

A Kansas City, Missouri man has received a 32-month prison sentence for orchestrating a ransomware attack targeting his former employer.

Background of the Case

The Department of Justice confirmed the sentencing of Daniel Rhyne, who had previously admitted to charges including extortion related to damage of a protected computer and intentional harm to a protected computer. Rhyne served as a core infrastructure engineer at an industrial company based in Somerset County, New Jersey. The firm operates across multiple sectors, including aquaculture, biopharmaceuticals, chemistry, electronics, food and beverage, healthcare, hydrogen mobility, manufacturing, metals, oil and gas, and pulp and paper.

The Perpetrator and His Role

In November 2023, Rhyne executed a series of malicious actions on the company’s domain controller. He configured automated tasks to delete 13 domain administrator accounts, alter passwords for 301 domain user accounts, and change credentials for two local administrator accounts affecting 254 servers. Additionally, he modified passwords for two local administrator accounts impacting 3,284 workstations. These actions disrupted the company’s access to critical systems and data.

The Ransom Demand and Response

The altered passwords were typically set to “TheFr0zenCrew!”, a credential associated with the attack. The scheduled tasks were executed in the late afternoon on November 25. Within an hour of the attacks, employees received an email from an external source. The message, titled “Your Network Has Been Penetrated,” warned that administrators had been locked out or removed, backups deleted, and that 40 servers would be shut down daily over 10 days unless a ransom was paid. Rhyne demanded 20 Bitcoin, equivalent to approximately $750,000 at the time. The victim organization did not comply with the ransom request but initiated an internal forensic investigation.

The Attack and Aftermath

It cross-referenced network logs with physical access records and collaborated with the FBI. The FBI traced the unauthorized activity to Rhyne’s residential IP address in Warren County, New Jersey. This led to the filing of a criminal complaint by FBI Special Agent Timothy Lee on August 8, 2024, resulting in Rhyne’s arrest on August 27, 2024, in Kansas City, where he had relocated. He pleaded guilty on April 1, 2026, in federal court in Trenton, New Jersey, before District Judge Michael A. Shipp. The sentencing occurred on September 28, 2026, with Rhyne receiving a 32-month prison term for his role in the sabotage and extortion scheme.

According to the Department of Justice, Rhyne’s actions caused significant disruption to the company’s operations and highlighted the risks of insider threats in critical industries.

FBI Special Agent Timothy Lee stated, “This case underscores the importance of collaboration between private sector entities and law enforcement to combat cybercrime and hold perpetrators accountable.”



About Author

en_USEnglish