A former engineer at a New Jersey industrial company has been sentenced to 32 months in prison for attacking his employer’s computer network and demanding a Bitcoin ransom, federal prosecutors said Monday.
Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced on Sept. 28 by U.S. District Judge Michael A. Shipp in Trenton. He had pleaded guilty in April to extortion in relation to a threat to damage a protected computer and to intentional damage to a protected computer.
Attack targeted an unnamed industrial company
According to the FBI criminal complaint, Rhyne had been the company’s core infrastructure engineer and its subject matter expert on hosting virtual machines. Prosecutors did not name the company. They said it is headquartered in Somerset County, New Jersey, and serves industries ranging from biopharmaceuticals to oil and gas.
At about 4 p.m. on Nov. 25, 2023, the company’s network administrators began receiving password reset notifications for hundreds of accounts. They then found that all other domain administrator accounts had been deleted, the complaint said.
Forty-four minutes later, employees received an email with the subject line “Your Network Has Been Penetrated.” The message said the company’s IT administrators had been locked out and its backups deleted. It warned that 40 more servers would be shut down each day for 10 days unless 20 BTC, worth about $750,000 at the time, was paid by Dec. 2.
The complaint also said the email set the ransom at €700,000, payable in Bitcoin.
Investigators traced the incident to a hidden virtual machine
Investigators linked the attack to an unauthorized virtual machine created on the company’s network on Nov. 9, 2023. Its password was “TheFr0zenCrew!”, the same password later set on the administrator account, on 301 user accounts, and on the email account that sent the ransom demand.
On the morning of the attack, a remote desktop session from that machine created scheduled tasks to delete 13 administrator accounts, change passwords affecting 254 servers and 3,284 workstations, and shut down dozens of servers starting Dec. 3, according to the complaint.
The FBI tied the machine to Rhyne through his company laptop. The complaint said browsing on the laptop stopped whenever browsing took place on the hidden machine. Building access logs also showed him entering headquarters minutes before his account logged in.
On the day of the attack, Rhyne’s laptop connected to the company network from an IP address assigned to his home in Warren County, New Jersey, minutes before the session that set up the scheduled tasks.
Search history and charging details
Days before the attack, the machine’s user searched for “how to clear all windows logs from command line” and “how to remotely shutdown a computer using cmd,” the complaint said.
The complaint also charged Rhyne with wire fraud, though that count did not appear in the two-count information to which he pleaded guilty. He had faced a maximum of five years on the extortion count and 10 years on the damage count.

