Former Engineer Sentenced to 32 Months Over Bitcoin Extortion Attack on Employer

Former Engineer Sentenced to 32 Months Over Bitcoin Extortion Attack on Employer

N
News Editor
2026-10-07 12:39:09
A former engineer at a New Jersey industrial company has been sentenced to 32 months in prison after carrying out a computer attack against his own employer and demanding a Bitcoin ransom, according to federal prosecutors. Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced on Sept. 28 by U.S. District Judge Michael A. Shipp in Trenton after pleading guilty in April to extortion tied to a threat to damage a protected computer and to intentional damage to a protected computer. The FBI complaint said Rhyne had served as the company’s core infrastructure engineer and internal expert on hosting virtual machines. Prosecutors did not identify the company, saying only that it is based in Somerset County, New Jersey, and serves sectors ranging from biopharmaceuticals to oil and gas. Investigators said the attack began on Nov. 25, 2023, when administrators saw password reset notices for hundreds of accounts and discovered that other domain administrator accounts had been deleted. Employees later received a message titled “Your Network Has Been Penetrated,” which said IT administrators had been locked out, backups had been deleted, and 40 more servers would be shut down each day for 10 days unless 20 BTC, worth about $750,000 at the time, was paid by Dec. 2. Investigators traced the incident to an unauthorized virtual machine and linked it to Rhyne through laptop activity, access logs, and an IP address assigned to his home.

A former engineer at a New Jersey industrial company has been sentenced to 32 months in prison for attacking his employer’s computer network and demanding a Bitcoin ransom, federal prosecutors said Monday.

Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced on Sept. 28 by U.S. District Judge Michael A. Shipp in Trenton. He had pleaded guilty in April to extortion in relation to a threat to damage a protected computer and to intentional damage to a protected computer.

Attack targeted an unnamed industrial company

According to the FBI criminal complaint, Rhyne had been the company’s core infrastructure engineer and its subject matter expert on hosting virtual machines. Prosecutors did not name the company. They said it is headquartered in Somerset County, New Jersey, and serves industries ranging from biopharmaceuticals to oil and gas.

At about 4 p.m. on Nov. 25, 2023, the company’s network administrators began receiving password reset notifications for hundreds of accounts. They then found that all other domain administrator accounts had been deleted, the complaint said.

Forty-four minutes later, employees received an email with the subject line “Your Network Has Been Penetrated.” The message said the company’s IT administrators had been locked out and its backups deleted. It warned that 40 more servers would be shut down each day for 10 days unless 20 BTC, worth about $750,000 at the time, was paid by Dec. 2.

The complaint also said the email set the ransom at €700,000, payable in Bitcoin.

Investigators traced the incident to a hidden virtual machine

Investigators linked the attack to an unauthorized virtual machine created on the company’s network on Nov. 9, 2023. Its password was “TheFr0zenCrew!”, the same password later set on the administrator account, on 301 user accounts, and on the email account that sent the ransom demand.

On the morning of the attack, a remote desktop session from that machine created scheduled tasks to delete 13 administrator accounts, change passwords affecting 254 servers and 3,284 workstations, and shut down dozens of servers starting Dec. 3, according to the complaint.

The FBI tied the machine to Rhyne through his company laptop. The complaint said browsing on the laptop stopped whenever browsing took place on the hidden machine. Building access logs also showed him entering headquarters minutes before his account logged in.

On the day of the attack, Rhyne’s laptop connected to the company network from an IP address assigned to his home in Warren County, New Jersey, minutes before the session that set up the scheduled tasks.

Search history and charging details

Days before the attack, the machine’s user searched for “how to clear all windows logs from command line” and “how to remotely shutdown a computer using cmd,” the complaint said.

The complaint also charged Rhyne with wire fraud, though that count did not appear in the two-count information to which he pleaded guilty. He had faced a maximum of five years on the extortion count and 10 years on the damage count.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.