A former core infrastructure engineer at an industrial company in New Jersey has been sentenced to 32 months in prison after attacking his former employer’s computer network and demanding a Bitcoin ransom. The defendant, 59-year-old Daniel Rhyne of Kansas City, Missouri, was sentenced on Sept. 28 in Trenton by U.S. District Judge Michael A. Shipp. He had already pleaded guilty in April to extortion involving threats to damage a protected computer and intentional damage to a protected computer.
Prosecutors did not name the victim company, saying only that it is headquartered in Somerset County, New Jersey, and serves clients across industries including biopharmaceuticals and oil and gas. According to an FBI criminal complaint, the company’s network administrator began receiving hundreds of password reset notifications at about 4 p.m. on Nov. 25, 2023, and then discovered that all other domain administrator accounts had been deleted.
Forty-four minutes later, employees received an email titled 「Your Network Has Been Penetrated」 claiming that IT administrators had been locked out and backups had been deleted. The message demanded 20 BTC by Dec. 2, then worth about $750,000, and warned that 40 more servers would be shut down each day for 10 days if payment was not made. Investigators traced the attack to an unauthorized virtual machine created on the company network on Nov. 9, 2023.
Daniel Rhyne, a former core infrastructure engineer at an industrial company in New Jersey, has been sentenced to 32 months in prison for attacking his former employer’s computer network and demanding a Bitcoin ransom.
Rhyne, 59, is from Kansas City, Missouri. He was sentenced on Sept. 28 in Trenton by U.S. District Judge Michael A. Shipp. He had pleaded guilty in April to extortion involving threats to damage a protected computer and intentional damage to a protected computer.
Victim company not identified
Prosecutors did not disclose the company’s name. They said it is headquartered in Somerset County, New Jersey, and serves customers in sectors ranging from biopharmaceuticals to oil and gas.
FBI complaint details the attack
According to an FBI criminal complaint, at about 4 p.m. on Nov. 25, 2023, the company’s network administrator began receiving hundreds of password reset notifications tied to user accounts. The administrator then found that all other domain administrator accounts had been deleted.
Forty-four minutes later, employees received an email with the subject line 「Your Network Has Been Penetrated」. The message said the company’s IT administrators had been locked out and backups had been deleted. It warned that unless the company paid 20 BTC by Dec. 2, worth about $750,000 at the time, another 40 servers would be shut down each day for 10 days.
The email also set the ransom at 700,000 euros, payable in Bitcoin.
Attack traced to unauthorized virtual machine
Investigators traced the intrusion to an unauthorized virtual machine created on the company’s network on Nov. 9, 2023. Its password was set as 「TheFr0zenCrew!」. Investigators said the same password was later applied to administrator accounts, 301 user accounts, and the mailbox used to send the extortion email.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.