A former core infrastructure engineer has been sentenced to 32 months in prison for attacking his employer’s network and trying to extort a Bitcoin payment from the company. Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced in September by U.S. District Judge Michael A. Shipp in Trenton after pleading guilty to extortion and damaging a protected computer.
Prosecutors said the scheme involved disabling key administrative access, deleting backups and threatening additional disruption unless the company paid 20 BTC, worth about $750,000 at the time. The case centered on an internal attack launched against the employer’s own systems rather than an outside intrusion.
Attack tied to hidden virtual machine
According to investigators, the FBI traced the incident to a concealed virtual machine created inside the company’s network. A password, “TheFr0zenCrew!,” was allegedly used across multiple accounts connected to the activity.
Authorities said the machine was linked to the attack on November 9, 2023. A remote desktop session from that system was used to create tasks that deleted backups, removed administrator accounts, changed passwords across hundreds of servers and workstations, and prepared additional shutdown actions.
Ransom demand followed administrator lockout
The company’s administrators began receiving password reset notifications on November 25, 2023, and then discovered that domain administrator accounts had been deleted. Roughly 44 minutes later, an email with the subject line “Your Network Has Been Penetrated” arrived with a ransom demand.
That message claimed IT administrators had been locked out and backups erased. It also threatened to shut down 40 more servers each day for 10 days unless the company paid 20 BTC by December 2, 2023. At the time, prosecutors said, that amount was worth about $750,000.
Investigators connected activity to Rhyne
Federal investigators said they linked the hidden machine to Rhyne through his company-issued laptop and network records. According to the case, internet browsing on the laptop stopped whenever the hidden virtual machine was active, suggesting the same device was being used in connection with the concealed environment.
Logs also showed Rhyne entering the company’s headquarters shortly before his account was used to log in, investigators said. Authorities described the operation as building toward a further phase in which dozens of servers would be shut down starting on December 3.
Charges, plea and sentence
Rhyne had also faced a wire fraud charge, in addition to extortion and damaging a protected computer. But the two-count information to which he pleaded guilty covered only extortion and damage to a protected computer.
Those offenses carried maximum penalties of five years for extortion and 10 years for damaging a protected computer. Judge Shipp ultimately imposed a 32-month prison sentence, resolving the criminal case on the counts in Rhyne’s plea.
What the case establishes
The confirmed outcome is that a former employee admitted to the extortion and computer damage charges and received a federal prison sentence. The underlying allegations describe a ransomware-style pressure campaign carried out from within the employer’s own network, with Bitcoin named as the demanded payment method.
Beyond the sentence already imposed in September, the article does not describe any further court action or any indication that the ransom was paid. The clearest next confirmed point in the record is the sentencing itself and the facts presented by investigators and prosecutors in support of the plea.
Source: decrypt.co