A former infrastructure engineer has been sentenced to 32 months in federal prison after admitting he sabotaged his employer’s computer systems and demanded bitcoin to halt further disruption. Federal prosecutors said the attack targeted a New Jersey-based industrial company where he had held a privileged technical role.
Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced on Sept. 28 in federal court in Trenton. He had previously pleaded guilty to extortion involving a threat to damage a protected computer and to intentionally damaging a protected computer.
Attack carried out through hidden access
According to investigators, Rhyne worked as a core infrastructure engineer for the unnamed company and had administrative access to its systems. Prosecutors said he created a hidden virtual machine inside the company network and protected it with the password “TheFr0zenCrew!” to preserve remote access.
Using that hidden system, authorities said, he connected to an administrator account and prepared a series of automated tasks to run on Nov. 25, 2023. The planned commands were designed to strip the company of control over key systems and credentials.
Company systems and accounts were disrupted
Court filings said the automated actions were set to delete 13 domain administrator accounts, reset passwords for 301 user accounts, alter local administrator passwords on 254 servers, and change credentials associated with more than 3,200 employee workstations.
Other scheduled tasks were intended to shut down company servers and computers, prosecutors said, with the goal of denying the business access to its own systems and data. At about 4 p.m. on Nov. 25, network administrators discovered that their accounts had been deleted.
Bitcoin demand followed within minutes
Roughly 44 minutes after the account deletions were detected, employees received an extortion email, according to the complaint. The message claimed that all IT administrator accounts had been deleted and that backups had been erased.
The sender threatened to shut down 40 additional servers each day for 10 days unless the company paid about 20 bitcoin by Dec. 2. Prosecutors said that amount was worth about $750,000 at the time. The source article noted that the same sum would be worth about $1.67 million at current prices.
Investigators traced the activity back to Rhyne
Authorities said the complaint also described preparation in the days before the incident. Searches made from the hidden virtual machine allegedly included queries on how to change administrator passwords from a command line, delete a domain account, and remotely shut down a computer. Similar searches were also found on Rhyne’s company laptop.
Investigators said they connected the hidden virtual machine to Rhyne’s account and laptop. They also found that the password securing the extortion email address was “TheFr0zenCrew!”, matching the password used on the hidden virtual machine.
Confirmed outcome of the case
The criminal case has now produced a prison sentence following Rhyne’s guilty plea. The confirmed outcome reported in the case is a 32-month federal sentence imposed in Trenton on Sept. 28.
Beyond that sentencing result, the source report does not identify the employer by name or describe any further court steps. What is established in the record summarized by prosecutors is the sequence of sabotage, the bitcoin demand, and the convictions tied to damaging protected computers and extortion.
Source: news.bitcoin.com