Skip to content

Engineer gets 32 months for locking out his own employer

Daniel Rhyne, a core infrastructure engineer, was sentenced to 32 months for deleting admin accounts and demanding 20 BTC from the New Jersey industrial firm that employed him.

Published 3 min read

Daniel Rhyne, a former core infrastructure engineer, was sentenced on September 28, 2026 to 32 months in federal prison for sabotaging the network of the New Jersey industrial firm that employed him and then demanding a bitcoin ransom to undo the damage. He pleaded guilty on April 1, 2026, in federal court in Trenton before U.S. District Judge Michael A. Shipp.

What he did

Over November 8–25, 2023, Rhyne used an administrator account without authorization and scheduled tasks on the company's domain controller to lock the firm out of its own systems, SecurityWeek reports. The tasks:

  • deleted 13 domain administrator accounts;
  • changed passwords on 301 domain user accounts;
  • changed passwords on two local admin accounts across 254 servers and two more across 3,284 workstations.

Most passwords were reset to the string TheFr0zenCrew!. The scheduled jobs finished late on November 25.

The extortion

Within an hour, employees received an email titled "Your Network Has Been Penetrated." It claimed backups were gone and threatened to shut down 40 random servers a day for ten days unless the company paid 20 bitcoin — roughly $750,000 at the time, per Decrypt. The firm, headquartered in Somerset County and unnamed in court filings, paid nothing. It ran its own forensic analysis, correlated system logs with physical-access records, and brought in the FBI.

The Bureau traced the activity to Rhyne's residential IP address. FBI Special Agent Timothy Lee filed the criminal complaint in the District of New Jersey on August 8, 2024; Rhyne was arrested on August 27, 2024, in Kansas City, where he had relocated.

The complaint is the primary record here — the DOJ announced the sentencing without a separate press release locatable as of writing.

What to do today

Insider sabotage by a privileged admin defeats most perimeter controls. The defenses that would have caught this are mundane:

  1. Alert on bulk account and password changes. Deleting 13 domain admins and resetting 301 user passwords in one window is a detection that should fire on its own, independent of who did it.
  2. Require change control on domain-controller scheduled tasks. Rhyne's attack ran as scheduled jobs; a tamper-alert on DC task creation would have surfaced it before execution.
  3. Keep offline, tested backups and verify restore paths — the extortion leverage was the claim that backups were deleted.
  4. Enforce separation of duties and session recording for Tier-0 access, so no single engineer can both make and hide these changes.

Context

The firm's refusal to pay and its own log-to-badge correlation are what closed the case — not any upstream threat intel. Insider cases rarely get the coverage a ransomware gang does, but the blast radius here (3,284 workstations, 254 servers) matches a mid-sized ransomware hit, executed by someone who already held the keys. The lesson isn't a new tool; it's that Tier-0 activity needs the same monitoring you point at external attackers.

Related stories