A former core infrastructure engineer has been sentenced to 32 months in prison after carrying out a ransomware-style attack against his former employer’s computer network. Daniel Rhyne, 59, of Kansas City, Missouri, pleaded guilty to charges involving intentional damage to a protected computer and extortion. The company was a U.S.-based industrial organization headquartered in New Jersey. The sentence was imposed by U.S. District Judge Michael A. Shipp on September 28, 2026.
Rhyne carried out the attack in November 2023 after gaining unauthorized remote access to the company’s network using an administrator account. He prepared scheduled tasks that could delete administrator accounts, change passwords and shut down servers across the company’s systems. Court documents showed that these actions were designed to disrupt access to the organization’s network and its devices. The incident demonstrated how dangerous privileged access can become when it is deliberately misused.
The attack affected thousands of systems through changes made to administrator accounts and passwords. Rhyne scheduled password changes that blocked access to 254 servers and another 3,284 workstations on the company’s network. He also deleted 13 domain administrator accounts and changed the passwords of 301 domain user accounts. Several servers and workstations were also scheduled to be shut down during December 2023.
On November 25, 2023, Rhyne sent an extortion email to employees at the company demanding approximately 20 Bitcoin. The cryptocurrency was worth around $750,000 at the time of the demand. He threatened to continue shutting down company servers unless the ransom was paid. The email also claimed that the company’s server backups had been deleted, making recovery more difficult.
Investigators later found evidence showing that Rhyne had been preparing for the attack before carrying it out. During the planning stage, he searched for information about changing domain passwords, deleting administrator accounts and clearing Windows logs. Investigators also found searches related to remotely changing local administrator passwords and shutting down computers using command-line tools. These searches helped investigators connect his activity with the planned attack.
The case highlights the serious risks that organizations can face from insiders who have access to critical systems. Unlike many external ransomware attacks, Rhyne was able to use his knowledge and privileged access to disrupt the company’s network directly. The investigation was conducted by the FBI’s Newark Field Office with assistance from the FBI’s Kansas City Field Office. The case is a reminder that organizations need strong controls around administrator accounts, continuous monitoring and rapid access removal when trusted employees leave.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news