Engineer sentenced for locking over 3,000 employer devices
Daniel Rhyne received 32 months for locking over 3,000 devices on a New Jersey employer's network and demanding about $750,000 in bitcoin.
Daniel Rhyne of Kansas City, Missouri, a former core infrastructure engineer at an unnamed industrial company headquartered in New Jersey, was sentenced on September 28, 2026, to 32 months in federal prison in Trenton after pleading guilty to extortion and intentional damage to a protected computer. Sources disagree on his age, stating 57 or 59, and on timing: one report places the conduct in November–December 2023, while others date it to November 2023 or specifically November 25, 2023. Using scheduled tasks on a domain controller—reached, two reports say, through a hidden virtual machine and a domain administrator account, including remote desktop—he deleted 13 domain administrator accounts, reset passwords for 301 domain users, and changed local administrator passwords affecting 254 servers and 3,284 workstations, which outlets also describe as locking more than 3,000 devices. An email demanded 20 bitcoin, then about $750,000, and threatened daily server shutdowns; one outlet specifies 40 servers a day for ten days and says no file encryption was shown, so the impact was lockouts and scheduled shutdowns rather than ransomware encryption, though two reports still call it a ransomware-style attack. Investigators tied the activity to his laptop, badge records, footage, home IP, and the reused password TheFr0zenCrew!, and court documents show he had researched password changes, deleting accounts, and clearing Windows logs. One outlet also noted a separate case in which contractor Cameron Curry received two years in March for extorting Brightly Software for $2.5 million.
- Daniel Rhyne of Kansas City, Missouri, a former core infrastructure engineer, was sentenced on September 28, 2026, to 32 months in federal prison in Trenton after pleading guilty to extortion and intentional damage to a protected computer;…
- The unnamed industrial employer is headquartered in New Jersey. Reports place the conduct in November–December 2023, November 2023, or specifically November 25, 2023.
- Scheduled tasks on a domain controller deleted 13 domain administrator accounts, reset passwords for 301 domain users, and changed local administrator passwords affecting 254 servers and 3,284 workstations, also described as locking more…
- Two reports say access used a hidden virtual machine and a domain administrator account, including remote desktop.
- An email demanded 20 bitcoin, then about $750,000, and threatened daily server shutdowns; one report specifies 40 servers a day for ten days.
- One outlet says no file encryption was shown and the impact was lockouts and scheduled shutdowns; two others still call the case ransomware-style.
- Investigators linked the activity to his laptop, badge records, footage, home IP, and the reused password TheFr0zenCrew!; court documents show he researched password changes, deleting accounts, and clearing Windows logs.
- Separately, one report says contractor Cameron Curry received two years in March for extorting Brightly Software for $2.5 million.
Coverage timelineoldest first · each row is one article
- · 4d agoEngineer sentenced for locking over 3,000 devices on employer network
BleepingComputer· 45
Former New Jersey industrial company engineer Daniel Rhyne sentenced to 32 months for locking over 3,000 devices and demanding 20 bitcoin from his employer.
- · 4d agoFormer Employee Sentenced for Damaging Employer’s Windows Network Infrastructure
GBHackers· 42
Former engineer Daniel Rhyne got 32 months for sabotaging a New Jersey employer's Windows network and demanding Bitcoin.
- · 4d agoFormer Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network
Cyber Security News· 52