A particularly disturbing cybersecurity case in the United States highlights the dangers posed not only by external attackers, but also by individuals within organizations themselves. A former infrastructure engineer has pleaded guilty to orchestrating a blackmail attack against his own employer (an industrial company in New Jersey), successfully blocking administrator access to hundreds of Windows systems.

According to court documents , Daniel Rhyne, 57 , gained unauthorized access to the company's network using an administrator account for several days in November. During that time, he planned and executed a series of automated actions aimed at completely destabilizing the IT infrastructure .
The methodology of the attack and the extent of the damage
The attack was based on scheduled tasks on Windows domain controllers, through which the attacker deleted administrator accounts and changed passwords en masse. Specifically, he affected dozens of high-privilege accounts and hundreds of user accounts, setting a common password that effectively nullified any control from the company's side.
See also: NoVoice: New Android malware on Google Play
It also targeted local administrator accounts, affecting thousands of workstations and hundreds of servers. In some cases, it even programmed random system shutdowns for days, increasing pressure and confusion within the organization.
This coordinated action resulted in administrators being completely locked out of critical systems, leading to operational chaos and significant risk of data loss.
The blackmail message and ransom demands
The attack culminated in an email sent to company employees, in which the attacker claimed that the network had been completely compromised. He also claimed that backups had been deleted, making it impossible to recover the data without their cooperation.

In the same message, he demanded a ransom 20 bitcoins , equivalent to approximately $750,000 at the time. He also threatened to shut down dozens of servers daily if his demands were not met, in an attempt to increase pressure on the administration.
See also: PXA Stealer malware campaign from Vietnam exploits LinkedIn
Digital traces and preparation of the attack
Investigations revealed that the attack was the result of careful planning. Analysts identified that Daniel Rhyne had conducted a series of searches on techniques for deleting log files and managing Windows accounts, both from corporate and personal systems.
In fact, he used a virtual machine to hide his activity, attempting to reduce the digital traces that could link him to the attack. Despite these efforts, the evidence collected was sufficient for his arrest and confession.
The broader dimensions of the internal threat
This case highlights a critical issue for cybersecurity: the insider threat. Unlike external attackers, internal users already have knowledge of the infrastructure and often have elevated access rights, which makes their attacks harder to detect and more destructive.
Similar incidents have begun to increase, with recent cases of extortion even involving company employees or contractors. The increasing reliance on digital infrastructure makes such attacks particularly dangerous, especially when combined with inadequate access control.
See also: Intesa Sanpaolo: Unauthorized access for 2 Years
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The importance of prevention and security checks
This case highlights the need for stricter management of privileged accounts and continuous activity monitoring. Practices such as the zero trust model, multi-factor authentication , and real-time logging can significantly reduce such incidents.
At the same time, staff training and timely revocation of access rights for departing employees are key prevention measures. In a world where cybersecurity is constantly evolving, organizations are called upon to address not only external risks, but also threats that are already within their walls.
Source: www.bleepingcomputer.com
