HomeSecurityFormer engineer convicted of ransomware attack on his company

Former engineer convicted of ransomware attack on his company

A former infrastructure engineer for an industrial company in New Jersey was sentenced to 32 months in prison for carrying out a ransomware attack against his former employer, using the knowledge and access rights he had acquired during his employment.

Former engineer convicted of ransomware attack on his company

Daniel Rhyne, 57, of Kansas City, Missouri, pleaded guilty to attempted extortion of the company . Rhyne was arrested in August 2024 and arraigned in federal court, and the case has once again highlighted the serious risk that an employee or former employee can pose when they have extensive access privileges to critical infrastructure.

The attack was launched from an administrator account

According to court documents, Rhyne gained unauthorized remote access to the company network and used an administrator account to perform a series of destructive actions.

See also: Ransomware at the University of Illinois Chicago – The Medical School is in the spotlight

Between November 8 and 25, he scheduled tasks on the company's domain controller that password administrator account and deleted 13 domain administrator accounts. also changed the passwords of 301 user accountsusing the same password.

This particular tactic had a clear goal: to drastically limit the ability of legitimate administrators to regain control of the infrastructure.

Thousands of computers went out of service

The attack was not limited to user accounts. Rhyne also created scheduled tasks that modified the passwords of two local administrator accounts, blocking access to 254 servers.

At the same time, two more administrator accounts were used in a way that blocked access to approximately 3,284 workstations. Over the course of several days in December 2023, the perpetrator also remotely shut down servers and computers.

The incident shows how a compromised administrator account can be turned into a tool for mass disruption. In such cases, the attacker does not necessarily need to install a classic ransomware on every device. The abuse of existing administrative tools and privileges can itself cause similar operational chaos.

Former engineer convicted of ransomware attack on his company

The requirement for 20 Bitcoins

On November 25, Rhyne sent his colleagues an email with the subject line “Your Network Has Been Penetrated,” informing them that the company network had been breached.

See also: FBI fires Accenture contractor after ShinyHunters breach

The message claimed that backups had been deleted server, implying that data recovery was impossible. It also threatened to disable 40 random servers every day for ten days if the company did not pay 20 Bitcoin.

At the time of the attack, the amount was equivalent to approximately $750,000. The demand in cryptocurrency followed a model that has become particularly prevalent in ransomware attacks, as digital currencies can be used to demand payments without directly using traditional banking systems.

The searches that revealed the preparation

Researchers also found evidence that the attack was not spontaneous. On November 22, while preparing the extortion plan, Rhyne used his account in a hidden virtual machine to search for information about changing user passwords, deleting domain accounts, and clearing Windows logs.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A week earlier, he had conducted similar searches on his laptop. Among other things, he was looking for ways to change the local administrator password, change passwords remotely, and shut down computers via the command line.

These searches are particularly important because they capture the transition from preparation to execution. At the same time, they highlight the importance of monitoring unusual activity in corporate systems, especially when it is combined with elevated access rights.

The risk of insider threats

The Rhyne case is a typical example of the so-called insider threat, that is, the threat coming from an individual who has or had legal access to the corporate infrastructure.

Former engineer convicted of ransomware attack on his company

For businesses, this incident highlights the need to implement the principle of least privilege, ensuring that each employee has only the rights required for their role. Equally important is the immediate revocation of accounts and credentials after employees leave, as well as the use of multi-factor authentication, privileged access management, and suspicious behavior detection systems.

Backups also need special protection . Backups should be sufficiently isolated from the main network so that a compromised account cannot delete or modify them.

See also: Social Engineering: Real-time threat detection

This is not the only recent case

Rhyne's conviction comes on the heels of another employee extortion case. In March, Cameron Curry, an outsourcing and data analyst in North Carolina, was sentenced to two years in prison for extorting money from Brightly Software.

In that case, Curry demanded about $2.5 million from the company, which shows that insider threats can take different forms, from data theft to the paralysis of critical infrastructure.

The two cases serve as a reminder that cybersecurity is not just about defending against unknown external hackers. Managing privileged accounts, monitoring administrator actions, and properly terminating staff are equally critical elements of a modern protection strategy.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS