A former infrastructure engineer for an industrial company in New Jersey was sentenced to 32 months in prison for carrying out a ransomware attack against his former employer, using the knowledge and access rights he had acquired during his employment.

Daniel Rhyne, 57, of Kansas City, Missouri, pleaded guilty to attempted extortion of the company . Rhyne was arrested in August 2024 and arraigned in federal court, and the case has once again highlighted the serious risk that an employee or former employee can pose when they have extensive access privileges to critical infrastructure.
The attack was launched from an administrator account
According to court documents, Rhyne gained unauthorized remote access to the company network and used an administrator account to perform a series of destructive actions.
See also: Ransomware at the University of Illinois Chicago – The Medical School is in the spotlight
Between November 8 and 25, he scheduled tasks on the company's domain controller that password administrator account and deleted 13 domain administrator accounts. also changed the passwords of 301 user accountsusing the same password.
This particular tactic had a clear goal: to drastically limit the ability of legitimate administrators to regain control of the infrastructure.
Thousands of computers went out of service
The attack was not limited to user accounts. Rhyne also created scheduled tasks that modified the passwords of two local administrator accounts, blocking access to 254 servers.
At the same time, two more administrator accounts were used in a way that blocked access to approximately 3,284 workstations. Over the course of several days in December 2023, the perpetrator also remotely shut down servers and computers.
The incident shows how a compromised administrator account can be turned into a tool for mass disruption. In such cases, the attacker does not necessarily need to install a classic ransomware on every device. The abuse of existing administrative tools and privileges can itself cause similar operational chaos.

The requirement for 20 Bitcoins
On November 25, Rhyne sent his colleagues an email with the subject line “Your Network Has Been Penetrated,” informing them that the company network had been breached.
See also: FBI fires Accenture contractor after ShinyHunters breach
The message claimed that backups had been deleted server, implying that data recovery was impossible. It also threatened to disable 40 random servers every day for ten days if the company did not pay 20 Bitcoin.
At the time of the attack, the amount was equivalent to approximately $750,000. The demand in cryptocurrency followed a model that has become particularly prevalent in ransomware attacks, as digital currencies can be used to demand payments without directly using traditional banking systems.
The searches that revealed the preparation
Researchers also found evidence that the attack was not spontaneous. On November 22, while preparing the extortion plan, Rhyne used his account in a hidden virtual machine to search for information about changing user passwords, deleting domain accounts, and clearing Windows logs.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A week earlier, he had conducted similar searches on his laptop. Among other things, he was looking for ways to change the local administrator password, change passwords remotely, and shut down computers via the command line.
These searches are particularly important because they capture the transition from preparation to execution. At the same time, they highlight the importance of monitoring unusual activity in corporate systems, especially when it is combined with elevated access rights.
The risk of insider threats
The Rhyne case is a typical example of the so-called insider threat, that is, the threat coming from an individual who has or had legal access to the corporate infrastructure.

For businesses, this incident highlights the need to implement the principle of least privilege, ensuring that each employee has only the rights required for their role. Equally important is the immediate revocation of accounts and credentials after employees leave, as well as the use of multi-factor authentication, privileged access management, and suspicious behavior detection systems.
Backups also need special protection . Backups should be sufficiently isolated from the main network so that a compromised account cannot delete or modify them.
See also: Social Engineering: Real-time threat detection
This is not the only recent case
Rhyne's conviction comes on the heels of another employee extortion case. In March, Cameron Curry, an outsourcing and data analyst in North Carolina, was sentenced to two years in prison for extorting money from Brightly Software.
In that case, Curry demanded about $2.5 million from the company, which shows that insider threats can take different forms, from data theft to the paralysis of critical infrastructure.
The two cases serve as a reminder that cybersecurity is not just about defending against unknown external hackers. Managing privileged accounts, monitoring administrator actions, and properly terminating staff are equally critical elements of a modern protection strategy.
source: www.bleepingcomputer.com
