3 min read

IT engineer gets 32 months in prison after sabotaging employer and demanding $750,000

Filip TRUȚĂ

October 07, 2026

IT engineer gets 32 months in prison after sabotaging employer and demanding $750,000

An infrastructure engineer used his knowledge of his employer’s network to lock administrators out, disrupt servers and demand $750,000 in Bitcoin. He will now spend almost three years behind bars.

A former infrastructure engineer who turned his privileged access against his employer, sabotaging its computer network before demanding ransom, has been sentenced to 32 months in federal prison.

Key takeaways

  • Former infrastructure engineer Daniel Rhyne was sentenced to 32 months in prison for computer sabotage and extortion
  • Prosecutors say he used unauthorized remote desktop sessions and scheduled tasks to attack his employer’s network
  • The attack deleted administrator accounts, changed passwords and shut down servers
  • Court documents indicate the planned password changes could affect thousands of computers
  • Rhyne demanded 20 Bitcoin, worth roughly $750,000 at the time, to stop the disruption

From infrastructure engineer to extortionist

Daniel Rhyne, 59, of Kansas City, Missouri, worked as a core infrastructure engineer at a US-based industrial company headquartered in New Jersey.

According to the US Department of Justice, Rhyne began preparing an attack against the company’s network in November 2023.

Rather than breaking in using some sophisticated vulnerability exploit, prosecutors say Rhyne initiated unauthorized remote desktop sessions and created scheduled tasks designed to damage the network.

Those tasks could delete network administrator accounts, change passwords belonging to other users and shut down company servers.

On Nov. 25, 2023, Rhyne sent an extortion email threatening to continue shutting down servers unless the company handed over approximately 20 Bitcoin – worth about $750,000 at the time.

It was, in effect, a ransomware-style extortion attempt without the traditional ransomware.

Thousands of computers potentially affected

Court documents previously reported by BleepingComputer offer a clearer picture of just how disruptive the scheme was designed to be.

Rhyne allegedly scheduled tasks that would delete 13 domain administrator accounts and change passwords of 301 domain users.

Other password changes targeting local administrator accounts could affect 254 servers and 3,284 workstations, according to the criminal complaint.

The goal was straightforward: deny the company and its administrators access to their own systems.

Investigators also found evidence of web searches made while the scheme was being prepared, including searches for ways to delete domain accounts, clear Windows logs and remotely change administrator passwords using command-line tools.

The activity was traced back to a virtual machine accessed using Rhyne’s account and company-issued laptop, according to court documents.

He pleaded guilty

Rhyne pleaded guilty in April to extortion involving a threat to damage a protected computer and to intentionally damaging a protected computer.

The extortion charge carried a maximum sentence of five years, while intentional damage to a protected computer carried up to 10 years.

US District Judge Michael A. Shipp sentenced Rhyne to 32 months in prison on Sept. 28, the Justice Department announced this week.

The proverbial ‘insider threat’

Not every cyberattack starts with a phishing email, stolen password or unpatched vulnerability. Sometimes the greatest threat is a person who already understands the network.

Infrastructure engineers, system administrators and other privileged users may legitimately need access capable of changing passwords, modifying accounts, managing servers and altering critical systems. The same privileges that let them keep an organization running can cause enormous damage when abused.

Organizations must apply the principle of least privilege, restrict powerful administrative accounts to people who genuinely need them, and separate everyday user accounts from administrator credentials.

Organizations should also monitor unusual privileged activity, such as mass password resets, unexpected administrator-account changes, suspicious remote sessions or newly created scheduled tasks.

Access should be reviewed whenever an employee changes roles and revoked promptly when it’s no longer needed. Critical administrative actions should also be logged so security teams can investigate suspicious behavior before it develops into a wider incident.

And backups need protection of their own. Keeping isolated or otherwise protected copies can help prevent someone with extensive access to production systems from destroying the organization’s path to recovery.

tags


Author


Filip TRUȚĂ

Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.

View all posts

You might also like

Bookmarks


loader