
An infrastructure engineer used his knowledge of his employer’s network to lock administrators out, disrupt servers and demand $750,000 in Bitcoin. He will now spend almost three years behind bars.
A former infrastructure engineer who turned his privileged access against his employer, sabotaging its computer network before demanding ransom, has been sentenced to 32 months in federal prison.
Daniel Rhyne, 59, of Kansas City, Missouri, worked as a core infrastructure engineer at a US-based industrial company headquartered in New Jersey.
According to the US Department of Justice, Rhyne began preparing an attack against the company’s network in November 2023.
Rather than breaking in using some sophisticated vulnerability exploit, prosecutors say Rhyne initiated unauthorized remote desktop sessions and created scheduled tasks designed to damage the network.
Those tasks could delete network administrator accounts, change passwords belonging to other users and shut down company servers.
On Nov. 25, 2023, Rhyne sent an extortion email threatening to continue shutting down servers unless the company handed over approximately 20 Bitcoin – worth about $750,000 at the time.
It was, in effect, a ransomware-style extortion attempt without the traditional ransomware.
Court documents previously reported by BleepingComputer offer a clearer picture of just how disruptive the scheme was designed to be.
Rhyne allegedly scheduled tasks that would delete 13 domain administrator accounts and change passwords of 301 domain users.
Other password changes targeting local administrator accounts could affect 254 servers and 3,284 workstations, according to the criminal complaint.
The goal was straightforward: deny the company and its administrators access to their own systems.
Investigators also found evidence of web searches made while the scheme was being prepared, including searches for ways to delete domain accounts, clear Windows logs and remotely change administrator passwords using command-line tools.
The activity was traced back to a virtual machine accessed using Rhyne’s account and company-issued laptop, according to court documents.
Rhyne pleaded guilty in April to extortion involving a threat to damage a protected computer and to intentionally damaging a protected computer.
The extortion charge carried a maximum sentence of five years, while intentional damage to a protected computer carried up to 10 years.
US District Judge Michael A. Shipp sentenced Rhyne to 32 months in prison on Sept. 28, the Justice Department announced this week.
Not every cyberattack starts with a phishing email, stolen password or unpatched vulnerability. Sometimes the greatest threat is a person who already understands the network.
Infrastructure engineers, system administrators and other privileged users may legitimately need access capable of changing passwords, modifying accounts, managing servers and altering critical systems. The same privileges that let them keep an organization running can cause enormous damage when abused.
Organizations must apply the principle of least privilege, restrict powerful administrative accounts to people who genuinely need them, and separate everyday user accounts from administrator credentials.
Organizations should also monitor unusual privileged activity, such as mass password resets, unexpected administrator-account changes, suspicious remote sessions or newly created scheduled tasks.
Access should be reviewed whenever an employee changes roles and revoked promptly when it’s no longer needed. Critical administrative actions should also be logged so security teams can investigate suspicious behavior before it develops into a wider incident.
And backups need protection of their own. Keeping isolated or otherwise protected copies can help prevent someone with extensive access to production systems from destroying the organization’s path to recovery.
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts