A former core infrastructure engineer has been sentenced to 32 months in prison for attacking his employer's computer network and demanding a ransom in Bitcoin.
Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced on September 28 by U.S. District Judge Michael A. Shipp in Trenton. He pleaded guilty in April to extortion in relation to a threat to damage a protected computer and to intentional damage to a protected computer.
Rhyne worked for an industrial company headquartered in Somerset County, New Jersey, that serves biopharmaceuticals, oil and gas, and other industries. He was the company's subject matter expert on hosting virtual machines.
The Attack
On November 25, 2023, at approximately 4 p.m., the company's network administrators received password reset notifications for hundreds of accounts. All domain administrator accounts had been deleted.
Forty-four minutes later, employees received an email titled "Your Network Has Been Penetrated." The message claimed IT administrators had been locked out, backups deleted, and warned that 40 additional servers would be shut down each day for 10 days unless the company paid 20 Bitcoin, worth approximately $750,000 at the time, by December 2. The email also specified a ransom of €700,000 in Bitcoin.
Investigation and Evidence
Federal investigators traced the attack to an unauthorized virtual machine created on the company's network on November 9, 2023. The machine's password was "TheFr0zenCrew!"—the same password later used on the administrator account, 301 user accounts, and the email account that sent the ransom demand.
On the morning of the attack, a remote desktop session from that machine created scheduled tasks to delete 13 administrator accounts, change passwords on 254 servers and 3,284 workstations, and shut down dozens of servers beginning December 3.
The FBI linked the machine to Rhyne through his company laptop. Browsing activity on the laptop stopped whenever browsing occurred on the hidden machine. Building access logs showed Rhyne entering headquarters minutes before his account logged in, and his laptop connected to the network from his home IP address minutes before the session that set up the deletion tasks.
Days before the attack, searches were performed on the machine for "how to clear all windows logs from command line" and "how to remotely shutdown a computer using cmd."


