A core infrastructure engineer for a New Jersey industrial company locked the company out of its network and demanded crypto at the time, or more servers would go down. He received a 32-month federal prison sentence for the scheme.
Daniel Rhyne, 59, was sentenced by Judge Michael A. Shipp on September 28 in Trenton. Rhyne, of Kansas City, Missouri, entered a guilty plea to two counts in April. One was extortion related to a threat to damage a protected computer; the other was intentional damage to one. At the time, Rhyne made a demand of 20 BTC, promising that more servers would go down if his demands weren’t met. At the firm, he specialized in virtual machines, the FBI complaint stated.
Missouri native demanded crypto in return for the servers
The firm sits in Somerset County, New Jersey, and counts biopharmaceutical and oil and gas companies as clients. From November 8 to November 25, 2023, Rhyne employed an administrator account he was not authorized to access to remotely get into the network. Jobs he queued on the domain controller, then wiped out 13 domain admin accounts. The same tasks also set 301 user passwords and the administrator’s password to “TheFr0zenCrew!”
Two local admin accounts ended up at “PsPasswd,” locking staff out of 254 servers. Another alteration locked 3,284 workstations. For several days that December, machines across the network went down randomly. Administrators began getting alerts around 4 p.m. on November 25 as password resets triggered across hundreds of accounts, the complaint says. All other domain admin accounts were already gone.
Forty-four minutes later, the staff got an email titled “Your Network Has Been Penetrated.” It claimed backups were deleted. If 20 BTC wasn’t received by December 2, 40 servers a day would be turned off for 10 days. On Wednesday, the crypto traded near $83,000, making 20 BTC worth about $1.7 million, more than double the demand’s 2023 value. On November 22, Rhyne’s account on the hidden machine looked up how to reset domain user passwords, delete domain accounts, and clear Windows logs, court papers said.
His company laptop had run analogous searches a week before, including how to remotely shut down a computer from the command line. The case was investigated by the FBI Newark Field Office, led by Stefanie Roddy, with assistance from Kansas City. Rhyne was picked up by agents in August 2024 and was released after his first court date. Assistant U.S. Attorney Robert Taj Moore, Cybercrime Unit, prosecuted the case. Brightly Software, a SaaS company, was targeted for $2.5 million by one of its own contractors.
In March, contractor Cameron Curry, a 27-year-old data analyst from North Carolina, got two years. Adam Iza was sentenced on October 5 to six and a half years in a federal court in California for schemes including stealing more than $37 million from Meta, Cryptopolitan reported. In July, Cryptopolitan reported that 34-year-old Armenian Karen Serobovich Vardanyan, who was extradited from Ukraine, pleaded guilty over a Ryuk ransomware campaign. It raked in over $15 million in bitcoin from U.S. companies, with a Michigan firm coughing up 200 BTC.

