Engineer Gets 32 Months for Bitcoin Extortion Plot Against His Own Employer

Daniel Rhyne locked his company's IT administrators out of its network and demanded 20 BTC, then worth $750,000, to stop the shutdowns.

By Decrypt Agent

3 min read

A former engineer at a New Jersey industrial company has been sentenced to 32 months in prison for attacking his employer's computer network and demanding a ransom in Bitcoin, federal prosecutors said Monday.

Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced on September 28 by U.S. District Judge Michael A. Shipp in Trenton. He pleaded guilty in April to extortion in relation to a threat to damage a protected computer, and to intentional damage to a protected computer.

Rhyne was the company's core infrastructure engineer and its subject matter expert on hosting virtual machines, according to the FBI's criminal complaint. Prosecutors have not named the company, which is headquartered in Somerset County, New Jersey, and serves industries ranging from biopharmaceuticals to oil and gas.

At about 4pm on November 25, 2023, the company's network administrators began receiving password reset notifications for hundreds of accounts, then found that all other domain administrator accounts had been deleted, the complaint says.

Forty-four minutes later, employees received an email headed "Your Network Has Been Penetrated." It claimed the company's IT administrators had been locked out and its backups deleted, and warned that 40 more servers would be shut down each day for 10 days unless 20 BTC, about $750,000 at the time, was paid by December 2.

The email set the ransom at €700,000, payable in Bitcoin, according to the complaint.

Myriad: How high will Bitcoin go? Click to make your prediction.

The hidden virtual machine

Investigators traced the attack to an unauthorized virtual machine created on the company's network on November 9, 2023. Its password was "TheFr0zenCrew!", the same password later set on the administrator account, on 301 user accounts, and on the email account that sent the demand.

On the morning of the attack, a remote desktop session from that machine created scheduled tasks to delete 13 administrator accounts, change passwords affecting 254 servers and 3,284 workstations, and shut down dozens of servers from December 3.

The FBI linked the machine to Rhyne through his company laptop. Browsing on the laptop stopped whenever browsing took place on the hidden machine, and building access logs showed him entering headquarters minutes before his account logged in, according to the complaint.

On the day of the attack, Rhyne's laptop connected to the network from an IP address assigned to his home in Warren County, New Jersey, minutes before the session that set up the tasks.

Days earlier, the machine's user had searched for "how to clear all windows logs from command line" and "how to remotely shutdown a computer using cmd," the complaint says.

The complaint also charged Rhyne with wire fraud, a count that did not appear in the two-count information to which he pleaded guilty. He had faced a maximum of five years on the extortion count and 10 years on the damage count.

 

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News