A former infrastructure engineer who deleted his employer’s administrator accounts and demanded 20 bitcoin has been sentenced to 32 months in federal prison. Prosecutors say Daniel Rhyne, 59, was caught because the same password, “TheFr0zenCrew!”, protected both the hidden virtual machine used in the attack and the email account that sent the ransom note.
Investigators uncovered signs of an insider threat
Investigators said evidence showed that the attack was prepared in advance rather than being an improvised incident.
Days before the systems were disrupted, searches from the concealed virtual machine reportedly included instructions on changing administrator passwords through a command line, deleting domain accounts and remotely shutting down computers. Similar searches were also found on Rhyne’s company laptop.
The findings helped investigators establish a connection between Rhyne and the technical infrastructure used in the attack. The hidden virtual machine was linked to his account and company-issued laptop, prosecutors said.
The password “TheFr0zenCrew!” also appeared on the email account used to communicate the Bitcoin ransom demand. Investigators said the same password had been used to protect the hidden virtual machine.
That overlap provided another link between the infrastructure engineer and the extortion attempt.
At about 4 p.m. on Nov. 25, network administrators discovered that their accounts had been deleted. About 44 minutes later, employees received an extortion email warning that “all IT administrator accounts had been deleted and backups erased.”
The message represented a significant escalation because it combined the disruption already carried out against the company with a financial demand and an additional threat of damage.
Bitcoin ransom threat targeted 40 more servers
The extortion email demanded approximately 20 bitcoin by Dec. 2. At the time, the cryptocurrency was worth roughly $750,000, although the same amount of bitcoin would be worth substantially more at later prices.
The sender threatened to shut down another 40 servers every day for 10 days unless the company met the Bitcoin ransom demand.
The threat demonstrated the scale of the potential disruption. Rather than merely locking individual files or systems, the attacker allegedly sought to maintain leverage by threatening further shutdowns across the company’s infrastructure.
The case also highlights the particular risks organizations face when an employee or former employee has extensive administrative privileges. Rhyne’s role as a core infrastructure engineer gave him access that investigators said was subsequently used against the company.
The concealed virtual machine, scheduled commands, account deletions and password changes together formed a coordinated effort to interfere with the company’s ability to operate its technology systems.
Federal court imposes 32-month sentence
Federal authorities ultimately identified Rhyne as the person behind the attack and the Bitcoin ransom demand. His guilty plea resolved the criminal case before his sentencing in New Jersey.
The 32-month federal prison sentence reflects the seriousness of the offenses, which involved both an attempt to obtain money through a threat against a protected computer and the intentional damage of a protected computer.
The case illustrates how an internal cybersecurity incident can quickly develop into an extortion operation when an individual possesses high-level administrative access. It also shows how investigators can combine technical evidence, account records, device information and digital communications to connect an insider to a coordinated attack.
For the company involved, the incident began with the disappearance of administrator accounts and escalated into a Bitcoin ransom demand backed by threats of additional server shutdowns.
Rhyne’s sentence brings the criminal proceedings to a conclusion after investigators traced the attack from the compromised systems to the infrastructure engineer who had the access needed to carry it out.
The case serves as a reminder that cybersecurity threats do not always originate outside an organization. Employees with legitimate access to critical systems can potentially cause substantial damage if those privileges are misused, making access controls, monitoring and rapid response important elements of corporate security.