
A former core infrastructure engineer at a New Jersey industrial company, 57-year-old Daniel Rhyne of Kansas City, Missouri, was sentenced to 32 months in prison for locking thousands of devices on his employer’s network in what BleepingComputer calls a ransomware-style attack. He had pleaded guilty to a failed extortion plot against the company that employed him.
According to the court documents BleepingComputer cites, between November 8 and 25, 2023 he used an administrator account to schedule tasks on the domain controller that deleted 13 domain admin accounts, reset the password of an administrator account and 301 domain user accounts to “TheFr0zenCrew!”, and reset local admin passwords. That blocked access to 254 servers and 3,284 workstations, and he shut down random servers and workstations over several days in December 2023. On November 25 he emailed coworkers a message titled “Your Network Has Been Penetrated,” claimed server backups were deleted, and threatened to shut down 40 random servers daily for ten days unless the company paid 20 bitcoin (roughly $750,000 then). Investigators found he had searched for how to change domain passwords, delete domain accounts and clear Windows logs days before.
The case is a reminder for defenders that a privileged insider needs no malware to cause ransomware-level disruption: a handful of scheduled tasks on a domain controller was enough. Controls that limit this include separating admin duties, alerting on mass password resets and admin-account deletions, and keeping offline backups that one administrator cannot erase alone.
