Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Apache Struts Flaws Allow Remote Code Execution
October 6, 2026
ASOS Hacked: App Users Receive Malicious Notifications
October 6, 2026
SOC and MSSP Leaders Build Intelligence-Led Threat Monitoring
October 6, 2026
Home/CyberSecurity News/Ex-Engineer Jailed for Sabotaging Employer’s Windows Network
CyberSecurity News

Ex-Engineer Jailed for Sabotaging Employer’s Windows Network

Key Takeaways A former infrastructure engineer received a 32-month prison sentence for intentionally sabotaging his employer’s Windows network. The attacker used legitimate Windows...

Emy Elsamnoudy
Emy Elsamnoudy
October 6, 2026 3 Min Read
2 0

Key Takeaways

  • A former infrastructure engineer received a 32-month prison sentence for intentionally sabotaging his employer’s Windows network.
  • The attacker used legitimate Windows administration tools to delete accounts, change passwords, and schedule server shutdowns, rather than deploying typical ransomware.
  • The incident involved a ransom demand of 20 Bitcoin, valued at approximately $750,000 at the time.
  • Investigators linked the malicious activity directly to the former employee through digital forensics and physical access records.

A former infrastructure engineer has been handed a 32-month federal prison sentence for orchestrating a sophisticated sabotage campaign against his employer’s Windows network, culminating in a significant cryptocurrency ransom demand.

Table Of Content

  • Key Takeaways
  • Former Infrastructure Engineer Sentenced for Network Sabotage
  • Investigation Uncovers Digital Footprints

Daniel Rhyne, 59, of Kansas City, Missouri, received his sentence on September 28, 2026, from U.S. District Judge Michael A. Shipp in federal court in Trenton. Rhyne had previously entered a guilty plea to charges of extortion involving threats to damage a protected computer and intentional damage to a protected computer. His admission confirmed his role in the attack on an unnamed industrial firm headquartered in New Jersey.

Rhyne, who served as a core infrastructure engineer and the company’s specialist for hosting virtual machines, leveraged his intimate knowledge of the network. According to the complaint describes, investigators traced the malicious actions to an unauthorized virtual machine established within the company’s network on November 9, 2023.

This clandestine virtual machine served as a pivot point, granting access to the company’s domain controller, which is critical for managing network authentication. Forensic analysis revealed that the unauthorized machine repeatedly accessed a legitimate domain administrator account via remote desktop sessions between November 10 and November 25, 2023.

Former Infrastructure Engineer Sentenced for Network Sabotage

The full extent of the sabotage began unfolding on November 25, 2023, around 8:12 a.m. The compromised administrator account initiated the creation of approximately 16 unauthorized scheduled tasks. Six of these tasks were configured for immediate execution that afternoon, leading to the deletion of 13 domain administrator accounts and password changes for 301 domain user accounts.

The remaining scheduled tasks were set to trigger a systematic shutdown of dozens of servers, commencing on December 3. Notably, the attack did not involve a typical file-encrypting payload but instead exploited legitimate Windows administration tools to achieve its destructive goals.

Specifically, the “net user” utility was employed for modifying domain accounts, while Microsoft’s Sysinternals PsPasswd tool was used to alter local administrator passwords. These local credential changes impacted accounts across 254 servers and 3,284 workstations.

By approximately 4:00 p.m. on November 25, administrators began receiving a flurry of password reset notifications. They soon discovered that other critical domain administrator accounts had been deleted, effectively locking them out of administrative control over the network.

Approximately 44 minutes later, company employees received an external email bearing the ominous subject line “Your Network Has Been Penetrated.” The message demanded 20 Bitcoin, valued at approximately $750,000 at the time, with a payment deadline set for December 2, 2023.

The extortionists threatened to shut down 40 random servers daily for 10 days if the ransom was not paid. The email also falsely claimed that backups had been deleted. However, the complaint describes backup deletion as an assertion within the ransom email itself, not a independently verified forensic finding.

Investigation Uncovers Digital Footprints

Investigators meticulously connected the hidden virtual machine to Rhyne’s assigned laptop and user account. Physical access records and security footage corroborated his presence at company headquarters shortly before corresponding laptop logins and subsequent access to the virtual machine.

Further evidence emerged from remote connections originating from an IP address assigned to Rhyne’s residence. On the morning of the attack, investigators successfully reconstructed a sequence linking his laptop login, connection to his home network, access to the hidden virtual machine, and a remote desktop session to the domain controller.

Another crucial piece of evidence was password reuse. The password “TheFr0zenCrew!” was found to be shared across the hidden virtual machine, several altered domain accounts, and the extortion email account. Investigators also uncovered Rhyne’s related search history, which included queries about password changes, account deletion, remote shutdowns, and methods for clearing Windows logs.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test

Next Post

Critical GitHub Copilot CLI Bug Exposes Developer Secrets via Prompt Injection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test
October 6, 2026
Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks
October 6, 2026
Critical Dell SupportAssist CVE-2024-28956 Vulnerability Allows Code Execution
October 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us