Ex-Engineer Jailed for Sabotaging Employer’s Windows Network
Key Takeaways A former infrastructure engineer received a 32-month prison sentence for intentionally sabotaging his employer’s Windows network. The attacker used legitimate Windows...
Key Takeaways
- A former infrastructure engineer received a 32-month prison sentence for intentionally sabotaging his employer’s Windows network.
- The attacker used legitimate Windows administration tools to delete accounts, change passwords, and schedule server shutdowns, rather than deploying typical ransomware.
- The incident involved a ransom demand of 20 Bitcoin, valued at approximately $750,000 at the time.
- Investigators linked the malicious activity directly to the former employee through digital forensics and physical access records.
A former infrastructure engineer has been handed a 32-month federal prison sentence for orchestrating a sophisticated sabotage campaign against his employer’s Windows network, culminating in a significant cryptocurrency ransom demand.
Table Of Content
Daniel Rhyne, 59, of Kansas City, Missouri, received his sentence on September 28, 2026, from U.S. District Judge Michael A. Shipp in federal court in Trenton. Rhyne had previously entered a guilty plea to charges of extortion involving threats to damage a protected computer and intentional damage to a protected computer. His admission confirmed his role in the attack on an unnamed industrial firm headquartered in New Jersey.
Rhyne, who served as a core infrastructure engineer and the company’s specialist for hosting virtual machines, leveraged his intimate knowledge of the network. According to the complaint describes, investigators traced the malicious actions to an unauthorized virtual machine established within the company’s network on November 9, 2023.
This clandestine virtual machine served as a pivot point, granting access to the company’s domain controller, which is critical for managing network authentication. Forensic analysis revealed that the unauthorized machine repeatedly accessed a legitimate domain administrator account via remote desktop sessions between November 10 and November 25, 2023.
Former Infrastructure Engineer Sentenced for Network Sabotage
The full extent of the sabotage began unfolding on November 25, 2023, around 8:12 a.m. The compromised administrator account initiated the creation of approximately 16 unauthorized scheduled tasks. Six of these tasks were configured for immediate execution that afternoon, leading to the deletion of 13 domain administrator accounts and password changes for 301 domain user accounts.
The remaining scheduled tasks were set to trigger a systematic shutdown of dozens of servers, commencing on December 3. Notably, the attack did not involve a typical file-encrypting payload but instead exploited legitimate Windows administration tools to achieve its destructive goals.
Specifically, the “net user” utility was employed for modifying domain accounts, while Microsoft’s Sysinternals PsPasswd tool was used to alter local administrator passwords. These local credential changes impacted accounts across 254 servers and 3,284 workstations.
By approximately 4:00 p.m. on November 25, administrators began receiving a flurry of password reset notifications. They soon discovered that other critical domain administrator accounts had been deleted, effectively locking them out of administrative control over the network.
Approximately 44 minutes later, company employees received an external email bearing the ominous subject line “Your Network Has Been Penetrated.” The message demanded 20 Bitcoin, valued at approximately $750,000 at the time, with a payment deadline set for December 2, 2023.
The extortionists threatened to shut down 40 random servers daily for 10 days if the ransom was not paid. The email also falsely claimed that backups had been deleted. However, the complaint describes backup deletion as an assertion within the ransom email itself, not a independently verified forensic finding.
Investigation Uncovers Digital Footprints
Investigators meticulously connected the hidden virtual machine to Rhyne’s assigned laptop and user account. Physical access records and security footage corroborated his presence at company headquarters shortly before corresponding laptop logins and subsequent access to the virtual machine.
Further evidence emerged from remote connections originating from an IP address assigned to Rhyne’s residence. On the morning of the attack, investigators successfully reconstructed a sequence linking his laptop login, connection to his home network, access to the hidden virtual machine, and a remote desktop session to the domain controller.
Another crucial piece of evidence was password reuse. The password “TheFr0zenCrew!” was found to be shared across the hidden virtual machine, several altered domain accounts, and the extortion email account. Investigators also uncovered Rhyne’s related search history, which included queries about password changes, account deletion, remote shutdowns, and methods for clearing Windows logs.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.