Summary
- Daniel Rhyne, a former core infrastructure engineer, received a 32-month prison sentence for compromising his New Jersey employer's network and demanding a Bitcoin ransom.
- In his email sent in November 2023, he requested 20 BTC, equating to roughly $750,000, and threatened to disable 40 servers daily for 10 days.
- The FBI's investigation identified the attack through a concealed virtual machine accessed via Rhyne's company laptop, with passwords set to "TheFr0zenCrew!"
A former engineer from an industrial firm in New Jersey has been sentenced to 32 months in prison for hacking into his employer's computer system and demanding a ransom in Bitcoin, as stated by federal prosecutors on Monday.
Daniel Rhyne, 59, who resides in Kansas City, Missouri, was sentenced on September 28 by U.S. District Judge Michael A. Shipp in Trenton. He had previously pleaded guilty in April to charges of extorting his employer through threats to harm a protected computer and for intentionally damaging that computer.
Former Employee of Industrial Company Sentenced to 32 Months in Prison for Computer Attack and Extortion https://t.co/m4J4b8MxeQ
— NJ US Attorney (@USAO_NJ) October 5, 2026
Rhyne was recognized as the core infrastructure engineer and the subject matter expert on hosting virtual machines within the company, according to the FBI's criminal complaint. The specific company, located in Somerset County, New Jersey, has not been disclosed but operates across various sectors, including biopharmaceuticals and oil and gas.
On November 25, 2023, at approximately 4 PM, the company's network administrators began receiving notifications about password resets for numerous accounts, followed by the discovery that all domain administrator accounts had been deleted, as detailed in the complaint.
Just 44 minutes later, employees were alerted via an email titled "Your Network Has Been Penetrated." The email claimed that IT administrators had been locked out and backups erased, threatening that 40 additional servers would be shut down daily for 10 days unless a ransom of 20 BTC, valued at about $750,000 at the time, was paid by December 2. The email also listed the ransom amount in euros, setting it at €700,000, to be paid in Bitcoin.
Myriad: How high will Bitcoin go? Click to make your prediction.The Concealed Virtual Machine
Investigators traced the cyberattack back to an unauthorized virtual machine that was set up on the company’s network on November 9, 2023. The password for this machine was "TheFr0zenCrew!", which was also used for the administrator account, 301 user accounts, and the email account that sent the ransom demand.
On the day of the incident, a remote desktop session from this machine initiated scheduled tasks to delete 13 administrator accounts, modify passwords for 254 servers and 3,284 workstations, and shut down multiple servers starting December 3.
The FBI connected the virtual machine to Rhyne through his company laptop, noting that internet browsing on the laptop ceased whenever he accessed the hidden machine. Access logs indicated that he entered the company premises shortly before his account logged in, according to the complaint.
On the day of the attack, Rhyne's laptop accessed the network from an IP address linked to his residence in Warren County, New Jersey, just moments before the session that executed the tasks.
Prior to the attack, the machine’s user had searched for terms like "how to clear all windows logs from command line" and "how to remotely shutdown a computer using cmd," the complaint states.
Additionally, Rhyne faced a charge of wire fraud, which was not included in the two counts to which he pleaded guilty. He was facing up to five years for the extortion charge and a maximum of ten years for the damage charge.