Former Engineer Sentenced to 32 Months for Network Sabotage and Ransom Demand
A former infrastructure engineer has been sentenced to 32 months in prison for intentionally damaging his employer's Windows network and demanding a cryptocurrency ransom.

Daniel Rhyne, a 59-year-old former core infrastructure engineer from Kansas City, Missouri, has been sentenced to 32 months in federal prison for orchestrating a significant sabotage attack against his former employer, an unnamed industrial company. The sentence, handed down on September 28, 2026, by U.S. District Judge Michael A. Shipp, follows Rhyne's guilty plea to charges of extortion and intentional damage to a protected computer.
The attack, which occurred between November 9 and November 25, 2023, involved Rhyne leveraging his expertise as a virtual machine specialist. Investigators traced the initial intrusion to an unauthorized virtual machine he created within the company's network. This hidden machine served as a critical pivot point, allowing Rhyne to gain access to the company's domain controller, the central hub for network authentication and user management.
Using legitimate Windows administration tools, Rhyne systematically compromised the network. Between November 10 and November 25, he repeatedly accessed a domain administrator account via remote desktop sessions. On the morning of November 25, he configured approximately 16 unauthorized scheduled tasks designed to execute later that day. These tasks were programmed to delete 13 domain administrator accounts and alter the passwords of 301 domain user accounts, severely disrupting network operations and access.
Further escalating the damage, Rhyne's malicious tasks were also set to shut down dozens of servers beginning December 3. The attack notably eschewed file-encrypting ransomware, instead focusing on direct system disruption. Utilities like "net user" were used for account manipulation, and Microsoft's Sysinternals PsPasswd tool was employed to change local administrator passwords across 254 servers and 3,284 workstations.
As administrators began receiving password reset notifications on the afternoon of November 25, they discovered the extent of the compromise, including the loss of administrative access. Shortly thereafter, an external email arrived, demanding 20 bitcoin (approximately $750,000 at the time) with a deadline of December 2. The ransom note threatened daily server shutdowns and falsely claimed backup deletion.
Investigators were able to link the malicious activity directly to Rhyne. Forensic analysis connected the unauthorized virtual machine and the compromised accounts to his company-issued laptop and user account. Security footage and physical access logs confirmed his presence at the company headquarters prior to key login events. Furthermore, remote connections originated from an IP address associated with his residence.
Password reuse played a crucial role in the attack's success, with the unauthorized virtual machine, altered domain accounts, and the extortion email all sharing the same password: "TheFr0zenCrew!". Rhyne's digital footprint also included suspicious internet searches related to password changes, account deletion, and log clearing, further solidifying the evidence against him.
Rhyne's actions highlight the severe risks posed by insider threats, particularly when individuals with deep technical knowledge and administrative privileges act maliciously. The case underscores the importance of robust access controls, continuous monitoring, and stringent password policies, even for seemingly trusted employees.