Employee arrested for locking Windows admins out of 254 servers in extortion plot

Share:

A former core infrastructure engineer at an industrial company headquartered in Somerset County, New Jersey, was arrested after locking Windows admins out of 254 servers in a failed extortion plot targeting his employer.

According to court documents, company employees received a ransom email titled “Your Network Has Been Penetrated” on November 25, around 4:44 PM EST. The email claimed that all IT administrators had been locked out of their accounts and server backups had been deleted to make data recovery impossible.

Additionally, the message threatened to shut down 40 random servers on the company’s network daily over the next ten days unless a ransom of €700,000 (in the form of 20 Bitcoin) was paid—at the time, 20 BTC were worth $750,000.

The investigation coordinated by FBI Special Agent James E. Dennehy in Newark uncovered that 57-year-old Daniel Rhyne from Kansas City, Missouri, who was working as a core infrastructure engineer for the New Jersey industrial company, had remotely accessed the company’s computer systems without authorization using a company administrator account between November 9 and November 25.

He then scheduled tasks on the company’s domain controlled to change the passwords for the Administrator account, 13 domain administrator accounts, and 301 domain user accounts to the “TheFr0zenCrew!” text string.

The criminal complaint alleges that Rhyne also scheduled tasks to change the passwords for two local administrator accounts, which would impact 254 servers, and for two more local admin accounts, which would affect 3,284 workstations on his employer’s network. He also scheduled some tasks to shut down random servers and workstations over multiple days in December 2023.

Exposed by incriminating web searches

The investigators also found during forensic analysis that, while planning his extortion plot, Rhyne allegedly used a hidden virtual machine he accessed using his account and laptop to search the web on November 22 for information on how to delete domain accounts, clear Windows logs, and change domain user passwords using the command line.

On November 15, Rhyne also made similar web searches on his laptop, including “command line to change local administrator password” and “command line to remotely change local administrator password.”

“By changing administrator and user passwords and shutting down Victim-l’s servers, the scheduled tasks were collectively designed and intended to deny Victim-1 access to its systems and data,” the criminal complaint reads.

“On or about November 25, 2023, at approximately 4:00 p.m. EST, network administrators employed at Victim-1 began receiving password reset notifications for a Victim-1 domain administrator account, as well as hundreds of Victim-1 user accounts. Shortly thereafter, the Victim-1 network administrators discovered that all other Victim-1 domain administrator accounts were deleted, thereby denying domain administrator access to Victim-1’s computer networks.”

Rhyne was arrested in Missouri on Tuesday, August 27, and was released after his initial appearance in the Kansas City federal court. The extortion, intentional computer damage, and wire fraud charges carry a maximum penalty of 35 years in prison and a $750,000 fine.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:38 pm, Mar 27, 2025
weather icon 14°C
L: 14° | H: 14°
clear sky
Humidity: 64 %
Pressure: 1017 mb
Wind: 10 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 6%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:46 am
Sunset: 6:24 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
10° | 14°°C 0 mm 0% 7 mph 80 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 13°°C 0.38 mm 38% 13 mph 86 % 1016 mb 0 mm/h
Sat Mar 29 9:00 pm
weather icon
4° | 13°°C 0 mm 0% 9 mph 78 % 1022 mb 0 mm/h
Sun Mar 30 9:00 pm
weather icon
8° | 17°°C 0 mm 0% 11 mph 93 % 1025 mb 0 mm/h
Mon Mar 31 9:00 pm
weather icon
8° | 15°°C 0 mm 0% 9 mph 79 % 1027 mb 0 mm/h
Today 6:00 pm
weather icon
14° | 14°°C 0 mm 0% 7 mph 65 % 1017 mb 0 mm/h
Today 9:00 pm
weather icon
10° | 10°°C 0 mm 0% 7 mph 80 % 1017 mb 0 mm/h
Tomorrow 12:00 am
weather icon
7° | 7°°C 0 mm 0% 7 mph 85 % 1015 mb 0 mm/h
Tomorrow 3:00 am
weather icon
6° | 6°°C 0 mm 0% 8 mph 84 % 1013 mb 0 mm/h
Tomorrow 6:00 am
weather icon
9° | 9°°C 0 mm 0% 9 mph 86 % 1012 mb 0 mm/h
Tomorrow 9:00 am
weather icon
10° | 10°°C 0.28 mm 28% 9 mph 85 % 1011 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
13° | 13°°C 0.38 mm 38% 12 mph 49 % 1012 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
12° | 12°°C 0 mm 0% 13 mph 42 % 1012 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€80,815.22
0.18%
Ethereum(ETH)
€1,864.06
-0.52%
Tether(USDT)
€0.93
-0.03%
XRP(XRP)
€2.18
-2.60%
Solana(SOL)
€128.25
-1.25%
USDC(USDC)
€0.93
-0.01%
Dogecoin(DOGE)
€0.178316
-2.44%
Shiba Inu(SHIB)
€0.000013
-3.05%
Pepe(PEPE)
€0.000008
-3.00%
Peanut the Squirrel(PNUT)
€0.213778
7.85%
Scroll to Top