Engineer Gets 32 Months for Bitcoin Extortion Plot Against His Own Employer

A former core infrastructure engineer, Daniel Rhyne, was sentenced to 32 months in prison for penetrating his New Jersey employer's network and demanding a Bitcoin ransom. Prosecutors say Rhyne locked IT administrators out, deleted administrator accounts and backups, and threatened to take down additional servers unless 20 BTC (about $750,000 at the time) was paid.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 1 hour agoUpdated about 1 hour ago0 views
Engineer Gets 32 Months for Bitcoin Extortion Plot Against His Own Employer

Why It Matters

The case shows an insider using technical knowledge and company resources to deploy a targeted extortion campaign paid in cryptocurrency, illustrating risks organizations face from privileged employees. It also demonstrates law enforcement tracing crypto-linked attacks back to individual actors through digital forensic evidence.

Key Facts

  • Defendant: Daniel Rhyne, 59, of Kansas City, Missouri
  • Sentence: 32 months in prison (sentenced Sept. 28)
  • Court: U.S. District Court, Judge Michael A. Shipp, Trenton
  • Charges pleaded to: Extortion related to a threat to damage a protected computer; intentional damage to a protected computer (pleaded guilty in April)
  • Ransom demand: 20 BTC (about $750,000 at the time); email also set ransom at €700,000 payable in Bitcoin)

Federal prosecutors announced that a former core infrastructure engineer at an industrial company headquartered in Somerset County, New Jersey, was sentenced to 32 months in prison for orchestrating an extortion attack against his employer. Daniel Rhyne pleaded guilty in April to extortion tied to a threat to damage a protected computer and to intentional damage to a protected computer; the sentence was imposed Sept. 28 by U.S. District Judge Michael A. Shipp in Trenton. Prosecutors did not identify the company by name but said it serves sectors including biopharmaceuticals and oil and gas. According to the FBI complaint, the incident began on Nov. 25, 2023, when network administrators received password-reset notifications for hundreds of accounts and then discovered that domain administrator accounts had been deleted. Minutes later employees received an email titled "Your Network Has Been Penetrated" that claimed backups were deleted and warned that 40 additional servers would be shut down each day for 10 days unless 20 BTC—about $750,000 at the time—was paid by Dec. 2. The complaint says the same demand also set the ransom at €700,000 payable in Bitcoin. Investigators traced the intrusion to an unauthorized virtual machine created on the company network on Nov. 9, 2023. That VM used the password "TheFr0zenCrew!", which was later set on an administrator account, on 301 user accounts, and on the email account that sent the ransom demand. On the morning of the attack the hidden VM initiated scheduled tasks to delete 13 administrator accounts, change passwords affecting 254 servers and 3,284 workstations, and schedule shutdowns of dozens of servers beginning Dec. 3. The FBI linked activity on the hidden VM to Rhyne’s company laptop, noting that browsing on the laptop stopped whenever browsing occurred on the hidden machine, and that building access logs showed Rhyne entering company headquarters minutes before his account logged into the VM. On the day of the attack his laptop connected from an IP address assigned to his Warren County, New Jersey, home shortly before the session that established the damaging tasks. The complaint also noted prior searches from the VM for commands to clear Windows logs and remotely shut down computers. Prosecutors had also included a wire fraud allegation in the complaint, though the two-count information to which Rhyne pleaded guilty did not include that count.

Keep Reading