0x3000097b3000…3000097e
Ex-Engineer Gets 32 Months for $750K Bitcoin Extortion of New Jersey Firm
Daniel Rhyne, a former New Jersey core infrastructure engineer, received 32 months in federal prison for wiping admin accounts and demanding 20 BTC (~$750,000) to halt a 40-server-per-day shutdown spree.

Outputs
Daniel Rhyne, 59, was sentenced September 28, 2026 to 32 months in federal prison by U.S. District Judge Michael A. Shipp in Trenton.
Rhyne demanded 20 BTC (~$750,000; €700,000 in the email) on November 25, 2023 to halt a planned shutdown of 40 servers per day for 10 days.
The attack affected 254 servers and 3,284 workstations; 13 administrator accounts were deleted and 301 user account passwords were reset.
Rhyne's Somerset County, New Jersey employer has not been publicly named; the December 2, 2023 ransom deadline was not met.
Rhyne pleaded guilty in April to one count of extortion and one count of intentional damage to a protected computer.
Former core infrastructure engineer Daniel Rhyne received a 32-month federal prison sentence on Monday for wiping administrator accounts at his New Jersey employer and demanding a 20 Bitcoin ransom worth roughly $750,000, the U.S. Attorney's Office for the District of New Jersey announced.
U.S. District Judge Michael A. Shipp in Trenton imposed the sentence on September 28 against Rhyne, 59, of Kansas City, Missouri. He had pleaded guilty in April to one count of extortion involving threats to damage a protected computer and one count of intentional damage to a protected computer.
Who is Daniel Rhyne?
Prosecutors have not named Rhyne's employer. The FBI criminal complaint describes it as a Somerset County-headquartered industrial company serving biopharmaceuticals, oil and gas, and other sectors, where Rhyne oversaw core infrastructure and served as the internal subject matter expert on hosting virtual machines.
Network administrators there began receiving password reset notifications for hundreds of accounts at about 4 p.m. on November 25, 2023, and quickly discovered that every other domain administrator account had been deleted, the complaint says.
Forty-four minutes later, employees received an email headed "Your Network Has Been Penetrated." The message claimed that IT staff had been locked out and that backups had been deleted. It threatened to shut down 40 servers per day for 10 days unless paid.
What did the ransom demand specify?
The email set the demand at €700,000 payable in Bitcoin, the complaint says. At the time, 20 BTC traded for roughly $750,000. The sender required payment by December 2, 2023.
Investigators tied the attack to an unauthorized virtual machine created on the company network on November 9, 2023, sixteen days before the ransom note. Its password, "TheFr0zenCrew!", was later reused on the compromised administrator account, on 301 user accounts, and on the email account that sent the demand.
How did investigators link the breach to Rhyne?
The FBI linked the hidden VM to Rhyne through his company-issued laptop. Browsing on the laptop stopped whenever the attacker was active on the virtual machine. Building access logs placed Rhyne in headquarters minutes before his account logged in.
On the morning of the attack, his laptop connected to the network from an IP address tied to his home in Warren County, New Jersey, minutes before the session that set up the malicious tasks.
A remote desktop session from the hidden machine then created scheduled tasks to delete 13 administrator accounts, change passwords affecting 254 servers and 3,284 workstations, and orchestrate server shutdowns beginning December 3.
Days earlier, browsing from the VM had searched for "how to clear all windows logs from command line" and "how to remotely shutdown a computer using cmd," the complaint says.
What legal exposure remained?
Rhyne faced a statutory maximum of five years on the extortion count and 10 years on the damage count. The complaint also charged wire fraud, but that count did not appear in the two-count information to which Rhyne pleaded guilty.
For insider-enabled intrusions, the operational impact typically stretches well beyond any ransom payment. Victim firms in similar cases routinely face mass password resets, Active Directory rebuilds, and breach-notification filings.
The New Jersey U.S. Attorney's Office announced the sentence on Monday, closing the criminal matter at the trial-court level absent any appellate filings. The case stands as a cautionary signal on credential misuse by senior IT personnel with deep knowledge of production environments.
via justice.gov (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles