Engineer Gets 32 Months for Bitcoin Extortion Plot Against His Own Employer
In brief
- Former core infrastructure engineer Daniel Rhyne was sentenced to 32 months in prison for attacking his New Jersey employer's network and demanding a Bitcoin ransom.
- His November 2023 email demanded 20 BTC, then worth about $750,000, and threatened to shut down 40 company servers a day for 10 days.
- An FBI complaint traced the attack to a hidden virtual machine accessed from Rhyne's company laptop, with passwords reset to "TheFr0zenCrew!"
A former engineer at a New Jersey industrial company has been sentenced to 32 months in prison for attacking his employer's computer network and demanding a ransom in Bitcoin, federal prosecutors said Monday.
Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced on September 28 by U.S. District Judge Michael A. Shipp in Trenton. He pleaded guilty in April to extortion in relation to a threat to damage a protected computer, and to intentional damage to a protected computer.
Former Employee of Industrial Company Sentenced to 32 Months in Prison for Computer Attack and Extortion https://t.co/m4J4b8MxeQ
— NJ US Attorney (@USAO_NJ) October 5, 2026
Rhyne was the company's core infrastructure engineer and its subject matter expert on hosting virtual machines, according to the FBI's criminal complaint. Prosecutors have not named the company, which is headquartered in Somerset County, New Jersey, and serves industries ranging from biopharmaceuticals to oil and gas.
At about 4pm on November 25, 2023, the company's network administrators began receiving password reset notifications for hundreds of accounts, then found that all other domain administrator accounts had been deleted, the complaint says.
Forty-four minutes later, employees received an email headed "Your Network Has Been Penetrated." It claimed the company's IT administrators had been locked out and its backups deleted, and warned that 40 more servers would be shut down each day for 10 days unless 20 BTC, about $750,000 at the time, was paid by December 2.
The email set the ransom at €700,000, payable in Bitcoin, according to the complaint.

The hidden virtual machine
Investigators traced the attack to an unauthorized virtual machine created on the company's network on November 9, 2023. Its password was "TheFr0zenCrew!", the same password later set on the administrator account, on 301 user accounts, and on the email account that sent the demand.
On the morning of the attack, a remote desktop session from that machine created scheduled tasks to delete 13 administrator accounts, change passwords affecting 254 servers and 3,284 workstations, and shut down dozens of servers from December 3.

→
The FBI linked the machine to Rhyne through his company laptop. Browsing on the laptop stopped whenever browsing took place on the hidden machine, and building access logs showed him entering headquarters minutes before his account logged in, according to the complaint.
On the day of the attack, Rhyne's laptop connected to the network from an IP address assigned to his home in Warren County, New Jersey, minutes before the session that set up the tasks.
Days earlier, the machine's user had searched for "how to clear all windows logs from command line" and "how to remotely shutdown a computer using cmd," the complaint says.
The complaint also charged Rhyne with wire fraud, a count that did not appear in the two-count information to which he pleaded guilty. He had faced a maximum of five years on the extortion count and 10 years on the damage count.