Key facts
- Former engineer Daniel Rhyne was sentenced to 32 months in prison for an extortion plot.
- Rhyne attacked his employer's network and demanded 20 Bitcoin, worth about $750,000 in November 2023.
- He threatened to shut down 40 company servers daily for 10 days if the ransom was not paid.
- The FBI traced the attack to a hidden virtual machine accessed from Rhyne's company laptop.
- Rhyne's company laptop was linked to the attack through browsing activity and building access logs.
Daniel Rhyne, a former core infrastructure engineer, has been sentenced to 32 months in prison for orchestrating a Bitcoin extortion plot against his New Jersey-based employer. The sentencing took place on September 28 before U.S. District Judge Michael A. Shipp in Trenton.
Rhyne pleaded guilty in April to charges of extortion related to threatening a protected computer and intentional damage to a protected computer. According to the FBI's criminal complaint, Rhyne, who was the company's subject matter expert on hosting virtual machines, initiated the attack on November 25, 2023. Network administrators received notifications of hundreds of password resets, and all other domain administrator accounts were deleted. Shortly after, an email titled "Your Network Has Been Penetrated" claimed IT administrators were locked out and backups deleted.
The email demanded 20 Bitcoin, valued at approximately $750,000 at the time, to be paid by December 2, threatening to shut down 40 additional servers each day for 10 days. The ransom was also stated as €700,000.
Investigators traced the attack to an unauthorized virtual machine created on the company's network on November 9, 2023, with the password "TheFr0zenCrew!". This password was later used on administrator accounts, user accounts, and the email account sending the ransom demand. The FBI linked the machine to Rhyne through his company laptop, noting that browsing activity on the laptop ceased when the hidden machine was accessed and building access logs showed him entering the headquarters shortly before his account logged in. On the day of the attack, Rhyne's laptop connected to the network from an IP address assigned to his home in Warren County, New Jersey, minutes before the session that set up the server shutdown tasks. Earlier searches on the machine included "how to clear all windows logs from command line" and "how to remotely shutdown a computer using cmd."
