Engineer sentenced for locking over 3,000 devices on employer network

A former engineer at an industrial company has been sentenced to 32 months in prison for orchestrating a ransomware-style attack on his employer’s network. Daniel Rhyne, 57, remotely accessed the company’s network without authorization and scheduled tasks that effectively locked out thousands of devices, including servers and workstations. He then sent a ransom email to his coworkers, demanding $750,000 in exchange for restoring access.

Rhyne’s actions were carried out between November 8 and November 25, 2023, when he used an administrator account to change the passwords of domain user accounts to “TheFr0zenCrew!” and deleted 13 domain admin accounts. He also added scheduled tasks that blocked access to additional servers and workstations, effectively crippling the network. The attack was discovered on November 25, 2023, when network administrators began receiving password reset notifications for hundreds of user accounts.

But what exactly did Rhyne do? In plain terms, he exploited his administrative privileges to make changes to the company’s network that made it impossible for anyone else to access their devices. He changed passwords and deleted admin accounts, essentially locking out thousands of employees from their workstations. This was not a traditional ransomware attack, where malware infects a device and demands payment in exchange for restoring access. Instead, Rhyne used his insider knowledge to create a “digital hostage” situation.

Rhyne’s actions were part of a larger pattern of behavior. Investigators found that he had been searching online for ways to change domain user passwords, delete admin accounts, and clear Windows logs just days before the attack. This suggests that Rhyne had planned the attack carefully, using his knowledge of the company’s network to create maximum disruption.

The case highlights the risks posed by insiders with administrative privileges. While Rhyne’s actions were certainly malicious, they also demonstrate how easily a trusted employee can compromise an organization’s security. In this case, Rhyne used his access to cause chaos and extort his employer. The fact that he was eventually caught and sentenced is a testament to the vigilance of network administrators who detected the attack.

For organizations looking to prevent similar attacks, it’s essential to implement robust security measures, including regular monitoring of administrative activity and prompt incident response plans. Employees with access to sensitive systems should be subject to regular background checks and training on secure practices. By taking these steps, organizations can reduce the risk of insider threats like Rhyne’s and protect themselves against devastating attacks.


Source: Bleeping Computer — 2026-10-06