Engineer sentenced for locking over 3,000 devices on employer network

A former engineer has been sentenced to 32 months in prison for orchestrating a devastating cyberattack against his employer’s network, locking over 3,000 devices and threatening to extort millions of dollars unless his demands were met. Daniel Rhyne, a 57-year-old from Kansas City, Missouri, used his administrative privileges to remotely access the company’s network and manipulate its systems, rendering thousands of workstations inaccessible.

The attack was carried out in December 2023, when Rhyne scheduled tasks on the domain controller that deleted administrator accounts and changed passwords for hundreds of user accounts. He also shut down random servers and workstations over several days, creating chaos and disrupting critical operations. On November 25, 2023, Rhyne sent a ransom email to his coworkers, claiming that server backups had been deleted and threatening to shut down additional servers daily unless the company paid a staggering $750,000 in bitcoin.

Rhyne’s actions were not only devastating for his employer but also demonstrated a shocking level of arrogance. Court documents reveal that he used administrator accounts to search the web for information on changing domain user passwords, deleting domain accounts, and clearing Windows logs just days before carrying out the attack. This was no impulsive act; Rhyne had carefully planned his extortion plot, exploiting his access to the network to wreak havoc.

The aftermath of the attack highlights the importance of robust security measures in preventing such incidents. The company’s administrators were forced to scramble to regain control of their systems and recover from the devastating losses caused by Rhyne’s actions. This case serves as a stark reminder that even trusted employees can pose a significant threat to an organization’s security, emphasizing the need for vigilant monitoring and swift action when suspicious activity is detected.

Rhyne’s sentence marks another high-profile conviction in a string of recent cases involving insider threats. In March this year, Cameron Curry, a 27-year-old data analyst contractor from North Carolina, was sentenced to two years in prison after extorting his employer, Brightly Software, for $2.5 million. These cases demonstrate that the threat posed by insiders is real and demands attention from organizations of all sizes.

As we reflect on this case, it’s clear that robust security measures are essential for protecting against insider threats like Rhyne’s. Employers must prioritize vigilance in monitoring their networks, invest in employee training to identify and report suspicious activity, and develop incident response plans to quickly contain the fallout from such incidents. In a world where cyberattacks can come from anywhere, including within an organization itself, it’s imperative that we take proactive steps to safeguard our digital assets and protect against these types of devastating threats.


Source: Bleeping Computer — 2026-10-06