A shocking case of cyber extortion has landed a former infrastructure engineer behind bars. Daniel Rhyne, a 59-year-old man from Kansas City, Missouri, was sentenced to 32 months in federal prison for his role in a brazen plot to extort his own company.
Rhyne worked as a core infrastructure engineer at an industrial firm based in New Jersey, providing services to various industries including aquaculture, biopharmaceuticals, and manufacturing. In November 2023, he used his access to the company’s systems to place scheduled tasks that deleted domain administrator accounts, changed passwords on user and local administrator accounts, and even locked out employees from accessing their workstations.
The effect was immediate: when the tasks were completed, the company’s IT team was unable to access its systems, and employees received an email warning them that their network had been compromised. The email, allegedly sent by Rhyne himself using a fake external address, demanded a ransom of 20 bitcoin (approximately $750,000) in exchange for restoring access.
However, the company did not pay the ransom. Instead, it launched its own internal forensic investigation, which was later joined by the FBI. The joint effort tracked the unauthorized activity to Rhyne’s residential IP address in New Jersey, leading to his arrest and subsequent guilty plea in April 2026.
This case highlights a disturbing trend: insider threats can come from anyone, even those with authorized access to sensitive systems. It also shows that cybersecurity measures must be robust enough to detect and prevent such attacks, which often involve exploiting the trust placed in employees or contractors.
The investigation revealed that Rhyne used his knowledge of the company’s internal workings to plan and execute the attack, changing passwords to “TheFr0zenCrew!” – a clear indication of his intent. The FBI was able to track the unauthorized activity due to the company’s prompt response and thorough forensic analysis.
This case serves as a reminder that cybersecurity threats can come from within, and that organizations must be vigilant in monitoring employee behavior and access to sensitive systems. It also underscores the importance of having robust incident response plans in place to quickly respond to such attacks and minimize their impact.
As a takeaway for readers, this case emphasizes the need for companies to regularly review and audit their internal security measures, including access controls and password policies. It’s also essential to educate employees about cybersecurity best practices and to have clear protocols in place for responding to suspected insider threats. By doing so, organizations can reduce the risk of such attacks and protect themselves from the devastating consequences of cyber extortion.
Source: SecurityWeek — 2026-10-10