Threat to Shut Down Servers

Engineer Sentenced to 32 Months for Extorting His Employer

insider attack, server shutdown, engineer sentenced for cyber extortion, insider attack involving company serversk, employee locks company servers for ransom, engineer
Facebook
X
LinkedIn
Reddit
WhatsApp

An infrastructure engineer locked 254 servers and 3,284 workstations belonging to his employer and demanded 20 bitcoin. He has now been sentenced to prison.

A former core infrastructure engineer at an industrial company based in New Jersey has been sentenced to 32 months in prison. The 57-year-old, Daniel Rhyne of Kansas City, Missouri, locked thousands of devices on his employer’s network in November 2023 and demanded a ransom. He was arrested in August 2024 and pleaded guilty.

Ad

Scheduled Tasks on the Domain Controller

According to court documents, Rhyne remotely accessed his company’s network without authorization through an administrator account between November 8 and November 25, 2023. He created scheduled tasks on the domain controller that changed the administrator account password, deleted 13 domain administrator accounts, and reset the passwords of 301 domain user accounts.

Using additional scheduled tasks, he changed the passwords of two local administrator accounts, blocking access to 254 servers. By changing two more administrator accounts, he also prevented administrators from accessing 3,284 workstations. Over several days, he also shut down randomly selected servers and workstations.

“Shortly thereafter, the network administrators of Victim-1 discovered that all other domain administrator accounts had been deleted, thereby denying them administrator access to Victim-1’s computer networks,” the criminal complaint states.

Ad

Engineer Threatened to Shut Down 40 Servers a Day

On November 25, 2023, Rhyne emailed colleagues with the subject line “Your Network Has Been Penetrated.” He claimed that the company’s server backups had also been deleted, making recovery impossible. He threatened to shut down 40 randomly selected servers every day for 10 days unless the company paid 20 bitcoin, worth approximately $750,000 USD at the time.

Search History Helped Investigators Identify Him

Investigators found that on November 22, Rhyne had used an account on a hidden virtual machine to search the web for instructions on changing domain passwords, deleting domain accounts, and clearing Windows logs. A week earlier, he had also searched on his laptop for commands to remotely change local administrator passwords and shut down computers through the command line.

In March, 27-year-old data analyst Cameron Curry of North Carolina was sentenced to two years in prison. As an external contractor, he had attempted to extort $2.5 million from his client, Brightly Software.

(Editorial Team)

Ad

Weitere Artikel