Crypto Prices

Ex-Engineer Sentenced to 32 Months for Sabotaging Company Systems in Bitcoin Ransom Scheme

7 hours ago
1 min read
4 views

Former Engineer Sentenced for Cyber Extortion

A former engineer of a New Jersey industrial firm has been sentenced to 32 months in federal prison following his guilty plea to charges of sabotaging the company’s computer systems in an attempt to extort approximately $750,000 in Bitcoin. Daniel Rhyne, a 59-year-old from Kansas City, Missouri, appeared in court on September 28 in Trenton, where he acknowledged his involvement in the scheme involving threats to harm protected computer systems, as reported by the U.S. Attorney’s Office for the District of New Jersey.

Details of the Cyber Attack

Rhyne, who held the position of core infrastructure engineer with administrative access to the company’s IT infrastructure, exploited his position to execute a calculated attack. A criminal complaint from the FBI detailed that Rhyne created a concealed virtual machine on the company’s network, secured with a password he created, “TheFr0zenCrew!” He utilized this covert access to gain control over an administrator account.

On November 25, 2023, Rhyne initiated a series of automated commands set to execute that same day, which would have catastrophic effects on the company. He programmed tasks that were intended to:

  • Erase 13 domain administrator accounts
  • Change passwords for 301 user accounts
  • Modify local administrator passwords affecting 254 servers
  • Alter credentials for over 3,200 employee workstations
  • Shut down multiple company servers and computers

These actions would effectively lock the business out of its own systems and data.

Investigation and Extortion

According to investigators, Rhyne had been preparing for the attack days in advance, conducting online research from his hidden virtual machine on various hacking techniques such as changing administrator passwords, deleting accounts, and remotely powering down machines. Further forensic analysis revealed similar searches on Rhyne’s company-issued laptop.

Shortly after the attack began, network administrators noticed that their accounts had been compromised around 4 p.m. On the same day, employees received an extortion email claiming that all IT administrator accounts had been deleted and backups dismantled. This email threatened to shut down an additional 40 servers each day for ten days unless a ransom of approximately 20 Bitcoin was paid by December 2, corresponding to a value of about $750,000 at that time—an amount that would now exceed $1.67 million.

Further investigations traced the hidden virtual machine back to Rhyne’s account and his company laptop. Remarkably, the extortion email was protected by the same password, “TheFr0zenCrew!”, linking Rhyne firmly to the criminal activities.

Conclusion

This case underscores the growing concern over cybersecurity and internal threats faced by companies as they navigate an increasingly digital landscape.

Popular