Engineer Jailed Over Insider Cyber Extortion Plot Against Industrial Firm

The former infrastructure engineer was sentenced to 32 months in federal prison for sabotage of his employer's computer network and for demanding a ransom of $750,000 in Bitcoin from his employer. 

According to the US Department of Justice (DOJ), Daniel Rhyne, 59, was convicted of extortion involving threats to damage protected computers and intentional damage to protected computers.
Rhyne was previously employed as a core infrastructure engineer with a Somerset County, New Jersey industrial company. 

Providing services across various sectors, the company specializes in manufacturing, healthcare, biopharmaceuticals, electronics, energy and industrial processing. Rhyne is alleged to have prepared a coordinated disruption in November 2023 by using his privileged access and knowledge of the company's network. 

An alternative to conventional ransomware was used in this attack, which involved scheduled tasks that removed administrator accounts and changed passwords across the entire organization's systems and could have prevented employees from accessing critical information. 

Attack Disrupted Administrative Access

A court document indicates that Rhyne set up scheduled tasks on the domain controller to delete 13 domain administrator accounts and change the passwords of 301 domain users. Two additional tasks were also performed on November 25, 2023, to target two local administrator accounts related to 254 servers and two others affecting 3,284 workstations. 

Among the changes was a security threat that threatened the availability of a large number of devices across the network, as well as the locking of administrators and other employees out of company systems and data. Select employees received an email extortion request from an external address with the subject line "Your Network has been breached" approximately one hour after scheduled tasks had been executed. 

According to the message, administrator accounts were revoked, backups were removed, and administrator accounts had been deleted or locked out.
Rhyne also threatened to shut down 40 servers randomly each day for ten days if the company did not meet its ransom demand. In this email, Rhyne demanded 20 Bitcoin, which was approximately $750,000 at the time. This incident demonstrated that access to administrative systems can be abused to disrupt an organization without the use of traditional file-encrypting malicious code. 

Due to the attacks targeting accounts, passwords, and server access, the company was unable to manage its own IT environment and maintain normal business operations as a result of the attacks. 

Investigation Leads to Arrest and Prison Sentence

In response to the discovery of suspicious network activity, the company launched an internal forensic investigation. Investigators analyzed system logs and compared them with physical access records in order to determine the source of the changes. As a result of the FBI investigation, the activity was traced to the residential IP address of Rhyne in Warren County, New Jersey, which was associated with Rhyne. 

A criminal complaint was filed on August 8, 2024 by FBI Special Agent Timothy Lee in response to the findings. Rhyne was arrested on August 27, 2024, in Kansas City, Missouri, following his relocation to the area. He pleaded guilty to the charges on April 1, 2026, in federal court in Trenton, New Jersey, before US District Judge Michael A. 

On September 28, 2026, Shipp delivered the 32-month prison sentence.
An employee with extensive administrative privileges poses substantial security risks. While outsider attacks tend to exploit software vulnerabilities or steal credentials from external users, insider attacks are capable of exploiting legitimate access to disrupt a wide range of systems. 

Security teams may struggle to regain control of critical systems when mass password changes and administrator account deletions occur.
By restricting access to privileged accounts, monitoring unusual account activity, and maintaining backups that are protected from production network access, similar incidents may be reduced. 

It is also crucial to review and revoke access as soon as your employment responsibilities change to minimize the risk of deliberate misuse. This case illustrates the risks associated with insider threats and improper use of privilege.
A strong access control system, continuous monitoring, as well as secure backups are essential to safeguarding critical business systems from intentional attacks.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: