Staffer’s 20 BTC ransom demand on his employer ends in a 32-month sentence

- Daniel Rhyne, a former core infrastructure engineer, got 32 months in federal prison on September 28.
- He demanded 20 BTC, about $750,000 at the time, from his New Jersey employer in November 2023.
- Scheduled tasks he planted locked staff out of 254 servers and 3,284 workstations.
A core infrastructure engineer for a New Jersey industrial company locked it out of the company’s network and demanded 20 BTC, or approximately $750,000 at the time, or more servers would go down. He received a 32-month federal prison sentence for the scheme.
Daniel Rhyne, 59, was sentenced by Judge Michael A. Shipp on September 28 in Trenton.
Rhyne, of Kansas City, Missouri, entered a guilty plea to two counts in April. One was extortion related to a threat to damage a protected computer, the other was intentional damage to one.
Scheduled tasks wiped 13 admin accounts and locked 3,284 workstations
At the firm, he specialized in virtual machines, the FBI complaint stated.
The firm sits in Somerset County, New Jersey, and counts biopharmaceutical and oil and gas companies as clients.
From November 8 to November 25, 2023, Rhyne employed an administrator account he was not authorized to access to remotely get into the network. Jobs he queued on the domain controller, then wiped out 13 domain admin accounts.
The same tasks also set 301 user passwords, and the administrator’s password, to “TheFr0zenCrew!” Two local admin accounts ended up at “PsPasswd,” locking staff out of 254 servers.
Another alteration locked 3,284 workstations. For several days that December, machines across the network went down randomly.
Administrators began getting alerts around 4 p.m. on November 25 as password resets triggered across hundreds of accounts, the complaint says. All other domain admin accounts were already gone.
Forty-four minutes later, the staff got an email titled “Your Network Has Been Penetrated.” It claimed backups were deleted.
If 20 BTC wasn’t received by December 2, 40 servers a day would be turned off for 10 days. On Wednesday, Bitcoin traded near $83,000, making 20 BTC worth about $1.7 million, more than double the demand’s 2023 value.
Rhyne searched how to clear Windows logs on November 22
On November 22, Rhyne’s account on the hidden machine looked up how to reset domain user passwords, delete domain accounts, and clear Windows logs, court papers said. His company laptop had run analogous searches a week before, including how to remotely shut down a computer from the command line.
The case was investigated by the FBI Newark Field Office, led by Stefanie Roddy, with assistance from Kansas City. Rhyne was picked up by agents in August 2024 and was released after his first court date.
Assistant U.S. Attorney Robert Taj Moore, Cybercrime Unit, prosecuted the case.
Brightly Software, a SaaS company, was targeted for $2.5 million by one of its own contractors. In March, contractor Cameron Curry, a 27-year-old data analyst from North Carolina, got two years.
Adam Iza was sentenced on October 5 to six and a half years in a federal court in California for schemes including stealing more than $37 million from Meta, Cryptopolitan reported.
In July, Cryptopolitan reported that 34-year-old Armenian Karen Serobovich Vardanyan, who was extradited from Ukraine, pleaded guilty over a Ryuk ransomware campaign. It raked in over $15 million in bitcoin from U.S. companies, with a Michigan firm coughing up 200 BTC.
The smartest crypto minds already read our newsletter. Want in? Join them.
FAQs
Who is Daniel Rhyne and what did he do?
Rhyne is a 59-year-old former core infrastructure engineer who locked his New Jersey employer out of its own network in November 2023.
How much was the ransom and was it paid?
The demand was 20 BTC, about $750,000 at the time, due by December 2, 2023.
What sentence did Rhyne receive and when?
Rhyne got 32 months in federal prison from Judge Michael A. Shipp on September 28, 2026.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Randa Moses
Randa Moses is an editor and reporter at Cryptopolitan covering tech, AI, robotics, crypto, scams, and hacks. She has worked in the crypto space since 2017. She held roles at Forward Protocol, AmaZix, and Cryptosomniac. Randa holds a degree in Electrical and Electronics Engineering from the University of Bradford.
















