Skip to content

Security1 publisher2 min readPublished

Infrastructure engineer gets 32 months for locking his employer out of 3,538 machines

Daniel Rhyne, a former infrastructure engineer, got 32 months in prison for using domain controller tasks to lock out 254 servers and 3,284 workstations. He staged it over 17 days of unauthorized access, and administrators learned of it from password-reset notifications after the tasks ran.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Infrastructure engineer gets 32 months for locking his employer out of 3,538 machines
Generated illustration

What happened

  • On November 25 he emailed coworkers demanding 20 bitcoin, roughly $750,000 at the time, and threatened to shut down 40 random servers a day for ten days.
  • Investigators found that on November 22 he used a hidden virtual machine to look up how to change domain passwords, delete domain accounts and clear Windows logs.
  • Rhyne, 57, of Kansas City, Missouri, was arrested in August 2024 and pleaded guilty to his role in the failed extortion plot.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure One administrator account and tasks on one domain controller reached 3,538 machines, so write access to that controller amounts to control of thousands of endpoints.
  • constraint Password-reset notifications fired only once the tasks ran, so alerting on credential changes cannot catch a lockout staged days in advance; detection has to watch task creation on domain controllers.
  • decision Rhyne used the claimed deletion of backups as leverage, so recovery plans have to assume an insider with domain rights will go after the backups as well.
  • precedent Sentences of two years for Curry and 32 months for Rhyne give employers a working reference for what prosecuting insider extortion produces.

Rhyne's unauthorized access ran from November 8 to November 25, according to court documents [3]. The criminal complaint puts discovery at the end of that span. "On or about November 25, 2023, at approximately 4:00 p.m. EST, network administrators employed at Victim-1 began receiving password reset notifications for a Victim-1 domain administrator account, as well as hundreds of Victim-1 user accounts," the complaint reads [7]. It continues: "Shortly thereafter, the Victim-1 network administrators discovered that all other Victim-1 domain administrator accounts were deleted, thereby denying domain administrator access to Victim-1's computer networks" [8].

The endpoint lockout went through local accounts. Tasks reset two local admin accounts to "PsPasswd," cutting off 254 servers, and reset two more admin accounts, cutting off 3,284 workstations [4]. In total, tasks on one domain controller locked 3,538 machines [12].

He searched before he acted. A week before November 22, on his laptop, Rhyne looked up "command line to change local administrator password," "command line to remotely change local administrator password," and "how to remotely shutdown a computer usign cmd" [10]. He later ran local admin resets and remote shutdowns [4][5].

Rhyne was on the inside when this happened. BleepingComputer describes the New Jersey company as the one that employed him [2], and his ransom email went to coworkers [6]. Offboarding would not have closed this route. The reported court documents do not say whether the administrator account he used was his own; they describe the access as unauthorized [3]. I think the control this case points to is an alert on new scheduled tasks on a domain controller, raised while the tasks are still waiting to run. The notifications in the complaint arrived when the tasks executed [7].

The ransom email said server backups had been deleted [6]. The claim is Rhyne's own, made in a demand for money. His threat of 40 server shutdowns a day for ten days came to 400 shutdowns [13]. He did shut down random servers and workstations over several days in December 2023, according to BleepingComputer's account of the court documents [5].

BleepingComputer pairs the case with Cameron Curry, a 27-year-old North Carolina data analyst contractor sentenced in March to two years in prison for extorting his employer, Brightly Software, for $2.5 million [11]. Each man was an insider who tried to extort his own employer [1][11]. The two cases involve different employers and different roles. Rhyne's sentence is eight months longer than Curry's [14].

What to watch

  • Any filing that confirms or refutes Rhyne's claim that the server backups were deleted, and what recovery took.
  • Whether the sentencing record shows his searches on clearing Windows logs led to logs actually being wiped.
  • Further insider extortion prosecutions of the Rhyne and Curry type, where an employee or contractor demands payment from their own employer.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories