SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Engineer who locked his firm out through its domain controller gets 32 months in prison
Daniel Rhyne got 32 months in federal prison for planting scheduled tasks on his industrial employer's domain controller that locked the firm out. Access to that one server let a single engineer delete or reset 318 accounts and change local administrator passwords on 3,538 machines.
The Watch · Security desk

What happened
- Within an hour of the jobs finishing on November 25, 2023, an email from an external address demanded 20 bitcoin, then worth about $750,000.
- SecurityWeek reported no suggestion that the firm paid; the firm ran its own forensic review, matching internal logs against physical access records.
- The FBI, brought in by the firm, traced the unauthorized activity to Rhyne's home IP address in Warren County, New Jersey.
- Rhyne pleaded guilty on April 1, 2026, in federal court in Trenton to extortion and intentional damage to a protected computer.
Why it matters
- exposure Anyone who can schedule jobs on a domain controller can set up a firm-wide lockout ahead of time; in this case that access covered 318 accounts.
- decision Because the jobs could sit for up to 24 days before firing, firms have to choose between alerting a second person on every new domain-controller task and hearing about it first from a ransom email.
- capability Matching internal logs against badge records gave the victim a route to attribution without paying, and any firm that keeps both records has the same route.
Each step SecurityWeek describes is routine administration, run as scheduled tasks on the firm's domain controller [4]. The jobs deleted 13 domain administrator accounts and reset passwords on the others, 318 accounts in all, generally to 'TheFr0zenCrew!' [4][14][6]. Four of the resets hit local administrator accounts. Two covered 254 servers and two covered 3,284 workstations [5]. Four passwords cut the firm off from 3,538 machines [15].
SecurityWeek places the tasks on the controller in November 2023 and has them finishing late in the afternoon of November 25 [4][7]. Depending on when they were placed, the jobs sat on the controller for as long as 24 days before they fired [16]. The extortion email also claimed every backup had been deleted and threatened to shut down 40 random servers a day for ten days [8]. Those claims came from the attacker, quoted from his email [8].
The source does not say whether Rhyne still worked at the firm in November 2023, or whose credentials created the tasks [3]. Either way, we think two controls apply. A new scheduled task on a domain controller should alert someone other than the person who created it. A job that deletes domain administrators or resets hundreds of passwords should need a second approver. Here, either control would have had up to 24 days to act [16].
Attribution took months [17]. FBI Special Agent Timothy Lee filed the criminal complaint on August 8, 2024, 257 days after the lockout [12][17]. Rhyne had moved to Kansas City by then and was arrested there on August 27 [12]. He was sentenced on September 28, 2026, 34 months after the jobs fired [1][18].
The password suggests a crew. Beyond it, the public record describes one insider and one employer: a Somerset County, New Jersey firm serving industries that include oil and gas, chemistry and healthcare [6][3][13]. We see nothing in that record tying the attack to a ransomware operation or to other victims.
What to watch
- Court filings or the DOJ release stating whether Rhyne was still employed in November 2023 and which credentials created the domain-controller tasks.
- A restitution order or victim impact statement that puts a figure on the firm's recovery cost.
- Any second defendant or other victim linked to the 'TheFr0zenCrew!' password, which would make this more than a single-insider case.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence72
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced on September 28, 2026, to 32 months in federal prison for crimes related to a ransom attack against his own company.
- [2]
Rhyne pleaded guilty on April 1, 2026, in federal court in Trenton, New Jersey, before District Judge Michael A. Shipp, to extortion in relation to a threat to cause damage to a protected computer and intentional damage to a protected computer.
- [3]
Rhyne had been a core infrastructure engineer at an industrial firm headquartered in Somerset County, New Jersey.
- [4]
In November 2023, Rhyne placed scheduled tasks on the firm's domain controller that would delete 13 domain administrator accounts and change passwords to 301 domain user accounts.
- [5]
The scheduled tasks also changed passwords to two local administrator accounts impacting 254 servers and two local administrator accounts impacting 3,284 workstations; the effect was to deny the firm access to its systems and data.
- [6]
Where passwords were changed, it was generally to 'TheFr0zenCrew!'.
- [7]
The scheduled tasks were completed late afternoon on November 25 (2023); within an hour, certain employees received an email from an external address with the subject line "Your Network Has Been Penetrated".
- [8]
The email warned that administrators had been locked out or deleted, all backups had been deleted, and that unless a ransom was paid, 40 random servers would be shut down each day over a ten-day period.
- [9]
Rhyne demanded a payment of 20 bitcoin, worth at the time approximately $750,000.
- [10]
There is no suggestion the victim firm paid any ransom; it immediately started its own internal forensic analysis of network anomalies and correlated internal logs with physical access records.
- [11]
The firm involved the FBI, which tracked the unauthorized activity directly to Rhyne's residential IP address in Warren County, New Jersey.
- [12]
FBI Special Agent Timothy Lee filed a criminal complaint on August 8, 2024, leading to Rhyne's arrest on August 27, 2024, in Kansas City, where he had subsequently moved.
- [13]
The firm provides services to industries including aquaculture, biopharmaceuticals, chemistry, electronics, food and beverage, healthcare, hydrogen mobility, manufacturing and industrial processing, metals, oil and gas, and pulp and paper.
- [14]
The scheduled tasks deleted or changed passwords on 318 accounts in total.
- [15]
The four local administrator password changes affected 3,538 machines.
- [16]
The scheduled tasks sat on the domain controller for at most 24 days before completing.
- [17]
The criminal complaint was filed 257 days after the lockout.
- [18]
Sentencing came about 34 months after the lockout.
Sources
1 independent publisher whose own reporting we read for this story.
- securityweek.comInsider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison
1 article · October 10, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- Daniel RhyneFollow
- Michael A. ShippFollow
- Federal Bureau of InvestigationFollow
- U.S. Department of JusticeFollow
- SecurityWeekFollow