Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Engineer who locked his firm out through its domain controller gets 32 months in prison

Daniel Rhyne got 32 months in federal prison for planting scheduled tasks on his industrial employer's domain controller that locked the firm out. Access to that one server let a single engineer delete or reset 318 accounts and change local administrator passwords on 3,538 machines.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Engineer who locked his firm out through its domain controller gets 32 months in prison
Generated illustration

What happened

  • Within an hour of the jobs finishing on November 25, 2023, an email from an external address demanded 20 bitcoin, then worth about $750,000.
  • SecurityWeek reported no suggestion that the firm paid; the firm ran its own forensic review, matching internal logs against physical access records.
  • The FBI, brought in by the firm, traced the unauthorized activity to Rhyne's home IP address in Warren County, New Jersey.
  • Rhyne pleaded guilty on April 1, 2026, in federal court in Trenton to extortion and intentional damage to a protected computer.

Why it matters

  • exposure Anyone who can schedule jobs on a domain controller can set up a firm-wide lockout ahead of time; in this case that access covered 318 accounts.
  • decision Because the jobs could sit for up to 24 days before firing, firms have to choose between alerting a second person on every new domain-controller task and hearing about it first from a ransom email.
  • capability Matching internal logs against badge records gave the victim a route to attribution without paying, and any firm that keeps both records has the same route.

Each step SecurityWeek describes is routine administration, run as scheduled tasks on the firm's domain controller [4]. The jobs deleted 13 domain administrator accounts and reset passwords on the others, 318 accounts in all, generally to 'TheFr0zenCrew!' [4][14][6]. Four of the resets hit local administrator accounts. Two covered 254 servers and two covered 3,284 workstations [5]. Four passwords cut the firm off from 3,538 machines [15].

SecurityWeek places the tasks on the controller in November 2023 and has them finishing late in the afternoon of November 25 [4][7]. Depending on when they were placed, the jobs sat on the controller for as long as 24 days before they fired [16]. The extortion email also claimed every backup had been deleted and threatened to shut down 40 random servers a day for ten days [8]. Those claims came from the attacker, quoted from his email [8].

The source does not say whether Rhyne still worked at the firm in November 2023, or whose credentials created the tasks [3]. Either way, we think two controls apply. A new scheduled task on a domain controller should alert someone other than the person who created it. A job that deletes domain administrators or resets hundreds of passwords should need a second approver. Here, either control would have had up to 24 days to act [16].

Attribution took months [17]. FBI Special Agent Timothy Lee filed the criminal complaint on August 8, 2024, 257 days after the lockout [12][17]. Rhyne had moved to Kansas City by then and was arrested there on August 27 [12]. He was sentenced on September 28, 2026, 34 months after the jobs fired [1][18].

The password suggests a crew. Beyond it, the public record describes one insider and one employer: a Somerset County, New Jersey firm serving industries that include oil and gas, chemistry and healthcare [6][3][13]. We see nothing in that record tying the attack to a ransomware operation or to other victims.

What to watch

  • Court filings or the DOJ release stating whether Rhyne was still employed in November 2023 and which credentials created the domain-controller tasks.
  • A restitution order or victim impact statement that puts a figure on the firm's recovery cost.
  • Any second defendant or other victim linked to the 'TheFr0zenCrew!' password, which would make this more than a single-insider case.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence70
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence72
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced on September 28, 2026, to 32 months in federal prison for crimes related to a ransom attack against his own company.

    ReportedSupportedSource: SecurityWeek, reporting a DOJ announcementView cited source
  2. [2]

    Rhyne pleaded guilty on April 1, 2026, in federal court in Trenton, New Jersey, before District Judge Michael A. Shipp, to extortion in relation to a threat to cause damage to a protected computer and intentional damage to a protected computer.

    ReportedSupportedSource: SecurityWeekView cited source
  3. [3]

    Rhyne had been a core infrastructure engineer at an industrial firm headquartered in Somerset County, New Jersey.

    ReportedSupportedSource: SecurityWeekView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. securityweek.com

    1 article · October 10, 2026

    Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories