Cyber Security News

Former Employee Sentenced for Damaging Employer’s Windows Network Infrastructure

A former infrastructure engineer has been sentenced to 32 months in federal prison for damaging his employer’s computer network and demanding a ransom in Bitcoin.

Daniel Rhyne, 59, of Kansas City, Missouri, received the sentence from U.S. District Judge Michael A. Shipp on September 28, 2026, in Trenton, New Jersey.

Rhyne previously pleaded guilty to two charges: extortion involving threats to damage a protected computer, and intentional damage to a protected computer. His employer, an unnamed industrial company based in New Jersey, had employed him as a core infrastructure engineer specializing in virtual machine hosting.

Former Employee Sentenced

According to the criminal complaint, the attack preparation involved creating an unauthorized virtual machine within the company’s network. Investigators traced remote desktop connections from this hidden system to a legitimate domain administrator account on the organization’s domain controller.

On November 25, 2023, beginning at 8:12 a.m. EST, the administrator account created approximately 16 unauthorized scheduled tasks. Six of these tasks were configured to execute that afternoon, starting at 4:00 p.m., separating the preparation activities from the resulting disruptions to user accounts.

These tasks targeted 13 domain administrator accounts for deletion and reset the remaining administrator account’s password to “TheFr0zenCrew!” Additionally, the actor targeted 301 domain user accounts for password changes using Windows’ native net user utility.

Other scheduled tasks employed Microsoft Sysinternals’ PsPasswd utility to change local administrator passwords across 254 servers and 3,284 workstations.

The utility facilitated the changes, not to replace the passwords. Moreover, additional tasks were set up to shut down numerous servers over several days, beginning on December 3.

Around 4:00 p.m. on November 25, network administrators started receiving notifications about password resets. They soon discovered that other domain administrator accounts had been deleted, denying them administrative access to the network.

At 4:44 p.m., employees received an external email titled “Your Network Has Been Penetrated.” The email demanded a ransom of 20 Bitcoin, worth about $750,000 at the time. It threatened to shut down 40 random servers daily for ten days unless payment was made by December 2.

The message also claimed that backups had been deleted; however, the complaint presents this statement as part of the extortion email and does not independently confirm the destruction of all backups. The documented attack primarily focused on account manipulation and scheduled shutdowns, rather than demonstrated file encryption.

Investigators linked the access to the hidden virtual machine to Rhyne’s assigned laptop and user account. Physical access records, security footage, and connections from his residential IP address corroborated the access timeline.

Browser searches conducted on Rhyne’s device were focused on topics such as password changes, account deletions, remote shutdowns, and clearing Windows logs.

Investigators also noted that the email account used for the ransom reused the password “TheFr0zenCrew!” further linking it to the hidden virtual machine and the altered company accounts.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago