Former Infrastructure Engineer Jailed for Ransomware-Style Network Attack on Company

A 57-year-old engineer received a 32-month prison sentence after pleading guilty to executing a ransomware-style attack against his former employer in New Jersey, locking thousands of devices and demanding a 20 bitcoin ransom. Using administrator credentials, he changed passwords on hundreds of user accounts, deleted domain administrator accounts, and threatened to shut down servers unless the company paid approximately $750,000. The attack occurred between November and December 2023, with the engineer sending ransom demands after securing unauthorized access to the network.
Daniel Rhyne's attack unfolded methodically over several weeks. Beginning in mid-November 2023, he leveraged his legitimate administrative access to systematically disable network security controls, altering credentials across hundreds of accounts and eliminating backup recovery options. His search history revealed deliberate preparation, including queries on password manipulation and remote shutdown commands executed days before the assault commenced.
The incident represents a significant insider threat case, as Rhyne exploited trusted employee credentials to inflict widespread operational damage. His December ransom communication threatened escalating server shutdowns, creating urgency through threats of ongoing disruption rather than data theft alone—a hybrid extortion approach targeting both system availability and financial pressure.
This case may highlight vulnerabilities in credential management and insider access controls that organizations rely upon. Affected employees potentially experienced productivity losses and data access disruptions during recovery efforts. The incident could prompt companies to reconsider privileged account monitoring, credential rotation policies, and behavioral anomaly detection systems. Additionally, the case may inform security professionals about the risks posed by departing or disgruntled infrastructure personnel with deep system knowledge and administrative privileges.