The criminal complaint: what prosecutors say happened
Federal court documents describe a deliberate, multi-day campaign by a trusted insider that culminated in a ransom demand. The perpetrator, identified in the filings as 57-year-old Daniel Rhyne of Kansas City, Missouri, was a former core infrastructure engineer at an industrial company headquartered in New Jersey. According to the complaint, Rhyne remotely accessed the company's network without authorization using an administrator account between November 8 and November 25, 2023, and scheduled tasks on the domain controller to alter accounts and deny access to administrators and users.
Technical steps attributed to Rhyne
The filings list specific account and task changes. On the domain controller, the complaint says, Rhyne scheduled actions that changed the password of a domain administrator account to "TheFr0zenCrew!", deleted 13 domain admin accounts, and changed the passwords for 301 domain user accounts to "TheFr0zenCrew!". He also added scheduled tasks that changed two local administrator passwords to "PsPasswd," which the complaint says blocked access to 254 servers, and changed passwords for two additional admin accounts, blocking access to 3,284 workstations.
Over several days in December 2023, the complaint asserts, Rhyne also shut down random servers and workstations across the company's network. Investigators found contemporaneous searches tied to Rhyne’s devices consistent with the steps taken, including queries made on a hidden virtual machine on November 22 for how to change domain user passwords, delete domain accounts, and clear Windows logs. The complaint lists searches from about a week earlier on his laptop for "command line to change local administrator password," "command line to remotely change local administrator password," and "how to remotely shutdown a computer usign cmd."

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageThe ransom demand and claimed deletion of backups
On November 25, the complaint says, Rhyne sent coworkers a ransom email titled "Your Network Has Been Penetrated." The message, according to filings, asserted that server backups had been deleted to make recovery impossible and threatened to shut down 40 random servers daily over the next ten days unless the company paid 20 bitcoin — described in court papers as roughly $750,000 at the time.
The complaint frames the ransom as part of a failed extortion plot: despite the account changes and shutdowns, the attack did not produce the full coercive outcome Rhyne sought before law enforcement intervened.
Legal outcome: arrest, plea, and sentence
Rhyne was arrested in August 2024 and released after his initial appearance in federal court. He pleaded guilty to his role in the extortion plot and was sentenced to 32 months in prison. The complaint and sentence records document the unauthorized remote access, the account deletions and password changes, the shutdowns of servers and workstations, and the ransom message to coworkers as the basis for federal charges and the resulting punishment.
The filings place this case alongside an earlier insider extortion prosecution: in March, court records show 27-year-old Cameron Curry, a North Carolina data analyst contractor, was sentenced to two years in prison after being convicted of extorting his employer, Brightly Software (formerly SchoolDude), for $2.5 million.
What this means for technologists and employers
- Technologists and security teams: The complaint underscores how administrator credentials and scheduled tasks can be used to change passwords, delete admin accounts, and orchestrate mass shutdowns. The record of Rhyne's searches and the use of a hidden virtual machine are concrete indicators investigators relied upon in linking actions on the network to a particular individual.
- Employers and IT managers: The case highlights the operational impact when a long-time infrastructure engineer is alleged to have weaponized administrative access — from locked domain accounts to thousands of unreachable endpoints — and the potential scale of disruption tied to internal accounts and scheduled tasks.
The case against Daniel Rhyne, as laid out in the criminal complaint and followed by a guilty plea and a 32-month sentence, is a compact record showing how administrative privileges, scheduled tasks, and targeted credential changes can be combined to lock thousands of devices and support an extortion demand. The filings leave a concrete question in their wake: the ransom email claimed backups were deleted to prevent recovery — whether backups were actually erased and how the company recovered operational control are details the public record does not specify.




