Former Engineer Gets 32 Months for Bitcoin Extortion Against Employer
A New Jersey industrial firm's ex-infrastructure engineer received a 32-month sentence for sabotaging the company's network and demanding 20 BTC in ransom.
Key takeaways
- 32-Month Prison Term. Daniel Rhyne received a 32-month federal prison sentence for the Bitcoin extortion plot against his employer.
- $750,000 Ransom Demand. The extortion note demanded 20 Bitcoin, worth about $750,000 at the time of the 2023 attack.
- 254 Servers Targeted. Rhyne's planned attack would have altered credentials for 254 servers and 3,284 workstations.
What happened
A 59-year-old former core infrastructure engineer at an unnamed New Jersey industrial firm was sentenced to 32 months in federal prison on September 28, 2026, for launching a deliberate cyberattack against his employer and demanding a Bitcoin ransom. Daniel Rhyne, of Kansas City, Missouri, pleaded guilty in April to two counts: extortion tied to a threat to damage a protected computer, and intentional damage to a protected computer. The attack targeted the Somerset County-based company, which serves clients in sectors including biopharmaceuticals and oil and gas.
Why it matters
The case highlights the risk of insider threats for organizations that grant employees broad administrative access to critical systems. Rhyne's role as the company's subject matter expert for virtual machine hosting gave him the ability to create a hidden, unauthorized virtual machine on the company network on November 9, 2023, which he used to plan and execute the attack. The incident also underscores the continued use of Bitcoin in extortion schemes, as Rhyne demanded 20 BTC, roughly $750,000 at the time, or €700,000 per the extortion email, to halt his planned system disruptions.
What the data shows
- Rhyne created the hidden virtual machine used for the attack on November 9, 2023, more than two weeks before the network intrusion.
- The extortion email demanded 20 Bitcoin, worth approximately $750,000 at the time of the attack, or €700,000 as stated in the message.
- Scheduled tasks set by Rhyne were designed to delete 13 domain administrator accounts, change passwords for 301 user accounts, alter credentials for 254 servers and 3,284 workstations, and shut down dozens of servers starting December 3, 2023.
- The same password, 'TheFr0zenCrew!', protected the hidden virtual machine, the compromised administrator account, 301 user accounts, and the email account used to send the extortion demand.
Questions readers ask
What sentence did the engineer receive for the Bitcoin extortion plot?
Daniel Rhyne was sentenced to 32 months in federal prison on September 28, 2026. He had pleaded guilty in April to extortion and intentional damage to a protected computer.
How much Bitcoin did the engineer demand as ransom?
Rhyne demanded 20 Bitcoin from his employer, which was worth roughly $750,000 at the time of the November 2023 attack. The extortion email also listed the ransom as €700,000.
What was the engineer's role at the targeted company?
Rhyne worked as the company's core infrastructure engineer and was the subject matter expert for hosting virtual machines. His role gave him broad administrative access to the firm's computer systems.