Engineer sentenced for locking over 3,000 devices on employer network
Description
A former core infrastructure engineer at an industrial company in New Jersey was sentenced to 32 months in prison for locking over 3,000 devices on his employer's network in a ransomware-style extortion attempt. The attacker used administrator privileges to change passwords, delete domain admin accounts, and shut down servers and workstations. He demanded a ransom of 20 bitcoins and claimed backups were deleted to prevent recovery. The attack was discovered when password reset notifications were received and domain admin accounts were found deleted, denying access to the network.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Daniel Rhyne, a former core infrastructure engineer, remotely accessed his employer's network without authorization using an administrator account between November 8 and November 25, 2023. He scheduled tasks on the domain controller to change the administrator account password, deleted 13 domain admin accounts, and reset passwords for 301 domain user accounts. He also changed passwords for local admin accounts, blocking access to 254 servers and 3,284 workstations, and shut down random servers and workstations over several days. On November 25, he sent a ransom email demanding 20 bitcoins, threatening to shut down 40 servers daily unless paid. Investigations revealed he researched methods to change passwords, delete accounts, and clear Windows logs prior to the attack. This insider attack disrupted critical infrastructure and attempted extortion.
Potential Impact
The attack resulted in loss of administrative access to the company's network by deleting domain admin accounts and changing passwords, effectively locking out legitimate administrators and users. Access to thousands of servers and workstations was blocked, and random shutdowns caused operational disruption. The attacker also claimed to have deleted backups, which would have complicated recovery efforts. The incident caused significant operational impact and posed a severe risk to business continuity.
Defensive Guidance
This incident was caused by malicious insider activity using legitimate administrator credentials. Mitigation involves enforcing strict access controls, monitoring for unusual administrative activity, and implementing robust insider threat detection programs. Since this is a past incident with a criminal conviction, no patch or fix applies. Organizations should review and harden privileged access management and incident response procedures to prevent similar insider attacks.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6ac4b2512cdf04f6568f3ff5
Added to database: 10/06/2026, 08:33:21 UTC
Last enriched: 10/06/2026, 08:33:26 UTC
Last updated: 10/06/2026, 14:48:37 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.