U.S. federal prosecutors stated on Monday that a former employee of an industrial company in New Jersey was sentenced to 32 months in prison for attacking the employer's computer network and demanding Bitcoin ransom.
59-year-old Daniel Rhyne comes from Kansas City, Missouri. He was sentenced on September 28th in Trenton by U.S. Federal District Judge Michael A Shipp. Rhyne pleaded guilty in April, admitting to one charge of extortion related to threatening to damage protected computers, as well as one charge of intentionally damaging protected computers.
On October 5th, the United States Attorney's Office of New Jersey wrote on social media: “Former Employee of Industrial Company Sentenced to 32 Months in Prison for Computer Attack and Extortion”.
According to a criminal complaint from the Federal Bureau of Investigation, Rhyne was once a core infrastructure engineer for the company and an expert in virtual machine hosting. The prosecution did not disclose the name of the company, but stated that it is headquartered in Somerset County, New Jersey, and its services cover the biopharmaceutical and oil and gas industries.
A complaint stated that around 4 p.m. on November 25, 2023, the company's network administrators began receiving notifications for password resets from hundreds of accounts, and subsequently discovered that all other domain administrator accounts had been deleted.
44 minutes later, an employee received an email with the subject “Your Network Has Been Penetrated.” The email claimed that the company’s IT administrator had been locked out and the backups had been deleted, and warned that unless $20 BTC (approximately $750,000 at the time) was paid by December 2nd, another 40 servers would be shut down each day for the following 10 days.
According to the complaint, the ransom demanded in the email was 700,000 euros, and payment was required to be made in Bitcoin.
Hidden Virtual Machine
Investigators traced this attack to an unauthorized virtual machine. The virtual machine was created on the company's network on November 9, 2023, with the password “TheFr0zenCrew!”, which was later also set on the administrator account, 301 user accounts, as well as the email account used to send ransom demands.

Complaints allege that on the morning of the attack, a scheduled task was created from this machine via a remote desktop session. The task was intended to delete 13 administrator accounts, modify the passwords of 254 servers and 3,284 workstations, and shut down dozens of servers starting from December 3rd.
FBI associated this machine with his own by using a company laptop owned by Rhyne. The complaint stated that the browsing activities on the laptop stopped when browsing on the hidden machine, and the building access records showed that he entered the headquarters a few minutes before logging into his own account.
The complaint also stated that on the day of the attack, the laptop belonging to Rhyne was connected to the internet from the IP address assigned to their residence in Warren County, New Jersey, and within a few minutes thereafter, sessions related to setting up these tasks appeared.
A complaint alleges that a few days ago, a user of this machine searched for “how to clear all windows logs from command line” and “how to remotely shutdown a computer using cmd”.
The complaint also raised allegations of wire fraud against Rhyne, but these allegations did not appear in the two charges for which he pleaded guilty. According to the prosecution, he could face a maximum sentence of 5 years for the extortion charges and a maximum sentence of 10 years for the computer damage charges.












