A former infrastructure engineer at a New Jersey-based industrial company has been sentenced to 32 months in federal prison after admitting that he sabotaged his employer’s computer systems—and demanded roughly $750,000 in bitcoin to stop the attack.
Engineer Who Sabotaged Employer for Bitcoin Ransom Gets Prison Time

Key Takeaways
- Daniel Rhyne was sentenced to 32 months in prison for sabotaging his former employer’s computer systems and attempting to extort the company.
- Prosecutors said he deleted administrator accounts, changed passwords, and shut down servers using his privileged access.
- Rhyne demanded about 20 bitcoin, worth roughly $750,000 at the time, in exchange for stopping the attack.
Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced Sept. 28 in federal court in Trenton after previously pleading guilty to extortion involving a threat to damage a protected computer and intentionally damaging a protected computer, according to the U.S. Attorney’s Office for the District of New Jersey.
Rhyne worked as a core infrastructure engineer for the unidentified industrial company, giving him administrative privileges over its computer systems. An FBI criminal complaint filed in 2024 describes a methodical effort to exploit that access. Investigators said Rhyne created a hidden virtual machine on the company network—protected by the password “TheFr0zenCrew!”—and used it to remotely access an administrator account.
On Nov. 25, 2023, prosecutors said, Rhyne scheduled a series of automated tasks designed to execute later that day. The commands would delete 13 domain administrator accounts, change the passwords of 301 user accounts, alter local administrator passwords affecting 254 servers, and change credentials tied to more than 3,200 employee workstations.
Other scheduled tasks would shut down company servers and computers. Investigators said the combined actions were designed to deny the company access to its own systems and data.
Evidence Pointed to an Internal Threat
The complaint detailed signs of preparation. Days before the attack, searches conducted from the hidden virtual machine included queries such as how to change administrator passwords from a command line, delete a domain account, and remotely shut down a computer. Similar searches were found on Rhyne’s company laptop, investigators said.
At about 4 p.m. on Nov. 25, network administrators discovered that their accounts had been deleted. Roughly 44 minutes later, employees received an extortion email claiming that all IT administrator accounts had been deleted and backups erased. The sender threatened to shut down an additional 40 servers each day for 10 days unless the company paid approximately 20 bitcoin by Dec. 2—then worth about $750,000, and currently valued near $1.67 million.
Investigators ultimately linked the hidden virtual machine to Rhyne’s account and company laptop. They also found that the password protecting the extortion email address was “TheFr0zenCrew!”—the same password used for the hidden virtual machine.
Bitcoin price dropped to an intraday low of $82,734, erasing early-month gains. Despite forced long liquidations, open interest remained steady,…
Read Now: Bitcoin Price Erases October Gains: Why $81,300 Is Now the Critical Level
















