BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

Engineer gets 32 months in prison for Bitcoin ransomware attack on employer

A federal court has sentenced Daniel Rhyne, a former core infrastructure engineer, to 32 months in prison after he pleaded guilty to orchestrating a ransomware attack against his previous emp

AnonymousCryptoCompass newsroom
October 7, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.

A federal court has sentenced Daniel Rhyne, a former core infrastructure engineer, to 32 months in prison after he pleaded guilty to orchestrating a ransomware attack against his previous employer in New Jersey. Rhyne targeted the company’s computer network, demanding a Bitcoin payment in exchange for halting further damage.

Details of the Attack

Rhyne, 59, of Kansas City, Missouri, was found responsible for gaining unauthorized access to his former employer’s IT infrastructure. The affected company, based in Somerset County, New Jersey, operates across major industries including biopharmaceuticals, oil, and gas, though its identity has not been made public by authorities.

At approximately 4pm on November 25, 2023, the company’s network administrators began receiving alerts indicating that hundreds of user passwords were being reset. Investigators later determined that all other domain administrator accounts had been deleted in the same incident.

Less than an hour after the first alerts, company employees received an email titled “Your Network Has Been Penetrated.” The message stated that IT administrators had been locked out and all backup files removed. Rhyne threatened to shut down 40 company servers per day for 10 consecutive days unless the company paid 20 BTC, valued at approximately $750,000 at the time. The demand was also specified in euros, totaling €700,000, with a payment deadline set for December 2.

Network administrators received an email reading, “Your Network Has Been Penetrated.” The attackers warned that 40 company servers would be shut down per day for 10 days unless 20 BTC was paid by December 2, following the deletion of backup files and lockout of administrators.

FBI Investigation and Evidence

Special agents from the FBI traced the origins of the breach to an unauthorized virtual machine initialized within the company’s network on November 9, 2023. The password for this virtual machine was set to “TheFr0zenCrew!”, a detail later found on 301 user accounts, the main administrator account, and the email used for the ransom demand.

Technical analysis showed that, on the morning the attack began, a remote desktop session from the rogue virtual machine created tasks to delete 13 administrator accounts, change passwords affecting 254 servers and 3,284 workstations, and schedule the shutdown of dozens of servers starting December 3.

Further digital forensics connected Rhyne’s company-issued laptop directly to the attack. The forensic team discovered that all browsing activity on his laptop ceased whenever actions took place on the hidden machine. Physical access logs corroborated his presence at company headquarters shortly before his credentials were used in the breach.

On the day of the incident, Rhyne’s laptop accessed the company’s system from his Warren County, New Jersey home, directly before initiating the attack. In the days leading up to the breach, browsing history from the compromised machine included searches such as “how to clear all windows logs from command line” and “how to remotely shutdown a computer using cmd.”

Rhyne pleaded guilty in April to charges of extortion relating to threats to damage protected computers and to the charge of intentional damage to a protected system. Though the complaint initially charged him with wire fraud, this was not included in the finalized charges to which he entered a plea. He faced a maximum sentence of five years for extortion and ten years for intentional damage but ultimately received a 32-month total sentence. U.S. District Judge Michael A. Shipp handed down the decision in Trenton.

The case has highlighted the increasing technical complexity and internal risks facing corporations as cyberattacks become more sophisticated. When crucial infrastructure and administrator access are compromised, monitoring developments across charts, news, and portfolio movements can be the difference between loss and recovery. In a market where a single Fed decision or a sudden altcoin listing can change everything in seconds, jumping between different apps for charts, news, and portfolio tracking is costing investors money. Smart traders are now utilizing privacy-first tools like CryptoAppsy to consolidate everything. Without even the hassle of creating an account, you get real-time charts, smart price alerts, coin-specific news, and critical macro data all on one screen.

Investigators found an unauthorized virtual machine within the company’s network, whose password matched the administrator account and other user profiles, directly linking the device to Rhyne’s laptop and physical access to the company.

The post Engineer gets 32 months in prison for Bitcoin ransomware attack on employer appeared first on COINTURK NEWS.