2 min read

Former Engineer Sentenced to 32 Months in Bitcoin Extortion Attack

Daniel Rhyne used privileged network access to disrupt his employer’s systems and demand 20 Bitcoin (BTC), valued at about $750,000 at the time.

Mentioned assets
Company laptop beside a secured industrial network operations room / TokenPost.ai
Company laptop beside a secured industrial network operations room / TokenPost.ai

Daniel Rhyne, a former infrastructure engineer, was sentenced to 32 months in federal prison after using privileged access to damage his employer’s network and demand a Bitcoin ransom.

The sentence was imposed Sept. 28, 2026, in Trenton, New Jersey. Rhyne, 59, worked for a U.S.-based industrial company headquartered in Somerset County, New Jersey. The company was not identified.

The attack began at about 4 p.m. ET (9 p.m. UTC) Nov. 25, 2023, when administrators received password-reset notifications and found that other domain-administrator accounts had been deleted. About 44 minutes later, an email with the subject line “Your Network Has Been Penetrated” demanded €700,000 in Bitcoin.

The demand involved 20 BTC, valued at approximately $750,000 at the time, with payment due Dec. 2, 2023. The email threatened to shut down “40 random servers” each day for 10 days.

Scheduled tasks were designed to delete 13 domain-administrator accounts, change passwords for 301 domain-user accounts, and affect 254 servers and 3,284 workstations. The actions were intended to disrupt the company’s network, but not every listed system was shown to have been disabled.

Rhyne used unauthorized remote-desktop sessions and a hidden virtual machine on the company’s network. His role as the company’s subject-matter expert on hosting virtual machines gave him detailed knowledge of its infrastructure. The hidden virtual machine and extortion email were linked to his company laptop and user account.

Rhyne pleaded guilty to extortion involving a threat to damage a protected computer and intentional damage to a protected computer. The charges carried maximum prison terms of five years and 10 years, respectively.

The case shows how privileged access and ordinary network-administration tools can be used to disrupt corporate systems and create leverage for a Bitcoin ransom. The scheduled actions targeted 254 servers and 3,284 workstations. There is no indication that the ransom was paid.

Rhyne’s guilty plea was announced April 2, 2026, and his sentence was announced Oct. 5.

Riza Dagoc

Riza Dagoc reports on regulation, investing and the digital-asset business for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…