ThreatPaper
Insider ThreatExtortion & BlackmailHigh

Insider sabotage at a New Jersey industrial firm: how the FBI traced Daniel Rhyne's domain-controller lockout

By Sethu Satheesh · 9 Oct 2026 · 20 min read

Source: www.justice.gov

Threat Actor: Daniel Rhyne (convicted insider; named in the Accused section, not a tracked threat-actor group) · Target: Unnamed U.S. industrial company headquartered in Somerset County, New Jersey ("Victim-1")


Executive Summary

On September 28, 2026, U.S. District Judge Michael A. Shipp sentenced Daniel Rhyne, 59, of Kansas City, Missouri, to 32 months in federal prison in Trenton, New Jersey, for a sabotage-and-extortion attack on the Windows network of his former employer, an unnamed U.S. industrial company headquartered in Somerset County, New Jersey and referred to in the record only as "Victim-1."1 Rhyne, a core infrastructure engineer who was Victim-1's subject-matter expert on hosting virtual machines, had pleaded guilty on April 1, 2026 to a two-count Information charging extortion in relation to a threat to damage a protected computer and intentional damage to a protected computer.2 The U.S. Attorney's Office for the District of New Jersey announced the sentence on October 5, 2026.1

The mechanism was an insider's abuse of Active Directory administration, not an attack on operational technology. Between November 8 and November 25, 2023, Rhyne used a legitimate Victim-1 domain administrator account — reached through an unauthorized virtual machine he had created on the network — to plant roughly 16 scheduled tasks on Victim-1's domain controller.3 Six of them fired at 4:00 p.m. EST on November 25, 2023: they deleted 13 domain administrator accounts, reset the passwords of the compromised administrator account and 301 domain user accounts to TheFr0zenCrew! using the net user command, and used the Sysinternals tool PsPasswd to change local administrator passwords affecting 254 servers and 3,284 workstations.3 The remaining tasks were set to shut down dozens of servers over several days beginning in December, which never happened because the scheme was detected.3

Forty-four minutes after the password resets began, at 4:44 p.m. EST, Victim-1 employees received an email titled "Your Network Has Been Penetrated" from an external address, claiming all IT administrators had been locked out or deleted and all backups destroyed, and demanding €700,000 in the form of 20 bitcoin — worth roughly $750,000 that day — by December 2, 2023, on threat of shutting down 40 random servers per day for ten days.3 No ransom was paid. The attack is frequently described in trade coverage as a "ransomware-style" incident, but no encrypting malware was deployed; the damage was done with built-in Windows administration tools and scheduled tasks.4

What makes this case a clean study in insider detection is how quickly the forensic trail closed. The intrusion was caught in progress by the password-reset notifications it generated and the sudden disappearance of the domain administrator accounts, and the FBI tied it to Rhyne through a chain of ordinary evidence: a rogue virtual machine that was the only system to remote-desktop into the administrator account, a reused password string that appeared on the virtual machine, the domain accounts, and the extortion mailbox alike, incriminating web searches on his assigned laptop, building badge and camera records that placed him on site minutes before each login, and a home IP address that carried the final attack session.3 This paper reconstructs that trail from the sworn criminal complaint.

Weekly Digest

Get the next investigation in your inbox

New research, once a week. No vendor pitches.

Verification of Claims

  1. Claim: Scheduled tasks on the domain controller were set to delete 13 domain admin accounts, reset 301 domain user passwords, and change local admin passwords affecting 254 servers and 3,284 workstations. → Verified → These exact figures appear in the sworn FBI criminal complaint (Mag. No. 24-12241), both in the summary of malicious activity and in the itemized list of the six scheduled tasks that executed on November 25, 2023.3 BleepingComputer's reporting independently matches the same counts.45 The split had circulated on at least one low-quality secondary page, but it originates in the primary charging document.

  2. Claim: The ransom demand was 20 bitcoin, worth about $750,000. → Verified → The complaint states the Extortion E-Mail demanded €700,000 "in the form of 20 bitcoin," and that 20 BTC had an equivalent value of approximately $750,000 on November 25, 2023.3 All three DOJ press releases cite the 20 BTC / ~$750,000 figure.162 The euro and dollar figures are not in conflict — both describe the same single demand.

  3. Claim: This was an attack on an "industrial" or operational-technology network. → Partially verified → The victim is an industrial company, which is verified.3 But the systems attacked were a Windows Active Directory environment — a domain controller, domain and local administrator accounts, servers and workstations.3 Nothing in the complaint, the DOJ releases, or trade coverage describes any programmable logic controller, SCADA system, or other operational-technology asset being touched.34 "Industrial network lockout" describes the victim's business, not the systems compromised.

  4. Claim: Rhyne was caught because of a reused password and a rogue virtual machine. → Verified → The complaint sets out that the password TheFr0zenCrew! was common to the Hidden Virtual Machine's account, the reset domain accounts, and the extortion mailbox, and that the Hidden Virtual Machine was the sole system to remote-desktop into the administrator account during the intrusion window and was in turn linked to Rhyne's assigned user account, laptop, badge records, and home IP address.3

Timeline

Date Actor Event Source
Nov 8, 2023 — Start of the charged intentional-damage window (Count Two) 3
Nov 9, 2023 Rhyne (per complaint) Hidden Virtual Machine created on Victim-1's network, its account password set to TheFr0zenCrew!; Rhyne badges into HQ at 6:55 a.m., logs into his laptop at 6:58 a.m., opens a company password spreadsheet including the administrator account's password at 7:38 a.m. 3
Nov 10–25, 2023 Rhyne (per complaint) Hidden Virtual Machine repeatedly used to access the Victim-1 Administrator Account on the domain controller; the only system to do so by remote desktop in this window 3
Nov 15, 2023 Rhyne (per complaint) Laptop web searches on command-line password changes and net user; Sysinternals Utilities (including PsPasswd) placed on the domain controller 3
Nov 22, 2023 Rhyne (per complaint) Hidden Virtual Machine web searches: setting domain passwords, deleting a domain account, remote shutdown, and clearing Windows logs from the command line 3
Nov 23, 2023 Rhyne (per complaint) From his home IP in Warren County, NJ: laptop login 6:48 a.m., network connection 6:50 a.m., Hidden VM 6:57 a.m., remote-desktop to the domain controller 7:02 a.m. 3
Nov 25, 2023, 7:48–9:45 a.m. EST Rhyne (per complaint) Remote-desktop session from the Hidden VM to the administrator account on the domain controller; ~16 unauthorized scheduled tasks created (starting 8:12 a.m.) 3
Nov 25, 2023, ~4:00 p.m. EST Scheduled tasks 13 domain admin accounts deleted; admin and 301 user passwords reset to TheFr0zenCrew!; local admin passwords changed on 254 servers and 3,284 workstations; admins begin receiving reset notifications 3
Nov 25, 2023, 4:44 p.m. EST Rhyne (per complaint) Extortion email "Your Network Has Been Penetrated" sent; demands €700,000 / 20 BTC (~$750,000) by Dec 2; threatens 40 servers/day shutdowns for 10 days 3
Dec 3, 2023 Scheduled tasks Server-shutdown tasks set to begin (prevented by detection) 3
Aug 8, 2024 FBI / Mag. Judge Clark Criminal complaint sworn in Newark (Mag. No. 24-12241) 36
Aug 27, 2024 FBI Rhyne arrested in Missouri; initial appearance in Kansas City; released 6
Apr 1, 2026 Rhyne Pleads guilty to a two-count Information before Judge Shipp in Trenton 2
Sep 28, 2026 Judge Shipp Rhyne sentenced to 32 months in prison 1
Oct 5, 2026 US Attorney's Office, D.N.J. Sentence announced 1

Attack Anatomy

This was sabotage of a Windows Active Directory environment by a privileged insider, carried out entirely with legitimate administration tools and native Windows features. Despite the victim being an industrial company, no operational-technology, SCADA, or industrial-control system is described anywhere in the record as having been accessed or affected; the targets were a domain controller, domain and local administrator accounts, servers, and workstations.34 The stages below are drawn from the FBI's sworn complaint.

Staging: a hidden virtual machine and a stolen admin password

On or about November 9, 2023, an unauthorized virtual machine — the "Hidden Virtual Machine" — was created on Victim-1's network, with its user-account password set to TheFr0zenCrew!.3 Rhyne was Victim-1's subject-matter expert on hosting virtual machines, which is precisely the access and skill a rogue VM on the corporate network requires.3 The same morning, badge and camera records placed Rhyne inside headquarters at 6:55 a.m.; his assigned laptop logged in at 6:58 a.m., and at 7:38 a.m. that laptop opened a company spreadsheet of passwords that included the credential for the domain administrator account later abused in the attack (T1552.001, T1564.006).3

Reconnaissance: command-line research

Over the following two weeks the operator researched the exact techniques used in the attack. On November 15, Rhyne's user account, on his laptop, searched for command line to change password, command line to change local administrator password, net user, and command line to remotely change local administrator password.3 On November 22, from the Hidden Virtual Machine, the searches continued: How to set domain user password from command line, how to delete a dmoain [sic] account from the command line, how to remotely shutdown a computer using cmd, how to clear all windows logs from command line, and net user syntax change password (T1059.003).3

Weaponization: Sysinternals on the domain controller

Also on November 15, the Hidden Virtual Machine's user placed the Sysinternals Utilities — including PsPasswd, the tool for changing account passwords on local or remote systems — onto Victim-1's domain controller, where it would later be invoked by the scheduled tasks to mass-change local administrator passwords.3

Execution: scheduled tasks lock the domain

Using the Hidden Virtual Machine to remote-desktop into the legitimate domain administrator account on the domain controller, the operator created approximately 16 unauthorized scheduled tasks between 8:12 a.m. and 9:45 a.m. on November 25, 2023 (T1053.005, T1021.001, T1078.002).3 Six were timed to execute at 4:00 p.m. that day (T1531):3

  • delete 13 domain administrator accounts and change the compromised administrator account's password to TheFr0zenCrew! via net user;
  • change 301 domain user account passwords to TheFr0zenCrew! via net user;
  • change two local administrator passwords affecting 254 servers via PsPasswd;
  • change two local administrator passwords affecting 3,284 workstations via PsPasswd.

The remaining tasks were configured to shut down dozens of servers over several days beginning December 3, 2023 (T1529, T1078.003).3 Collectively the tasks were designed to deny Victim-1 access to its own systems and data.3

Extortion: the ransom email

When the 4:00 p.m. tasks fired, Victim-1's network administrators began receiving password-reset notifications and found the domain administrator accounts gone.3 At 4:44 p.m., employees received an email titled "Your Network Has Been Penetrated" from an external address, claiming all IT administrators were locked out or deleted and all backups destroyed, and demanding €700,000 in 20 bitcoin (~$750,000) by December 2, 2023, failing which 40 random servers would be shut down daily for ten days (T1657).3 No payment was made.1

How investigators traced it to Rhyne

The forensic attribution rested on several independent threads, all in the complaint:3

  • A reused password. TheFr0zenCrew! was the password set on the Hidden Virtual Machine's account (November 9), the string the scheduled tasks pushed to the administrator and 301 user accounts, and the password of the external account that sent the extortion email — tying the staging VM, the sabotage, and the ransom demand to one operator.
  • A single rogue VM. The Hidden Virtual Machine was the only system to remote-desktop into the administrator account on the domain controller during November 10–25, and an internal investigation found it had been accessed by the user account and laptop Victim-1 had assigned to Rhyne for his VM-hosting duties.
  • Browsing correlation. Internet activity on Rhyne's laptop stopped whenever browsing occurred on the Hidden Virtual Machine, indicating one person switching between them; and the November 15 laptop searches mirrored the November 22 VM searches.
  • Physical access records. Security cameras and badge logs showed Rhyne entering headquarters minutes before his user account logged into his laptop and then reached the Hidden Virtual Machine (e.g., badge-in 6:55 a.m. / laptop 6:58 a.m. on November 9).
  • A home IP address. When Rhyne was not on site, his laptop reached the network — and the Hidden Virtual Machine, and through it the domain controller — from the IP address assigned to his Warren County, New Jersey residence, including the November 25 session that created the attack's scheduled tasks.

Loading diagram...

Accused

Name: Daniel Rhyne Age: 59 at sentencing (reported as 57 at the August 2024 charging)16 Residence: Kansas City, Missouri at the time of arrest and sentencing; a resident of Warren County, New Jersey at the time of the offense13 Role: Core infrastructure engineer at Victim-1 and its subject-matter expert on hosting virtual machines3 Status: Convicted by guilty plea; sentenced12

Rhyne was charged by criminal complaint on August 8, 2024 (Mag. No. 24-12241, D.N.J.) with three counts: extortion in relation to a threat to cause damage to a protected computer (18 U.S.C. §§ 1030(a)(7)(A), (c)(3)(A)), intentional damage to a protected computer (18 U.S.C. §§ 1030(a)(5)(A), (c)(4)(B)(i)), and wire fraud (18 U.S.C. § 1343).36 He was arrested in Missouri on August 27, 2024, appeared in Kansas City federal court, and was released.6 On April 1, 2026 he pleaded guilty before Judge Shipp to a two-count Information charging only the extortion and intentional-damage offenses; the wire-fraud count was not part of the plea.2 The extortion count carried a maximum of five years and the damage count a maximum of ten; on September 28, 2026 Judge Shipp imposed 32 months.12 Defense counsel was Jonathan F. Marshall, Esq.1

Because Rhyne has been convicted on his own guilty plea, the conduct above is treated as established for the two counts of conviction; the wire-fraud allegation was never adjudicated and is not a finding. The remaining details are the government's sworn allegations in the criminal complaint.

Motivation: Financial extortion of a former employer.3 The government did not publicly allege a grievance or co-conspirator; the extortion email's "TheFr0zenCrew!" string and plural "crew" framing were not tied by the complaint to any second person.3

Sophistication: Moderate. The tradecraft — a rogue VM, native net user commands, the legitimate Sysinternals PsPasswd tool, and Windows Task Scheduler — is "living off the land" with administrator privileges the insider already held, rather than custom malware. The planning (two weeks of staging and research) was deliberate, but the operational security was poor: the operator reused one memorable password everywhere, ran incriminating searches on his own assigned laptop, and connected from his home IP.3

MITRE ATT&CK techniques (Enterprise matrix; IDs verified live on attack.mitre.org on October 8, 2026):

ID Technique
T1078.002 Valid Accounts: Domain Accounts
T1078.003 Valid Accounts: Local Accounts
T1552.001 Unsecured Credentials: Credentials In Files
T1564.006 Hide Artifacts: Run Virtual Instance
T1136.001 Create Account: Local Account
T1021.001 Remote Services: Remote Desktop Protocol
T1059.003 Command and Scripting Interpreter: Windows Command Shell
T1053.005 Scheduled Task/Job: Scheduled Task
T1531 Account Access Removal
T1529 System Shutdown/Reboot
T1685.005 Disable or Modify Tools: Clear Windows Event Logs
T1657 Financial Theft

OPSEC: The attacker tried to work from a concealed virtual machine and researched clearing Windows event logs, but undercut both by reusing the TheFr0zenCrew! password across the VM, the sabotaged accounts, and the extortion mailbox, by running attack-related searches on his corporate laptop under his own account, and by connecting from his residential IP.3 T1685.005 (Clear Windows Event Logs) is included on the basis of the attacker's own command-line searches on clearing Windows logs; the complaint does not state that logs were in fact wiped, and the surviving artifacts suggest any such attempt failed or was not carried out.3

Technical Indicators

# From the sworn FBI criminal complaint (Mag. No. 24-12241). No file hashes, IP
# addresses, bitcoin address, or the extortion email address were published in
# the charging document; the items below are the behavioural and credential
# indicators that are in the record.
reused_password:
  - 'TheFr0zenCrew!'   # set on the rogue VM account, pushed to the domain admin
                       # and 301 domain user accounts, and the password of the
                       # extortion mailbox
extortion_email_subject:
  - 'Your Network Has Been Penetrated'
tools_and_techniques:
  - 'Unauthorized ("Hidden") virtual machine on the corporate network'
  - 'Remote Desktop Protocol into the domain controller'
  - 'Windows Task Scheduler (~16 malicious scheduled tasks on the domain controller)'
  - 'net user (account deletion and password changes)'
  - 'Sysinternals PsPasswd (local administrator password changes)'
attacker_web_searches:
  - 'command line to change local administrator password'
  - 'how to delete a dmoain [sic] account from the command line'
  - 'how to remotely shutdown a computer using cmd'
  - 'how to clear all windows logs from command line'
  - 'net user syntax change password'
ransom_demand:
  - 'EUR 700,000 in the form of 20 BTC (~$750,000 on 25 Nov 2023), due 2 Dec 2023'
file_hashes: none disclosed
network_iocs: none disclosed
note: >
  The bitcoin address and the external extortion email address exist in the
  investigation but were not reproduced in the public complaint. No encrypting
  ransomware was deployed; damage was done with built-in Windows administration.

Charges and court. United States v. Daniel Rhyne, Mag. No. 24-12241, U.S. District Court for the District of New Jersey, before Magistrate Judge James B. Clark III at the complaint stage and U.S. District Judge Michael A. Shipp for plea and sentencing.132 The August 8, 2024 complaint charged three counts; Rhyne pleaded guilty on April 1, 2026 to a two-count Information (the extortion and intentional-damage counts under 18 U.S.C. § 1030), and was sentenced on September 28, 2026 to 32 months in prison.132

Investigating agencies. The FBI's Newark Field Office led the investigation (Special Agent in Charge Stefanie Roddy at the plea and sentencing stage; James E. Dennehy was named at the arrest stage), with assistance from the FBI's Kansas City Field Office.162 The complaint was sworn by FBI Special Agent Timothy Lee.3

Prosecutors. Assistant U.S. Attorney Robert Taj Moore of the Cybercrime Unit in Newark represented the government at the plea and sentencing; AUSA Dong Joo Lee of the same unit was named on the 2024 arrest.162 The sentence was announced by U.S. Attorney Robert Frazer; the 2024 arrest was announced by then-U.S. Attorney Philip R. Sellinger.16

Victim. Victim-1 is not named in any public filing. The complaint describes it only as a U.S.-based industrial company headquartered in Somerset County, New Jersey that serves aquaculture, biopharmaceutical, chemistry, electronics, food and beverage, healthcare, hydrogen mobility, manufacturing, metals, oil and gas, and pulp and paper customers.3 This paper does not attempt to identify it; naming a victim the government deliberately anonymized would go beyond the record.

Regulatory. No securities, data-breach-notification, or sector-regulatory action tied to this incident had been published as of October 8, 2026; the matter was handled entirely as a federal criminal prosecution.1

Impact Assessment

  • Confirmed — domain lockout executed: The six scheduled tasks timed for 4:00 p.m. on November 25, 2023 executed: 13 domain administrator accounts were deleted and the passwords of the administrator account, 301 domain user accounts, and local administrator accounts affecting 254 servers and 3,284 workstations were changed, generating the reset notifications that exposed the attack.3
  • Confirmed — mass shutdowns prevented: The scheduled tasks designed to shut down dozens of servers over several days beginning December 3, 2023 did not run; the scheme was detected on November 25.3
  • Confirmed — extortion failed: No ransom was paid.1
  • Confirmed — loss threshold: The intentional-damage count charged aggregate loss to Victim-1 of at least $5,000 within a one-year period; this is the statutory jurisdictional floor, not a total damages figure.3
  • Reported, not independently confirmed: The extortion email's claims that all IT administrators were locked out or deleted and that all backups had been deleted are the attacker's own assertions in the email; the complaint's forensic section independently confirms the domain-admin deletions but does not separately confirm destruction of all backups.3
  • Unknown: Victim-1's total remediation cost and downtime; whether any local administrator password changes on the 254 servers / 3,284 workstations caused sustained operational disruption before remediation; the identity of Victim-1.3

Lessons and Defensive Recommendations

For SOC and detection teams

  • Treat a burst of password-reset notifications for a privileged account plus the disappearance of domain administrator accounts as a high-severity, page-someone-now signal — that pairing is exactly what surfaced this attack in progress.3
  • Alert on scheduled-task creation on domain controllers, especially tasks invoking net user or PsPasswd, and on the staging of Sysinternals binaries onto a DC.3
  • Hunt for virtual machines on the network that no change record accounts for; here a single rogue VM was both the staging host and the thread that unravelled the attribution.3

For identity and Active Directory teams

  • Store administrator credentials in a privileged-access vault, not a shared spreadsheet; the attacker lifted the domain administrator password from a company password spreadsheet.3
  • Enforce tiered administration and just-in-time elevation so one engineer's standing domain-admin rights cannot delete every other domain-admin account and reset hundreds of users in a single scheduled run.3
  • Keep offline, immutable backups of Active Directory and ensure domain-admin deletions are recoverable without the deleted accounts.

For leadership and insider-risk programs

  • The person best placed to do this kind of damage is the trusted specialist who built the systems; departure and role-change processes must revoke privileged access and audit for planted persistence (rogue VMs, scheduled tasks) rather than only disabling a user at exit.3
  • Correlating physical badge and camera records with account activity turned a strong technical case into an airtight one; insider-risk programs should ensure those data sets can be joined during an investigation.3

For reporters and researchers

  • "Ransomware" is the wrong label for this incident: no encrypting malware was used. It was credential-sabotage extortion built from native Windows administration. Precision matters because the defenses differ.34
  • "Industrial network lockout" describes the victim's sector, not the attack surface; the systems hit were ordinary Windows Active Directory, not operational technology.3

Sources

Footnotes

  1. U.S. Attorney's Office, District of New Jersey — Former Employee of Industrial Company Sentenced to 32 Months in Prison for Computer Attack and Extortion — October 5, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18

  2. U.S. Attorney's Office, District of New Jersey — Former Employee of National Industrial Company Pleads Guilty to Crimes Related to Hacking Computer Networks and Extorting Employees — April 2, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10

  3. U.S. Department of Justice — Criminal Complaint, United States v. Daniel Rhyne, Mag. No. 24-12241 (D.N.J.) — August 8, 2024 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46 ↩47 ↩48 ↩49 ↩50 ↩51 ↩52 ↩53 ↩54 ↩55 ↩56 ↩57 ↩58 ↩59 ↩60 ↩61 ↩62

  4. BleepingComputer — Engineer sentenced for locking thousands of devices on employer network — October 6, 2026 ↩ ↩2 ↩3 ↩4 ↩5

  5. BleepingComputer — Man admits to extortion plot locking coworkers out of thousands of Windows devices — April 3, 2026 ↩

  6. U.S. Attorney's Office, District of New Jersey — Former Employee of National Industrial Company Arrested for Attempted Data Extortion — August 28, 2024 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9

Topics: #insider-threat#daniel-rhyne#active-directory#domain-controller#scheduled-tasks#pspasswd#net-user#cfaa#district-of-new-jersey
Original Incident Report →

Related Research

Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.

RansomwareInsider ThreatExtortion & Blackmail

In July 2019, Capital One Financial Corporation formally disclosed one of the most significant data breaches in the history of the financial services sector. The security incident resulted in the...

Data Breach

ShinyHunters extorted Jeppesen ForeFlight, the aviation-navigation unit Boeing sold to Thoma Bravo for $10.55B. Boeing acknowledged the threat-actor claims, the company reported no operational impact, and a suspected member was reportedly detained in Jordan and cooperating with the FBI.

Extortion & BlackmailData Breach