A Kansas City, Missouri man, Daniel Rhyne, has been sentenced to 32 months in federal prison for extortion linked to a ransom plot against his former employer. The 59‑year‑old, who was a core infrastructure engineer at an industrial firm based in Somerset County, New Jersey, used scheduled tasks to sabotage the company’s domain controller in November 2023.
He deleted 13 domain administrator accounts, reset passwords for hundreds of user accounts, and altered local administrator passwords on thousands of assets, effectively denying access to servers, workstations and data. The attacker’s emails and the ransom note followed within an hour, warning of backups deletion and a plan to shut down more servers daily unless a payment of 20 bitcoin was made, with the ransom pegged at around $750,000 at the time. The firm did not pay the ransom and instead began internal forensics, aided by the FBI.
Forensic work connected the activity directly to Rhyne’s residential IP address in Warren County, New Jersey. The FBI filed a criminal complaint on 8 August 2024, leading to his arrest on 27 August 2024 in Kansas City after he had moved there. He pleaded guilty on 1 April 2026 in federal court in Trenton, New Jersey, before District Judge Michael A. Shipp, and was sentenced on 28 September 2026.
The case illustrates how insider sabotage can be used to threaten infrastructure, and how rapid incident response and cross‑agency cooperation can produce clear evidence of exploitation and accountability, even when no payment is received.