Daniel Rhyne: The IT Engineer Who Held His Own Company Hostage for 20 Bitcoin
He locked his own employer out of its network and demanded 20 bitcoin. His web searches gave him away. A judge gave him 32 months.

Key numbers
20 BTC ($750K)
Ransom demanded
32 months
Sentence
3,538
Computers targeted
None reported
Ransom paid
At about 4:00 p.m. on Saturday 25 November 2023, the long Thanksgiving weekend, the people who ran the computer network at an industrial company in Somerset County, New Jersey, started getting alerts on their phones. Passwords were being reset on hundreds of staff accounts. Then they found that every administrator account except one had been deleted. The people whose job was to fix the network could no longer get into it.
Forty-four minutes later, at 4:44 p.m., some employees received an email from an outside address. The subject line read "Your Network Has Been Penetrated." It said the company's IT administrators had been "locked out or deleted", that its backups had been deleted, and that 40 random servers would be shut down every day for 10 days unless a ransom was paid by 2 December. The price was 700,000 euros, to be sent as 20 bitcoin to an address in the email. On that day 20 bitcoin was worth about $750,000.
The email was unsigned. The man who wrote it had helped build the network. Daniel Rhyne was the company's core infrastructure engineer, one of the people responsible for the machinery underneath everything else, and its in-house expert on virtual machines. Less than three years later, on 28 September 2026, US District Judge Michael A. Shipp sentenced him in Trenton federal court to 32 months in prison. The US Attorney's Office for the District of New Jersey announced the sentence on 5 October 2026.
Powered by Cyntri AI
The technology behind this newsroom. Built by Cyntri AI.
AI-assisted publishing, content pipelines and analytics. Crypto Media Zone is our working example.
Powered by Cyntri AI
The company and the man
Prosecutors never named the company in their press releases, calling it only "Victim-1", a US industrial firm headquartered in Somerset County. The FBI's criminal complaint says it serves industries from aquaculture and biopharmaceuticals to hydrogen, metals, oil and gas, and pulp and paper. When the sentence was announced, NJ.com identified it as Messer North America, an industrial and medical gas supplier based in Bridgewater. Messer describes itself as part of the world's largest privately held industrial gas business. Messer did not respond to a request for comment from Inc. magazine.
Rhyne lived in Warren County, New Jersey, at the time. By his arrest he had moved to Kansas City, Missouri. He was 57 when he was charged and 59 when he was sentenced.
His job gave him the keys. A network administrator in a big company is something like the building manager who holds the master keys, the alarm codes and the list of who is allowed into which room. Rhyne knew where those keys were kept, and according to the complaint, on 9 November 2023 his laptop opened a company spreadsheet that held administrator passwords.
How the lockout worked
No hacking from outside was needed. Rhyne used ordinary tools that come with Microsoft Windows, the same ones administrators use every day, and set them on timers.
First, on 9 November he created a virtual machine on the company's network: a computer that exists only as software, running inside one of the company's real servers. To anyone not looking for it, it was invisible, like a spare room added to a building that is not on the floor plan. Its password was "TheFr0zenCrew!"
From that hidden machine he connected, on numerous occasions between 10 and 25 November, to the domain controller. That is the server that checks every login in the company, the front desk that decides who gets in. On 15 November he copied a free Microsoft toolkit called Sysinternals onto it, including a small program, PsPasswd, that changes passwords on many computers at once.
On the morning of 25 November, between 7:48 and 9:45 a.m., he set about 16 scheduled tasks: instructions that a Windows computer carries out by itself at a set time, like a timer on an oven. Six were set to go off at 4:00 p.m. that day. They would delete 13 administrator accounts, change the password on 301 staff accounts to "TheFr0zenCrew!", and change the local administrator passwords that controlled 254 servers and 3,284 workstations, the powerful desktop computers engineers use: 3,538 machines in all. The rest were set to start shutting down dozens of servers on 3 December, the day after the ransom deadline.
The effect was a hostage situation without a hostage-taker in the room. The company's own staff could not undo the changes because the accounts they would need had been deleted, and the timers kept running. The complaint says the scheme was designed to deny the company access to its own systems and data. Whether the backups really had been deleted is something the ransom email claimed; the court papers do not confirm it.
Why bitcoin, and why it did not hide him
Bitcoin is digital money that moves directly between two people over the internet, with no bank in the middle. Criminals ask for it in ransom notes for three reasons. There is no bank that can freeze or reverse a payment. It can be sent from anywhere in minutes. And a bitcoin address, the equivalent of an account number, carries no name.
That last point is where many of them go wrong. Every bitcoin payment ever made is written on a public ledger called the blockchain, which anyone can read, permanently. A ransom paid to an address can be followed from wallet to wallet for years. Turning bitcoin back into dollars usually means using an exchange, a broker for digital coins, and the big ones check passports and report to police. Bitcoin hides a name. It does not hide a trail.
In Rhyne's case the money trail was never tested. Nothing in the court record says the company paid, and the arrest press release called it an attempted extortion. What caught him was not the blockchain. It was the ordinary records any large office keeps.
The searches that gave him away
The FBI's case, sworn by Special Agent Timothy Lee on 8 August 2024, is a list of things Rhyne did not think anyone would check.
The hidden machine had been set up from the user account and laptop the company had issued to Rhyne. Whenever someone browsed the internet on the hidden machine, browsing on his laptop stopped, which suggested one person switching between the two.
On 22 November, the day before Thanksgiving, the hidden machine's user searched the web for "how to delete a dmoain [sic] account from the command line", "how to remotely shutdown a computer using cmd" and "how to clear all windows logs from command line". Clearing logs means wiping the records a computer keeps of what was done on it. A week earlier, his own laptop, logged in as him, had searched for "command line to remotely change local administrator password".
Security cameras and swipe-card records put him in the building minutes before his laptop logged on. On 14 November he walked in at 7:05 a.m., his laptop logged in at 7:07 and reached the hidden machine at 7:55. On days he was not in the office, his laptop connected from an internet address assigned to his home in Warren County. On Thanksgiving morning, at 6:57 a.m., it reached the hidden machine from his house. On 25 November it did the same at 7:10 a.m., 38 minutes before the session that set the timers.
The last link was the password. "TheFr0zenCrew!" was the password on the hidden machine, the password set on the hijacked accounts, and the password on the email account that sent the ransom note. One password, used three times, tied the machine, the attack and the demand together.
Arrest, plea and sentence
Rhyne was charged by complaint with extortion involving a threat to damage a protected computer, intentional damage to a protected computer and wire fraud. He was arrested in Missouri on 27 August 2024, appeared in federal court in Kansas City and was released.
On 1 April 2026 he pleaded guilty before Judge Shipp to a two-count charge: extortion in relation to a threat to damage a protected computer, which carries up to five years, and intentional damage to a protected computer, which carries up to 10. The wire fraud count, which carried up to 20 years, was not part of the plea. His 32-month sentence is a little over half the five-year maximum on the extortion count alone. The Justice Department's announcement did not state any period of supervised release, fine or restitution.

The aftermath
The company's network survived. Nothing in the public record shows that any bitcoin was paid, and the Justice Department described the scheme from the start as attempted extortion. The case was investigated by the FBI's Newark Field Office, with help from the FBI in Kansas City, and prosecuted by Assistant US Attorney Robert Taj Moore of the Cybercrime Unit in Newark. Rhyne was represented by Jonathan F. Marshall.
When Rhyne was charged in August 2024 he faced three counts with combined maximums of 35 years. He pleaded to two of them, with a combined maximum of 15 years, and received 32 months. The public announcements did not say whether he must also repay the company for the cost of the clean-up; any restitution order would appear in the judgment filed with the court.
The case lands in a run of insider prosecutions. In March 2026 a North Carolina data analyst contractor, Cameron Curry, was sentenced to two years for trying to extort $2.5 million from Brightly Software. In both cases the attacker already had the access that outside criminals spend months trying to steal. The FBI's Internet Crime Complaint Center counted 89,129 extortion complaints in 2025, with reported losses above $122 million.
What this teaches
- The most dangerous attacker is the one who already holds the keys. Rhyne needed no break-in; he used his own access and standard Windows tools.
- Administrator passwords kept in a shared spreadsheet are one bad employee away from a lockout.
- Bitcoin hides a name, not a trail. Every payment sits on a public ledger forever, and cashing out usually runs through exchanges that check identity.
- Ordinary office records, swipe cards, cameras, home internet addresses and search history, convicted Rhyne before any bitcoin moved.
- Reusing one password across a hidden machine, hijacked accounts and a ransom email account turned three separate clues into one signature.
COMMENTS