Daniel Rhyne, 59, pleaded guilty in Trenton federal court to attempting to extort his former employer through a fraudulent ransomware attack. Rhyne, a former infrastructure engineer for an unnamed industrial firm, admitted to one count of extortion and one count of intentional damage to a protected computer.
Rhyne gained access to the company’s network in 2023 through unauthorized remote desktop sessions and then set up automated tasks meant to cripple its infrastructure. According to the allegations, he deleted network administrator accounts to steal or remove credentials, changed passwords for critical service accounts to lock out legitimate users, and executed commands that shut down multiple internal servers.
Who Me?
He also allegedly tried to make the incident look like an outside attack, then demanded a $750,000 Bitcoin ransom in exchange for restoring access and preventing the release of company data.
“Specifically, and among other things, Rhyne initiated unauthorized remote desktop sessions and prepared for the attack by scheduling tasks that would trigger damage to Victim-1’s network,” the DOJ said in announcing the guilty plea.
Forrester’s 2025 Security Survey, cited at an RSAC 2026 session “Disgruntled Employees to Deepfaked Identities: Navigating Insider Response” found that 22% of breaches involved internal incidents. Among organizations that experienced an internal incident, 47% said it involved malicious intent.
Session host, Joseph Blankenship, VP, research director at Forrester, said to mitigate these type incidents businesses need to get the basics right. Tighten hiring and onboarding for remote workers, scrutinize resumes and references, do direct phone or video checks, restrict access to vetted remote-access tools, and use behavioral analytics to spot anomalies early, he said.
“Insider threats are one of the biggest reasons we implement something like zero trust, right?” Blankenship said. “Because you look at the controls in zero trust, basically what we’re saying is we only want people to have access to the things that they need to have access to… The other thing we want to do is be able to automatically change the way that we’re privileging folks based on their risk level.”
Legal Consequences
Federal agents arrested Rhyne before the company transferred any funds. U.S. District Judge Michael A. Shipp presided over the plea. Rhyne faces a maximum statutory penalty of 15 years in prison: five years for extortion and 10 years for damaging a protected computer.
The Department of Justice noted that Rhyne’s preparation involved specific technical maneuvers to ensure the company could not bypass his lockout. This case follows a pattern of “insider threats” where privileged users exploit administrative credentials to bypass perimeter security.Each violation also carries a maximum fine of $250,000.

Shaun Nichols is an IT news journalist. He has spent nearly 20 years covering the industry with a specialty in the cybersecurity
Image by kirill_makes_pics from Pixabay