Network Security, Identity, Privileged access management

Former engineer pleads guilty to server extortion plot

A former core infrastructure engineer has pleaded guilty to locking Windows administrators out of 254 servers as part of an extortion plot against his former employer, an industrial company based in Somerset County, New Jersey. The engineer, Daniel Rhyne, used administrator credentials to access the company's network and schedule tasks to delete admin accounts and change passwords. He also planned to shut down servers and workstations, according to a recent report by Bleeping Computer.

Rhyne, 57, remotely accessed the company's network between November 9 and November 25, using an administrator account. He scheduled tasks on the Windows domain controller to delete network admin accounts and change passwords for 13 domain admin accounts and 301 domain user accounts to "TheFr0zenCrew!". He also targeted local administrator accounts, affecting 3,284 workstations and 254 servers.

Rhyne sent ransom emails to coworkers on November 25, claiming all IT administrators were locked out and backups were deleted, demanding 20 bitcoin (approximately $750,000 at the time) to prevent daily server shutdowns.

Source: Bleeping Computer

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds