A former infrastructure engineer has been sentenced to 32 months in prison after using privileged access to lock thousands of devices on his employer’s network and demand a bitcoin ransom, according to BleepingComputer.
Daniel Rhyne, 57, pleaded guilty to his role in the extortion scheme targeting the New Jersey-headquartered industrial company where he worked. Between Nov. 8 and Nov. 25, 2023, Rhyne used an administrator account to remotely access the company’s network and create scheduled tasks on its domain controller.
The attack targeted the identity infrastructure administrators relied on to regain control. Rhyne changed the main administrator password, deleted 13 domain administrator accounts and reset passwords for 301 domain users. Other scheduled tasks changed local administrator passwords, blocking access to 254 servers and another 3,284 workstations. He also caused random servers and workstations to shut down.
On Nov. 25, Rhyne sent employees an email demanding 20 bitcoin, worth about $750,000 at the time. He claimed the company’s server backups had been deleted and threatened to shut down 40 servers each day if the company did not pay. Investigators later found searches on Rhyne’s devices for instructions on remotely changing administrator passwords, deleting domain accounts, clearing Windows logs and shutting down computers.
For MSSPs, the case is a reminder that trusted credentials can be as dangerous as an external compromise when privileged access lacks sufficient controls. Providers can help customers reduce insider risk by limiting persistent administrative privileges, separating privileged accounts, monitoring unusual administrative activity and protecting recovery mechanisms from the same credentials used in production. Alerts for mass password changes, deletion of administrator accounts and unusual domain-controller tasks can also give security teams an opportunity to intervene before an insider or attacker using a stolen admin account can turn legitimate access into a company-wide outage.
Source: BleepingComputer
