A 57-year-old man from the US state of Missouri was arrested in connection with a failed data extortion campaign targeting his former employer.
Daniel Rhine, of Kansas City, Missouri, was charged with one count of extortion for threatening to damage a protected computer, one count of willful damage to a protected computer and one count of wire fraud.
He was arrested in the state on August 27, 2024, after attempting to extort an unnamed industrial company headquartered in Somerset County, New Jersey, where he worked as a major infrastructure engineer.
According to court documents, some of the company’s employees received an extortion email warning that all of its IT administrators were locked out or removed from the network, data backups were deleted and an additional 40 servers would be down every day for the next 10 days if the ransom of 20 bitcoins, then valued at $750,000, was not paid.
“The investigation revealed that Ryne gained unauthorized access to the company’s computer systems by remotely accessing the company’s administrator account,” the US Department of Justice said in a statement. said.
“Rine then planned to perform several computer tasks on the network without permission, including changing the company’s administrator passwords and shutting down its servers. Ryne controlled the email address used to send the November 25 extortion email to company employees.”
Ryne allegedly used the Windows net user and Sysinternals Utilities’ PsPasswd tool to change domain and local administrator accounts and change passwords to “TheFr0zenCrew!”, prosecutors said in court documents.
Authorities said the defendant allegedly used a hidden virtual machine to remotely access an administrator account that was not only traced to his company-owned laptop, but also to search the Internet for details on how to use the command line to change the local administrator. password and clear Windows logs.
Raine, who made his first appearance on the same day of his arrest, faces a maximum penalty of 35 years in prison and a $750,000 fine on all three counts.