logo

Man admits to locking thousands of Windows devices in extortion plot

ID: 6d5429db-4f51-593a-b345-8406079610bb

STIX ID: report--6d5429db-4f51-593a-b345-8406079610bb

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-03

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A former core infrastructure engineer, Daniel Rhyne, pleaded guilty after using an administrator account to remotely change passwords for hundreds of domain and local accounts, delete domain admin accounts, schedule shutdowns of servers and workstations, and send a ransom demand of 20 BTC to his employer; the activity (Nov–Dec 2023) impacted 254 servers and thousands of workstations, forensic analysis found searches about clearing Windows logs and changing admin passwords, and prosecutors filed hacking and extortion charges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.