U.S. v. Daniel Rhyne (Industrial Insider Extortion)
Key Facts
- Legal Status: CHARGED in U.S. District Court for the Western District of Missouri.
- Primary Target Sector: Industrial Manufacturing, Critical Infrastructure.
- Documented Financial Loss: $750,000.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Industrial Manufacturing, Critical Infrastructure networks. Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.
Operational & Financial Fallout
Demanded $750,000 ransom and caused significant corporate operational stoppage. Impacted Industrial Manufacturing, Critical Infrastructure infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Industrial Manufacturing, Critical Infrastructure networks. Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.
Adversary Kill Chain Flow
1 Documented PhasesRhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier.
Demanded $750,000 ransom and caused significant corporate operational stoppage. Impacted Industrial Manufacturing, Critical Infrastructure infrastructure and associated victim operations.
Procedural & Incident Timeline
Rhyne arrested in Kansas City by FBI agents.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Daniel Rhyne | United States | charged | Pending | None | Former systems engineer charged with corporate extortion and intentional computer damage in W.D. Mo. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier." | Criminal Complaint ¶ 9, Page 4 | reviewed |