CASE DOSSIER charged

U.S. v. Daniel Rhyne (Industrial Insider Extortion)

Docket: 3:24-cr-00122 Court: U.S. District Court for the Western District of Missouri Opened: 2024-04-16 Sector: Industrial Manufacturing, Critical Infrastructure

Key Facts

Status
CHARGED
Legal disposition
Loss Amount
$750,000
Demanded $750,000 ransom and caused significant corporate operational stoppage.
Techniques
1
Verified mappings
Defendants
1
Named in charges
  • Legal Status: CHARGED in U.S. District Court for the Western District of Missouri.
  • Primary Target Sector: Industrial Manufacturing, Critical Infrastructure.
  • Documented Financial Loss: $750,000.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Industrial Manufacturing, Critical Infrastructure networks. Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.

Operational & Financial Fallout

Demanded $750,000 ransom and caused significant corporate operational stoppage. Impacted Industrial Manufacturing, Critical Infrastructure infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: CHARGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Industrial Manufacturing, Critical Infrastructure networks. Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier.

Artifacts & Tooling: T1078 Valid Accounts
Real-World Blast Radius & Operational Fallout

Demanded $750,000 ransom and caused significant corporate operational stoppage. Impacted Industrial Manufacturing, Critical Infrastructure infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2024-04-18 arrest

Rhyne arrested in Kansas City by FBI agents.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Daniel Rhyne United States charged Pending None Former systems engineer charged with corporate extortion and intentional computer damage in W.D. Mo.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier." Criminal Complaint ¶ 9, Page 4 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Daniel Rhyne (Industrial Insider Extortion), No. 3:24-cr-00122 (U.S. District Court for the Western District of Missouri 2024), https://cybercaselibrary.com/cases/us-v-rhyne-insider-ransomware-extortion/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-rhyne-insider-ransomware-extortion" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>