Ransomware & Extortion · Insider Threat

Engineer used domain controller to lock out employer

Daniel Rhyne, a former core infrastructure engineer at a New Jersey industrial firm, was sentenced to 32 months in prison after a November 2023 sabotage that deleted 13 domain administrator accounts and reset hundreds of passwords. The Justice Department said he later pleaded guilty to extortion and intentional damage to a protected computer.

According to the reporting, Rhyne placed scheduled tasks on the company’s domain controller so the system itself carried out the credential changes later. That let him use normal admin functions to delete accounts and mass-reset passwords across servers and workstations, which denied the firm access to its own systems and data without needing a malware payload.

The case is a reminder that centralized identity systems can become the attack path and the blast radius at the same time. For organizations that run authentication and administration through a domain controller, privileged insider abuse can translate into enterprise-wide lockout, and the cleanup problem is rebuilding trust in accounts and password state as much as restoring machines.

1 source · 6h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-10

Every edition of this story: Engineer used domain controller to lock out employer

More from today