A Company’s VM Expert Hid One Too Many Virtual Machines
On September 28, 2026, a federal judge in Trenton sentenced Daniel Rhyne to 32 months in prison for attacking and trying to extort his own employer, the industrial gases company Messer North America. The judgment ordered $302,450.13 in restitution, three years of supervised release, and a $200 special assessment. The fine was waived, which nearly qualifies as comic relief given the rest of the case.
Rhyne, 57 at the time of his arrest, was a core infrastructure engineer at Messer’s Somerset County headquarters, and his specialty was the company’s virtual machines. In November 2023 he built an unauthorized one on the production network, used it to lock thousands of his coworkers out of their systems, and demanded 20 bitcoin, then worth about $750,000, to stop. Then he got caught, partly because he typed one password, “TheFr0zenCrew!”, into every single component of the crime.
The attack, hour by hour
The criminal complaint, sworn by FBI Special Agent Timothy Lee on August 8, 2024, reconstructs the whole operation, and it starts with a spreadsheet.
At 7:38 a.m. on November 9, 2023, someone on Rhyne’s assigned laptop opened a company file containing passwords, including credentials for a legitimate domain administrator account. Rhyne had badged into the building at 6:55 that morning, three minutes before his user account logged in. That same day he created the hidden virtual machine, password-protected with “TheFr0zenCrew!”.
On November 22, while staging the attack, the company’s own VM expert searched the web for “how to delete a dmoain account from the command line.”
Over the next two weeks, he assembled his toolkit. Sysinternals utilities appeared on the domain controller on November 15, including PsPasswd, the tool later used to rotate administrator passwords at scale. His research ran on two tracks, first from the company laptop, then from the hidden virtual machine. On November 15, he searched for “command line to change local administrator password” and “net user” from the laptop. A week later, the rogue VM ran the more advanced searches on November 22: “how to clear all windows logs from command line,” “how to remotely shutdown a computer using cmd,” and the “dmoain” query above.
(The typo is Rhyne’s, preserved faithfully in the filing.)
Thanksgiving week, while his coworkers presumably ate turkey, Rhyne connected in from his home IP at 6:48 a.m. on Thursday, November 23, and again at 7:04 a.m. on Saturday, November 25. Saturday morning is when the payload got built. Between 7:48 and 9:45 a.m., a remote desktop session ran from the hidden virtual machine to the domain controller using the stolen admin credentials, and during that window the account created 16 scheduled tasks. 6 of them were timed to fire simultaneously at 4:00 p.m.
What went off at 4:00 p.m.
They fired on schedule. Domain administrators began receiving password reset notifications, then discovered that every domain administrator account but one had been deleted. The cumulative damage, from the complaint:
| Action | Scope |
|---|---|
| Domain administrator accounts deleted | 13 |
| Domain user passwords reset to “TheFr0zenCrew!” | 301 |
| Servers locked via changed local admin passwords | 254 |
| Workstations locked via changed local admin passwords | 3,284 |
Still more tasks queued the shutdown of dozens of servers beginning December 3, an escalating hostage mechanism baked into the task scheduler itself. Forty-four minutes after the first password reset notifications landed, at 4:44 p.m., employees received an email from an outside address with the subject line “Your Network Has Been Penetrated.” The message put the demand in euros, €700,000, payable as 20 bitcoin (about $750,000 at the time), to be delivered by December 2, or 40 random servers would be shut down every day for ten days. It also claimed all server backups had been deleted. That last assertion is the attacker talking; the charging documents describe password changes and scheduled shutdowns, not backup destruction, so treat the backup claim as a threat rather than established fact.
How the whole thing unraveled
The investigation required no challenging forensics. Messer’s own logs did most of the work.
Every time the hidden virtual machine was active, internet browsing on Rhyne’s laptop stopped, two machines taking turns and never overlapping once. The rogue VM was accessed exclusively through the user account and laptop the company assigned to Rhyne. Badge records put him in the building minutes before logins that preceded hidden VM sessions on November 9, 14, and 21, the days he staged his earlier access. When he wasn’t in the building, connections came from the IP registered to his Warren County home. And the extortion email account, the hidden VM, and all 301 compromised accounts shared one password.
The FBI’s Newark and Kansas City field offices took it from there. Rhyne was arrested in Missouri on August 27, 2024, and appeared first in Kansas City federal court, then in New Jersey, where Magistrate Judge Leda D. Wettre set a $100,000 unsecured bond. The initial complaint and arrest warrant charged three counts, including wire fraud. By the time the Information was filed on April 1, 2026, wire fraud had fallen away and Rhyne pleaded guilty to two Computer Fraud and Abuse Act (CFAA) counts, extortion in relation to a threat to damage a protected computer and intentional damage to a protected computer. DOJ’s announcement confirmed the 32-month term before Judge Michael A. Shipp, and the docket shows the roughly 19-month gap between arrest and plea consumed by continuance orders that offer no reason for the delay.
The lesson, minus the usual lecture
Plenty of the media commentary treated this as a story about offboarding, the familiar warning that companies need better processes for revoking access when disgruntled employees depart. That reading fails on the facts. Rhyne was a current employee, using hardware the company assigned him, badging into the building the mornings he staged the attack, and consulting the company’s own password spreadsheet. No leaver process was ever going to save Messer, because nobody was leaving. The person with the deepest knowledge of the virtualization stack, holding legitimate credentials and badge access, decided to wreck the network for $750,000 that never arrived.
What actually worked was dull telemetry. Correlated authentication logs and badge records closed the loop between a login and a human being. Camera timestamps and IP registration data filled whatever gaps remained. Trustwave’s 2024 Financial Services Insider Threat Report puts the average cost of an insider breach at $5 million, a financial-sector benchmark that tends to run pricier than other industries. The restitution figure of $302,450.13, plus rapid identification of the culprit, counts as a bargain by comparison, and it was made possible by infrastructure most organizations already own but few watch.
The prevention side is uglier. The domain administrator password lived in a spreadsheet that a workstation user could open on a Tuesday morning. Rhyne exploited no zero-day, just an unprotected password file and 16 days of nobody noticing a rogue virtual machine running on the production network. The log-clearing tutorials he pulled up from a company laptop drew no attention either.
Instead of walking away with the money, he misspelled “domain” into a search engine while planning the extortion and did his research on hardware traceable to his name, his desk, and eventually his front door. The scheduled shutdowns meant to start December 3 never ran. He’ll have 32 months to think about that spreadsheet, and about the 16 days in November when everything seemed to be going according to plan.