{
  "id": "case-daniel-rhyne-ransomware",
  "slug": "us-v-rhyne-insider-ransomware-extortion",
  "title": "U.S. v. Daniel Rhyne (Industrial Insider Extortion)",
  "summary": "Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.",
  "case_number": "3:24-cr-00122",
  "court": "U.S. District Court for the Western District of Missouri",
  "district": "W.D. Mo.",
  "country": "United States",
  "opened_at": "2024-04-16",
  "status": "charged",
  "victim_sector": "Industrial Manufacturing, Critical Infrastructure",
  "victim_country": "United States",
  "loss_amount_usd": 750000,
  "loss_amount_note": "Demanded $750,000 ransom and caused significant corporate operational stoppage.",
  "first_seen_at": "2023-11-20T00:00:00Z",
  "last_updated_at": "2026-07-01T15:00:00Z",
  "actor_slug": "insider-threat",
  "defendant_slugs": [
    "daniel-rhyne"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier.",
      "evidence_locator": "Criminal Complaint \u00b6 9, Page 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Complaint: U.S. v. Rhyne",
      "source_url": "https://www.justice.gov/usao-wdmo/pr/former-systems-administrator-charged-extortion-and-intentionally-damaging-protected",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2024-04-18",
      "description": "Rhyne arrested in Kansas City by FBI agents."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Industrial Manufacturing, Critical Infrastructure networks. Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.",
    "blast_radius": "Demanded $750,000 ransom and caused significant corporate operational stoppage. Impacted Industrial Manufacturing, Critical Infrastructure infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}