CASE DOSSIER
charged
U.S. v. Daniel Rhyne (Industrial Insider Extortion)
Docket: 3:24-cr-00122 Court: U.S. District Court for the Western District of Missouri Opened: 2024-04-16 Sector: Industrial Manufacturing, Critical Infrastructure
Key Facts
Status
CHARGED
Legal disposition
Loss Amount
$750,000
Demanded $750,000 ransom and caused significant corporate operational stoppage.
Techniques
1
Verified mappings
Defendants
1
Named in charges
- Legal Status: CHARGED in U.S. District Court for the Western District of Missouri.
- Primary Target Sector: Industrial Manufacturing, Critical Infrastructure.
- Documented Financial Loss: $750,000.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.
Procedural & Incident Timeline
2024-04-18 arrest
Rhyne arrested in Kansas City by FBI agents.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Daniel Rhyne | United States | charged | Pending | None | Former systems engineer charged with corporate extortion and intentional computer damage in W.D. Mo. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier." | Criminal Complaint ¶ 9, Page 4 | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Daniel Rhyne (Industrial Insider Extortion), No. 3:24-cr-00122 (U.S. District Court for the Western District of Missouri 2024), https://cyberattackcaselibrary.pages.dev/cases/us-v-rhyne-insider-ransomware-extortion/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-rhyne-insider-ransomware-extortion" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>