{
  "id": "case-daniel-rhyne-ransomware",
  "slug": "us-v-rhyne-insider-ransomware-extortion",
  "title": "U.S. v. Daniel Rhyne (Industrial Insider Extortion)",
  "summary": "Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.",
  "case_number": "3:24-cr-00122",
  "court": "U.S. District Court for the Western District of Missouri",
  "district": "W.D. Mo.",
  "country": "United States",
  "opened_at": "2024-04-16",
  "status": "charged",
  "victim_sector": "Industrial Manufacturing, Critical Infrastructure",
  "victim_country": "United States",
  "loss_amount_usd": 750000,
  "loss_amount_note": "Demanded $750,000 ransom and caused significant corporate operational stoppage.",
  "first_seen_at": "2023-11-20T00:00:00Z",
  "last_updated_at": "2026-07-01T15:00:00Z",
  "actor_slug": "insider-threat",
  "defendant_slugs": [
    "daniel-rhyne"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier.",
      "evidence_locator": "Criminal Complaint \u00b6 9, Page 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Complaint: U.S. v. Rhyne",
      "source_url": "https://www.justice.gov/usao-wdmo/pr/former-systems-administrator-charged-extortion-and-intentionally-damaging-protected",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2024-04-18",
      "description": "Rhyne arrested in Kansas City by FBI agents."
    }
  ]
}