Former Engineer Sentenced to 32 Months for Ransomware-Style Attack on Employer
A former core infrastructure engineer for a New Jersey-based industrial company has been sentenced to 32 months in prison for locking out thousands of devices on his employer’s network in a ransomware-style attack.
Daniel Line, 57, of Kansas City, Missouri, was arrested in August 2024 and released after his first federal court appearance. He later pleaded guilty to his role in a failed extortion scheme targeting the New Jersey company that employed him.
Former engineer used administrator access to lock out devices
According to court documents, between November 8 and November 25, Line used an administrator account to gain unauthorized remote access to the company’s network.
He changed the password for the administrator account on a domain controller to “TheFr0zenCrew!”, deleted 13 domain administrator accounts, and scheduled a task to change the passwords for 301 domain user accounts to “TheFr0zenCrew!”.
Line also changed the passwords of two local administrator accounts to “PsPasswd,” blocking access to 254 servers. He changed the passwords of two additional administrator accounts, blocking access to another 3,284 workstations.
He also added a scheduled task to shut down random servers and workstations on the company’s network over several days in December 2023.
Ransom demand threatened daily shutdowns
On November 25, Line sent colleagues a ransom email titled “Your network has been compromised.” The message claimed that server backups had also been deleted, making data recovery impossible.
Line threatened to shut down 40 servers at random every day for the next 10 days unless the company paid a ransom of 20 Bitcoin, worth approximately $750,000 at the time.
“On November 25, 2023, at approximately 4:00 PM EST, network administrators employed by Victim-1 began receiving password reset notifications for Victim-1’s domain administrator account and hundreds of Victim-1 user accounts,” the criminal complaint states.
“Shortly thereafter, Victim-1’s network administrator discovered that all other Victim-1 domain administrator accounts had been deleted, thereby denying the domain administrator access to Victim-1’s computer network.”
Investigators found searches about password changes and Windows logs
Investigators discovered that while planning the extortion scheme on November 22, Line used his account on a hidden virtual machine to search the web for information about changing domain user passwords, deleting domain accounts, and clearing Windows logs.
A week earlier, he had also searched on his laptop for “command line to change local administrator password,” “command line to change local administrator password remotely,” and “how to remotely shut down a computer using cmd.”
Another employee sentenced for cyber extortion
Earlier this year, in March, Cameron Curry, a 27-year-old contract data analyst from North Carolina, was also sentenced to two years in prison after being convicted of extorting $2.5 million from his employer, Brightly Software, a software-as-a-service company formerly known as SchoolDude.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



