{"id":421,"date":"2026-10-07T00:14:39","date_gmt":"2026-10-07T00:14:39","guid":{"rendered":"https:\/\/managedt.com\/blog\/engineer-sentenced-locking-workstations-ransomware-style-attack-employer\/"},"modified":"2026-10-07T00:14:40","modified_gmt":"2026-10-07T00:14:40","slug":"engineer-sentenced-locking-workstations-ransomware-style-attack-employer","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/engineer-sentenced-locking-workstations-ransomware-style-attack-employer\/","title":{"rendered":"Former engineer sentenced to 32 months for locking 3,284 workstations in ransomware-style attack on employer"},"content":{"rendered":"<p>A former core infrastructure engineer was sentenced to 32 months in federal prison for breaking into his employer&#8217;s network, changing the passwords of thousands of accounts, shutting down servers, and demanding roughly $750,000 in bitcoin to stop further damage. The case shows how a single trusted administrator account, used against the company that issued it, can take thousands of devices offline in a matter of days.<\/p>\n<h2>What the engineer did, and when<\/h2>\n<p>Court documents describe an attack carried out between November 8 and November 25, 2023, using an administrator account that was not authorized for the activity. The engineer scheduled tasks on the domain controller that changed the password of the administrator account to a string naming a hacker crew, deleted 13 domain admin accounts, and reset the passwords for 301 domain user accounts to the same string. Two more local admin accounts were reset to a separate string, which blocked access to 254 servers. Two further admin accounts were reset, blocking access to 3,284 workstations. Over several days in December 2023, random servers and workstations on the network were shut down.<\/p>\n<h2>The ransom demand<\/h2>\n<p>On November 25, the engineer sent coworkers a ransom email titled &#8220;Your Network Has Been Penetrated.&#8221; The message claimed that server backups had been deleted so that data recovery was impossible and threatened to shut down 40 random servers a day for the next 10 days unless the company paid a 20 bitcoin ransom. At the time, 20 bitcoin was worth roughly $750,000.<\/p>\n<h2>How the intrusion unfolded on the network<\/h2>\n<p>Network administrators at the company, identified in the criminal complaint as Victim-1 and headquartered in New Jersey, began receiving password reset notifications for a domain administrator account and hundreds of user accounts at approximately 4:00 p.m. EST on November 25. They soon discovered that every other domain administrator account had been deleted, cutting off administrative access to the computer networks.<\/p>\n<p>Investigators later found that on November 22, while the scheme was being prepared, the engineer used an account on a hidden virtual machine to search the web for instructions on changing domain user passwords, deleting domain accounts, and clearing Windows logs. A week earlier, searches on a personal laptop included &#8220;command line to change local administrator password,&#8221; &#8220;command line to remotely change local administrator password,&#8221; and &#8220;how to remotely shutdown a computer using cmd.&#8221;<\/p>\n<h2>Arrest, plea, and sentence<\/h2>\n<p>The engineer, 57, from Kansas City, Missouri, was arrested in August 2024 and released after an initial appearance in federal court. He pleaded guilty for his role in what the court described as a failed extortion plot targeting the New Jersey company that employed him. On October 6, 2026, he was sentenced to 32 months in prison.<\/p>\n<h2>What the case shows about insider-driven ransomware-style attacks<\/h2>\n<p>The incident is a textbook example of a trusted insider turning the tools of system administration against the employer. Every step the engineer took, from changing the domain admin password and deleting the remaining admin accounts to resetting thousands of local user accounts and shutting down random servers, used built-in Windows and Active Directory capabilities. No malware had to be smuggled in for the core of the attack to work. The damage was contained only because the ransom demand surfaced the scheme to administrators who could begin manual recovery.<\/p>\n<p>Two details stand out for defenders. First, the planning was visible in plain web search history and a hidden virtual machine on the company network, both of which were recovered after the fact. Second, the pivot from &#8220;I control these accounts&#8221; to &#8220;I control every device that authenticates against them&#8221; happened in a single batch of scheduled tasks on the domain controller, which is the single most sensitive server in most Windows environments.<\/p>\n<h2>A second insider extortion case in 2026<\/h2>\n<p>Earlier in 2026, in March, a 27-year-old data analyst contractor from North Carolina was sentenced to two years in prison after being found guilty of extorting his employer, Brightly Software, a Software-as-a-Service company previously known as SchoolDude, for $2.5 million. Taken together, the two cases point to a pattern in which current and former staff, not external criminal crews, were the source of the most consequential ransomware-style demands against their own employers in the past year.<\/p>\n<h2>FAQ<\/h2>\n<h3>Who was sentenced for the November 2023 attack on a New Jersey employer?<\/h3>\n<p>A 57-year-old former core infrastructure engineer from Kansas City, Missouri, was sentenced to 32 months in federal prison on October 6, 2026, after pleading guilty to his role in a failed extortion plot against the New Jersey industrial company that employed him.<\/p>\n<h3>How did the engineer lock so many devices at once?<\/h3>\n<p>He used an administrator account to schedule tasks on the domain controller that reset the domain admin password, deleted 13 other domain admin accounts, reset passwords for 301 domain user accounts, reset local admin passwords to block access to 254 servers, and reset two more admin accounts that blocked access to 3,284 workstations.<\/p>\n<h3>What was the ransom demand in the case?<\/h3>\n<p>The ransom email, titled &#8220;Your Network Has Been Penetrated,&#8221; demanded 20 bitcoin, worth roughly $750,000 at the time, and threatened to shut down 40 random servers a day for 10 days if the company did not pay.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Who was sentenced for the November 2023 attack on a New Jersey employer?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A 57-year-old former core infrastructure engineer from Kansas City, Missouri, was sentenced to 32 months in federal prison on October 6, 2026, after pleading guilty to his role in a failed extortion plot against the New Jersey industrial company that employed him.\"}},{\"@type\":\"Question\",\"name\":\"How did the engineer lock so many devices at once?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"He used an administrator account to schedule tasks on the domain controller that reset the domain admin password, deleted 13 other domain admin accounts, reset passwords for 301 domain user accounts, reset local admin passwords to block access to 254 servers, and reset two more admin accounts that blocked access to 3,284 workstations.\"}},{\"@type\":\"Question\",\"name\":\"What was the ransom demand in the case?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The ransom email, titled \\\"Your Network Has Been Penetrated,\\\" demanded 20 bitcoin, worth roughly $750,000 at the time, and threatened to shut down 40 random servers a day for 10 days if the company did not pay.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/engineer-sentenced-for-locking-thousands-of-devices-on-employer-network\/\" target=\"_blank\" rel=\"nofollow noopener\">bleepingcomputer.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A former core infrastructure engineer was sentenced to 32 months in prison for using admin access to lock thousands of devices and demand a 20 bitcoin ransom<\/p>\n","protected":false},"author":3,"featured_media":420,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-421","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/421","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=421"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/421\/revisions"}],"predecessor-version":[{"id":422,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/421\/revisions\/422"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/420"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=421"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=421"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=421"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}