A former infrastructure engineer received a 32-month federal sentence after using Bitcoin to extort his own employer.

Background of the attack

In late November 2023, employees at a New Jersey-based industrial firm received an email warning that the company’s network had been breached. The message claimed that IT administrators were locked out, backups erased, and that 40 additional servers would be taken offline each day for ten days unless a ransom of 20 BTC – valued at about $750,000 at the time – was paid by early December.

Technical execution

Prosecutors say the engineer, who served as the company’s core infrastructure specialist, created an unauthorized virtual machine on the corporate network on November 9, 2023. The VM was secured with the password “TheFr0zenCrew!”. From this hidden system, a remote desktop session launched scheduled tasks that deleted dozens of administrator accounts, altered passwords on hundreds of servers, and prepared shutdown commands for a large number of workstations. Log analysis tied the VM to the engineer’s company laptop, which connected from a home IP address minutes before the malicious tasks were scheduled.

Legal outcome

The engineer pleaded guilty in April to extortion and intentional damage to a protected computer. On September 28, a federal judge imposed a 32-month prison term, noting the severity of the cyber-attack and the use of cryptocurrency to facilitate the ransom demand. The case also included a wire-fraud charge, although the plea focused on the two primary counts.

Why it matters

The conviction underscores how cryptocurrency can be employed in workplace-related cyber-crimes and highlights law-enforcement capabilities to trace digital footprints back to individual actors. It serves as a cautionary example for organizations to monitor privileged access and for employees to understand the legal ramifications of misusing technical expertise for personal gain.