NJ Engineer Gets 32 Months for Locking 3,000 Devices
A former core infrastructure engineer in New Jersey was sentenced to 32 months in federal prison for locking more than 3,000 employer devices in a ransomware-style insider attack.

A former core infrastructure engineer at a New Jersey industrial company was sentenced to 32 months in federal prison this week for locking more than 3,000 devices on his employer’s network, according to BleepingComputer. Prosecutors described the attack as ransomware-like in its effect.
The sentence sits in familiar territory. An engineer with privileged access to critical systems decides to use it against the organization, either on the way out or shortly after. The method changes. The access problem does not.
What happened
The engineer held a core infrastructure role, the kind that carries broad access to network devices and systems by necessity. After his employment ended, he retained or used that access to lock more than 3,000 devices across the company’s network. The disruption in an industrial environment is not a minor event; operational technology and infrastructure systems are not like a deactivated SaaS account.
The “ransomware-like” framing from prosecutors is worth noting. No ransomware group was involved. No encryption payload was deployed for extortion. A former employee did it directly, using credentials and knowledge from his tenure. The outcome looks similar from the victim organization’s perspective: systems down, operations disrupted, and an incident response effort they did not plan for.
The access problem is structural
The standard critique follows a predictable path: revoke credentials on separation, audit privileged accounts, monitor for anomalous activity in the days around a departure. These are not wrong, and they are also not news. The more uncomfortable observation is that organizations continue to get this wrong at scale.
Privileged access accumulates in environments that were never designed to be audited. Legacy systems, shared service accounts, credentials embedded in scripts, and access granted for a project that was never revoked after the project ended: any of these can survive a departure review that checks the obvious boxes. In industrial environments, the sprawl is often worse, because the systems involved predate modern identity management tooling and were not built with rapid credential rotation in mind.
The 32-month sentence is a serious federal consequence. Courts have moved toward treating deliberate infrastructure sabotage as more than a civil employment dispute, and the consistency of outcomes in cases like this one matters as a signal. For reference on the recent arc: the Ryuk ransomware operator sentenced last month drew two years; a Conti developer convicted in September 2026 drew four. Insider cases like this one tend to land in the 2-3 year range when the disruption is substantial and the intent is clear.
What organizations should do
Separation procedures need a privileged-access checklist that goes beyond disabling the standard Active Directory account. Shared service accounts, VPN credentials, device management access, vendor portal logins, and remote access tools all need to be reviewed. The review should happen on the day of separation, not in the weeks after.
Beyond the immediate departure case, periodic access reviews against a current employee roster catch the accumulation problem. The CISA insider threat mitigation guidance covers the organizational and technical controls in more depth than most internal policy documents do.
The insider threat framing matters here too. Anomalous access from accounts belonging to recently separated employees is a detection opportunity, not just a policy gap. Monitoring for activity from accounts flagged for departure is a low-cost, high-signal control.
Attacks on critical infrastructure by external groups have drawn significant coverage this year, including the Warlock ransomware campaign against SharePoint environments and ongoing targeting of OT systems. The less dramatic version of the same outcome, one disgruntled employee with the right credentials, is harder to attribute and easier to prevent if the access controls are maintained.
Found this useful? Share it.


