Industrial Engineer Jailed for 20-Bitcoin Extortion
Former core infrastructure engineer deleted admin accounts, reset hundreds of passwords at an industrial firm, demanded 20 bitcoin for recovery. Now in prison.

The access was legitimate. That’s the specific fact that distinguishes insider extortion from a ransomware attack.
SecurityWeek reports a former core infrastructure engineer at an industrial firm deleted administrative accounts and reset hundreds of passwords before demanding 20 bitcoin to restore access. The engineer is now in prison.
What the attacker did
A core infrastructure role carries broad credential authority by design. According to SecurityWeek’s account, the engineer used that authority to delete admin accounts and reset passwords at scale, severing the company from its own systems. The demand: 20 bitcoin to reverse the damage.
Why industrial firms are a specific target
Industrial environments often run on credentials provisioned years ago and tested infrequently. A core infrastructure engineer knows which accounts matter, which resets cause the most disruption, and how long manual recovery takes without the original configuration knowledge. That institutional knowledge is the leverage.
Analysis: this pattern differs from standard ransomware in recovery complexity. Ransomware can sometimes be remediated without paying if backups are intact. Insider credential destruction targets the accounts and reset tokens that govern access to those same backups.
This case comes close behind an NJ engineer who received 32 months for locking 3,000 corporate devices. Both cases ended in prison time. Earlier this week, the MonsterCloud CEO faced charges for secretly negotiating ransoms while billing victims. The commonality across these cases: access, or proximity to access, monetized through threat.
For ICS context, a September incident showed ransomware reaching South Africa’s air traffic control operational network, a separate threat path with similar disruption potential.
The control gap
Most offboarding procedures include a step to revoke access. The gap that enables cases like this one sits between when access is scheduled for revocation and when it’s verified as revoked. For privileged accounts with authority over credential stores, that window needs to close in minutes.
One specific check: after an infrastructure engineer’s employment ends, confirm that admin account deletions and password resets require multi-party authorization from that point forward, not a single privileged session.
Found this useful? Share it.


