An Ohio IT contractor, Maxwell Schultz, pleaded guilty to sabotaging his former employer's network after being fired, causing over $862,000 in damages. Schultz gained unauthorized access by impersonating another contractor, reset approximately 2,500 passwords using a PowerShell script, and attempted to cover his tracks by deleting system logs. The attack resulted in widespread employee downtime and disrupted customer service, with Schultz facing up to ten years in prison and a $250,000 fine upon sentencing.
In a separate case, a technical manager at Dutch wind farm operator Nordex was sentenced to 120 hours of community service for secretly installing cryptocurrency mining rigs and Helium network nodes at two wind farm sites. The mining operation, discovered shortly after the company suffered a ransomware attack, exploited company resources and posed operational risks to the turbines. The employee was also ordered to pay restitution for the unauthorized use of company infrastructure. Both incidents highlight the ongoing threat posed by malicious insiders abusing privileged access for personal gain or retaliation.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
A court sentenced the wind farm worker for secretly converting turbine-related systems into a cryptocurrency mining operation. The sentencing marked the public legal resolution of the case.
The ex-contractor pleaded guilty or otherwise admitted sabotaging the former employer's environment, confirming responsibility for the attack and the reported financial damage. This development was reported by multiple outlets and represents the key legal milestone in the case.
A fired technology worker carried out sabotage against a former employer, causing about $862,000 in damage. The incident was later described in multiple reports as a criminal case involving an admission of guilt.
A worker at a wind farm turned wind turbines into a covert cryptocurrency mining operation, misusing employer-owned systems and infrastructure. The activity became the basis for a later criminal case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcego.theregister.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.