Within Rome Laboratory

How One Lab Breach Reached Defence Contractors

Captured contractor logins let intruders pose as authorised users and compromise machines in California and Texas without a fresh external breach.

26 sources 3 graphics
Preview for How One Lab Breach Reached Defence Contractors

On this page

  • How contractor credentials were captured
  • Why trusted remote access became a weakness
  • What the California and Texas compromises showed

Introduction

The Rome Laboratory intrusion is often described as a successful attack on a US Air Force research facility, but one of its most important consequences lay beyond the laboratory itself. Once the attackers had installed password-capturing software inside Rome Laboratory’s network, they did not need to breach every connected organisation independently. Instead, they harvested legitimate credentials belonging to researchers and defence contractors, then used those credentials to log into external systems as authorised users. This transformed a single compromise into a wider chain of trusted access across organisations with differing security standards.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Contractor Pivot illustration 1

This credential-based expansion is particularly significant in the wider history of cases involving hackers associated with UFO-related interests, such as Gary McKinnon. Although the Rome Laboratory incident involved different individuals and circumstances, it demonstrated how interconnected defence research networks could be exploited through trusted relationships rather than repeated technical break-ins. The contractor compromise became one of the clearest early examples of what is now known as a “pivot” attack, where one organisation’s breach becomes another organisation’s security problem.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

How contractor credentials were captured

The attackers’ greatest advantage did not come from discovering additional software vulnerabilities. It came from installing network sniffers inside Rome Laboratory after gaining an initial foothold. These programs silently monitored network traffic, recording usernames, passwords and connection details transmitted by legitimate users as they carried out their normal work. Because many remote logins in 1994 still relied on protocols that sent credentials without modern encryption, anyone controlling a compromised internal machine could collect passwords without alerting the user.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Among those affected were aerospace contractors who routinely connected from Rome Laboratory back to computers at their own organisations. Senate investigators later explained the sequence in unusual detail:

  • contractors authenticated to Rome Laboratory;
  • while working there, they logged into their home systems;
  • the sniffer recorded both the destination system and the contractor’s username and password;
  • the attackers then reused those credentials to impersonate the contractor directly on the external network.

The crucial point is that no fresh exploit against the contractor was necessarily required. Once the credentials had been stolen, the attackers appeared to be legitimate authorised users.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

This represented a shift in the nature of computer intrusion. Rather than repeatedly defeating technical security controls, the attackers increasingly relied on stolen identity. The password itself became the means of entry.

Why trusted remote access became a weakness

Rome Laboratory collaborated extensively with universities, government laboratories and commercial aerospace companies. Researchers and contractors frequently moved between organisational networks as part of ordinary engineering and research work. Those trusted connections were designed to improve collaboration, not to resist an attacker who had already established a presence inside one participant’s network.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…

Several characteristics of mid-1990s networking amplified this problem:

  • Remote logins commonly depended only on usernames and passwords.
  • Multi-factor authentication was generally unavailable.
  • Internal networks were often treated as trusted environments once a user had authenticated.
  • Organisations assumed that authorised users arriving from established partners posed relatively little risk.

These assumptions meant that possession of valid credentials frequently mattered more than the route by which they had been obtained. A contractor’s successful login therefore bypassed many of the suspicions that an unknown external attacker might otherwise have triggered.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

The incident exposed an important organisational weakness rather than merely a software flaw. Defence research increasingly depended on interconnected institutions, yet each participant’s security posture affected every other participant. An attacker only needed to compromise one trusted environment before exploiting relationships that had been built for legitimate collaboration.

Contractor Pivot illustration 2

What the California and Texas compromises showed

One of the clearest documented examples involved an unnamed aerospace contractor whose remote access credentials were captured at Rome Laboratory.

According to the Senate Permanent Subcommittee on Investigations, investigators observed the attackers using the stolen contractor credentials to access the contractor’s own systems. Four contractor computers located in California and another in Texas were successfully compromised after the attackers masqueraded as legitimate users. The report specifically notes that these systems were reached through credentials harvested at Rome Laboratory rather than through a new external penetration of each machine.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Investigators also reported that the attackers performed Internet scanning against the contractor’s wider infrastructure. Scanning software collected information about operating systems and available network services, helping identify additional targets or weaknesses after the initial authenticated access had been achieved. This illustrates that stolen credentials and technical reconnaissance worked together rather than serving as separate attack methods.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Although public reports do not identify the contractor by name, the documented sequence demonstrates three important points:

  • authentication credentials could travel farther than the original compromise;
  • trust relationships allowed attackers to move between organisations while appearing legitimate; and
  • a breach affecting one research laboratory could rapidly become a problem for geographically distant contractor facilities.

The California and Texas incidents therefore became practical evidence that defence supply chains were increasingly exposed through shared identities as much as through direct network attacks.

The broader security lesson

Subsequent government testimony repeatedly cited the Rome Laboratory incident as evidence that interconnected defence systems required stronger information security programmes rather than isolated technical fixes. The case illustrated that attackers could steal research, disrupt operations and launch attacks against other organisations from a compromised defence network. It also showed why password-only authentication and extensive implicit trust between collaborating organisations created systemic risk.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

Modern concepts such as credential theft, lateral movement, identity-based attacks and zero-trust security architectures had not yet become standard terminology in 1994, but the Rome Laboratory incident demonstrated the underlying problems with remarkable clarity. The compromise of contractor credentials showed that protecting an organisation’s perimeter alone was insufficient when authorised identities could be silently stolen and reused across a network of trusted partners.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Contractor Pivot illustration 3

Amazon book picks

Further Reading

Books and field guides related to How One Lab Breach Reached Defence Contractors. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromUFO disclosure poster oneBay.co.uk.

Endnotes

1. Source: armed-services.senate.gov
Link:https://www.armed-services.senate.gov/hearings/17-05-03-department-of-defense-laboratories-and-their-contributions-to-military-operations-and-readiness

Source snippet

U.S. Senate Committee on Armed ServicesMay 3, 2017 — DEPARTMENT OF DEFENSE LABORATORIES AND THEIR CONTRIBUTIONS TO MILITARY OPERATIONS...

Published: May 3, 2017

2. Source: armed-services.senate.gov
Title: sasc investigation finds chinese intrusions into key defense contractors
Link:https://www.armed-services.senate.gov/press-releases/sasc-investigation-finds-chinese-intrusions-into-key-defense-contractors

Source snippet

U.S. Senate Committee on Armed ServicesSeptember 17, 2014 —...

Published: September 17, 2014

3. Source: intelligence.senate.gov
Link:https://www.intelligence.senate.gov/1995/01/18/publications-special-report-committee-activities-select-committee-intelligence-january-4-1993/

4. Source: intelligence.senate.gov
Title: hearings nro headquarters project august 10 1994
Link:https://www.intelligence.senate.gov/1994/08/10/hearings-nro-headquarters-project-august-10-1994/

5. Source: intelligence.senate.gov
Title: hearings counterintelligence may 3 1994
Link:https://www.intelligence.senate.gov/1994/05/03/hearings-counterintelligence-may-3-1994/

6. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

7. Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm

Source snippet

Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...

8. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a

Source snippet

Unclassified. | National Security ArchiveMay 22, 1996 — GOVERNMENT ACCOUNTING OFFICE, GAO/AIMD- 96-84, INFORMATION SECURITY: COMPUTER ATT...

Published: May 22, 1996

9. Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr

10. Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/

11. Source: nsarchive.gwu.edu
Title: 21407 document 10b
Link:https://nsarchive.gwu.edu/document/21407-document-10b

12. Source: gao.gov
Title: b 256171
Link:https://www.gao.gov/products/b-256171

13. Source: gao.gov
Link:https://www.gao.gov/products/t-rced

14. Source: gao.gov
Title: nsiad 94 51
Link:https://www.gao.gov/products/nsiad

15. Source: gao.gov
Link:https://www.gao.gov/products/t-nsiad

Additional References

16. Source: justice.gov
Link:https://www.justice.gov/archive/opa/pr/2000/November/649civ.htm

Source snippet

#649: 11-06-00 HIGH-TECH FIRMS PAY $4.5 MILLION TO SETTLE ALLEGATIONS OF OVERBILLING THE AIR FORCENovember 6, 2000 — > FOR IMMEDIATE RELE...

Published: November 6, 2000

17. Source: youtube.com
Title: Matthew Bevan y [Richard Pryce]({{ ‘richard-pryce/’ | relative_url }})- Hackers Famosos
Link:https://www.youtube.com/watch?v=A0sCmWAUaZo

Source snippet

How to rescue secret Bloodborne character in Astro’s Playroom...

18. Source: youtube.com
Title: 10 Pinaka Notorious Na Mga Hackers Sa Buong Mundo
Link:https://www.youtube.com/watch?v=dRRfFoI7HaQ

Source snippet

Matthew Bevan y Richard Pryce- Hackers Famosos...

19. Source: youtube.com
Link:https://www.youtube.com/watch?v=9d2lH3M6esA

Source snippet

10 Pinaka Notorious Na Mga Hackers Sa Buong Mundo...

20. Source: youtube.com
Title: Gary Mc Kinnon wins extradition battle
Link:https://www.youtube.com/watch?v=y4lecD44F5E

Source snippet

Top 10 Best Hackers in the World in 2022...

21. Source: justice.gov
Title: #565 Teledyne pays U.S. $2 million to settle case
Link:https://www.justice.gov/archive/opa/pr/Pre_96/November95/565.txt.html

22. Source: youtube.com
Title: How to rescue secret Bloodborne character in Astro’s Playroom
Link:https://www.youtube.com/watch?v=XbfEa6TghnY

23. Source: govinfo.gov
Title: GA O/T-RCED-94-128
Link:https://www.govinfo.gov/app/details/GAOREPORTS-T-RCED

24. Source: gao.justia.com
Title: u s army and marine corps osi 94 3
Link:https://gao.justia.com/department-of-defense/1993/11/u-s-army-and-marine-corps-osi-94-3/

25. Source: washingtonpost.com
Title: SP Y UNIT’S SPENDING STUNS HILL
Link:https://www.washingtonpost.com/archive/politics/1994/08/09/spy-units-spending-stuns-hill/5f4456a3-5c90-4ecb-a50a-f2dd71613acf/