Within Early Insecurity
How Many Pentagon Intrusions Went Unnoticed?
GAO estimates suggested that many Defense systems were penetrated successfully while only a small fraction of intrusions were detected or reported.
On this page
- What the 250,000 attack estimate measured
- Why successful penetrations were rarely detected
- Why incident reporting missed the full scale
Page outline Jump by section
Introduction
One of the clearest indicators of how insecure early US military networks had become in the mid-1990s was not a single high-profile intrusion, but the enormous gap between the attacks that occurred and the attacks that defenders actually knew about. A 1996 assessment by the US General Accounting Office (GAO, now the Government Accountability Office) concluded that the Department of Defense (DoD) may have experienced around 250,000 attacks during 1995, while only a tiny fraction were detected and officially reported. That disparity became one of the strongest pieces of evidence that government computer security was failing long before cases such as Gary McKinnon’s intrusions drew public attention.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
Within the broader story of early internet insecurity behind UFO-related hacking, these figures matter because they show that individual intruders were operating in an environment where defenders often lacked the ability to see, investigate or even count successful compromises.
What the 250,000-attack estimate measured
The widely quoted figure of 250,000 attacks originated from Defence Information Systems Agency (DISA) estimates cited by the GAO in 1996. It was not a count of confirmed, unique hackers breaking into classified Pentagon systems. Instead, it represented an estimate of attempted attacks directed at DoD computer systems across an enormous and increasingly internet-connected infrastructure.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
The estimate reflected several realities of the period:
- the DoD operated tens of thousands of interconnected computers administered by different organisations;
- internet connectivity was expanding rapidly across military and research networks;
- many systems lacked consistent security controls;
- attack activity ranged from automated probing to deliberate intrusions by human attackers.
The GAO stressed that the exact number could not be determined with precision, but concluded that available evidence indicated attacks were occurring at a scale far beyond routine administrative awareness.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
Equally striking was the assessment that attackers successfully penetrated systems in roughly 64–65% of attempts recorded in the underlying estimates. Although that percentage reflected the methodology available at the time rather than modern incident-response metrics, it illustrated how frequently basic security weaknesses translated into actual unauthorised access.[GAO]gao.govInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAO…
Why successful penetrations were rarely detected
The most influential finding was not simply that attacks occurred, but that defenders frequently never realised they had happened.
The GAO reported that only about one attack in 500 was detected and reported. Using the 250,000-attack estimate, this implied that perhaps only a few hundred incidents reached official awareness, leaving the overwhelming majority effectively invisible to security managers.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
Several structural problems created this detection gap.
First, monitoring technology was immature. Many organisations relied primarily on local system administrators noticing suspicious behaviour rather than on continuous network-wide intrusion detection. Automated monitoring existed in limited forms but lacked today’s sophisticated logging, correlation and alerting capabilities.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
Second, responsibility for security was fragmented. Individual military commands, laboratories and support organisations managed their own systems with varying levels of expertise and inconsistent security practices. A successful intrusion affecting one organisation might never become visible elsewhere in the Department.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
Third, attackers often sought persistence rather than immediate disruption. Once administrator access had been obtained, intruders could install backdoor software, create additional accounts or alter system configurations in ways that blended into normal administrative activity unless someone specifically searched for evidence of compromise.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
Why incident reporting missed the full scale
Detection alone did not guarantee that an intrusion would appear in official statistics.
The GAO criticised the DoD for lacking a department-wide policy requiring comprehensive reporting of security incidents. Even when local administrators discovered unauthorised access, reporting procedures varied significantly between organisations, making central oversight incomplete. One of the report’s principal recommendations was to mandate reporting of all security incidents across the Department.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
The report also identified wider organisational shortcomings that reduced reporting quality:
- inconsistent risk assessments;
- outdated or conflicting security policies;
- limited training for system and network administrators;
- inadequate procedures for assessing damage after an intrusion;
- uneven correction of known vulnerabilities.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
These weaknesses meant that official incident counts reflected only the small subset of attacks that were both detected and formally communicated through the chain of command.
Why the estimates mattered for later Pentagon hacking cases
The GAO’s findings provide important context for understanding later cases involving unauthorised access to military systems, including the networks explored by Gary McKinnon.
The report was published in May 1996, several years before McKinnon’s intrusions began. Rather than explaining his activities specifically, it documented that large-scale weaknesses already existed throughout Defence networks. By the time McKinnon started scanning internet-connected systems, government auditors had already warned Congress that attackers were exploiting poor security controls while defenders detected only a small proportion of successful intrusions.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
This chronology is significant because it counters the impression that individual hackers exposed unprecedented vulnerabilities. Instead, the evidence suggests that many of the conditions they encountered—including weak administration, inconsistent monitoring and incomplete reporting—had already been recognised as systemic problems.
What the detection gap revealed
The lasting importance of the 1996 estimates lies less in the precise numerical values than in what they revealed about institutional awareness.
The GAO concluded that the Department of Defense was attempting to respond to attacks without a consistent framework for preventing intrusions, detecting them, assessing resulting damage or ensuring that lessons learned were shared across the organisation. It recommended mandatory incident reporting, routine risk assessments, faster correction of vulnerabilities and more consistent security policies across the Department.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
In retrospect, the “250,000 attacks” estimate became a symbol of a broader reality: during the formative years of widespread internet connectivity, the greatest weakness was not simply that Defence systems were being attacked, but that many successful intrusions passed unnoticed. That detection gap helps explain how later unauthorised access by individuals searching military networks—including those motivated by interests such as UFO-related material—could persist within an environment that lacked comprehensive visibility into its own security posture.[GAO]gao.govaimdInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996…
Amazon book picks
Further Reading
Books and field guides related to How Many Pentagon Intrusions Went Unnoticed?. Use these as the next step if you want deeper reading beyond the article.
Cyber War: The Next Threat to National Security and What to D...
Rating: 3.0/5 from 96 Google Books ratings
An essential, eye-opening book about cyberterrorism, cyber war, and the next great threat to our national security. " Cyber War may be th...
Where Wizards Stay Up Late
Rating: 3.8/5 from 11 Google Books ratings
In 1990, the ARPANET itself was shut down, fully merged by then with the Internet it had spawned.
Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin'...
"With the nuance of a reporter and the pace of a thriller writer, Andy Greenberg gives us a glimpse of the cyberwars of the future while...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromUFO enamel pin oneBay.co.uk.
Endnotes
1.
Source: gao.gov
Title: aimd 96 84
Link:https://www.gao.gov/products/aimd
Source snippet
Information Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAOMay 22, 1996...
Published: May 22, 1996
2.
Source: gao.gov
Link:https://www.gao.gov/products/t-aimd
Source snippet
Information Security: Computer Attacks at Department of Defense Pose Increasing Risks | U.S. GAO...
3.
Source: gao.gov
Title: United States General Accounting Office
Link:https://www.gao.gov/assets/hr-97-9.pdf
Source snippet
United States General Accounting Office...
4.
Source: gao.gov
Link:https://www.gao.gov/products/gao
Source snippet
March 29, 2001 — INFORMATION SECURITY: CHALLENGES TO IMPROVING DOD'S INCIDENT RESPONSE CAPABILITIES GAO-01-341...
Published: March 29, 2001
5.
Source: gao.gov
Title: Operation Desert Storm: Operation Desert Storm Air War | U.S
Link:https://www.gao.gov/products/pemd
Source snippet
July 2, 1996 — OPERATION DESERT STORM: OPERATION DESERT STORM AIR WAR PEMD-96-10...
Published: July 2, 1996
6.
Source: gao.gov
Title: Bottom-Up Review: Analysis of DOD War Game to Test Key Assumptions | U.S
Link:https://www.gao.gov/products/nsiad
Source snippet
June 21, 1996 — BOTTOM-UP REVIEW: ANALYSIS OF DOD WAR GAME TO TEST KEY ASSUMPTIONS NSIAD-96-170...
Published: June 21, 1996
7.
Source: gao.gov
Title: nsiad 96 72
Link:https://www.gao.gov/products/nsiad
Additional References
8.
Source: nsarchive.gwu.edu
Title: UNCLASSIFIED. United States General Accou
Link:https://nsarchive.gwu.edu/media/22366/ocr
Source snippet
of the Document | National Security ArchiveJune 5, 1996 — OCR OF THE DOCUMENT View the Document >> GENERAL ACCOUNTING OFFICE, GAO/T-AIMD...
Published: June 5, 1996
9.
Source: gao.justia.com
Title: information security aimd 96 84
Link:https://gao.justia.com/department-of-defense/1996/5/information-security-aimd-96-84/
Source snippet
GAO Reports - AIMD-96-84 - Information Security - Department of DefenseMay 22, 1996 — INFORMATION SECURITY Computer Attacks at Department...
Published: May 22, 1996
10.
Source: youtube.com
Title: The Man Who Hacked the U.S. Government
Link:https://www.youtube.com/watch?v=ND0zQX1rGdg
Source snippet
Hacking for UFOs and fighting for his life. Who is Gary McKinnon?...
11.
Source: youtube.com
Link:https://www.youtube.com/watch?v=b5afwWUYWVQ
Source snippet
Ancient Aliens: Hacking NASA Secrets (Season 12, Episode 9)...
12.
Source: legistorm.com
Link:https://www.legistorm.com/reports/view/gao/26571/Computer_Attacks_at_Department_of_Defense_Pose_Increasing_Risks.html
13.
Source: legistorm.com
Link:https://www.legistorm.com/reports/view/gao/26572/Computer_Attacks_at_Department_of_Defense_Pose_Increasing_Risks.html
14.
Source: youtube.com
Title: UK hacker’s extradition to US blocked
Link:https://www.youtube.com/watch?v=v4Js8DF80HY
Source snippet
[Gary McKinnon Case]({{ 'mc-kinnon-case/' | relative_url }}) (Interview from 2009)...
15.
Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ
Source snippet
UK hacker's extradition to US blocked...
16.
Source: ieee-security.org
Title: GA O Reports Do D SBU Computer Security Inadequate
Link:https://www.ieee-security.org/Cipher/Newsbriefs/1996/960522.GAOrept.html
17.
Source: youtube.com
Title: Ancient Aliens: Hacking NASA Secrets (Season 12, Episode 9)
Link:https://www.youtube.com/watch?v=20rWFDfh68Y


