Within Rome Laboratory

How Five Quiet Days Changed the Rome Breach

Five undetected days let intruders install sniffers, capture credentials and turn a single entry point into a much larger compromise.

24 sources 3 graphics
Preview for How Five Quiet Days Changed the Rome Breach

On this page

  • What happened between 23 and 28 March
  • Why the unauthorised file mattered
  • How delayed detection increased the damage

Introduction

The five-day period between the first confirmed penetration of Rome Laboratory on 23 March 1994 and its discovery on 28 March was not simply a delay in noticing an attack. It was the phase in which a limited compromise became a far broader security failure. During those undetected days, the intruders installed password-capturing software, collected legitimate user credentials, expanded from an initial foothold to dozens of systems, and prepared Rome Laboratory to serve as a launch point for attacks against other military, government and research networks. Later official investigations consistently identified this detection gap—not the original entry point—as the factor that most increased the scale and consequences of the incident.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Detection Gap illustration 1

What happened between 23 and 28 March

Official records show that system logs later revealed the attackers had entered Rome Laboratory on 23 March, but administrators did not recognise the intrusion until 28 March, when an unauthorised file drew attention to suspicious activity. By then, the attackers had already established a persistent presence inside the network.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Those five days allowed the attackers to work largely without interference. Rather than immediately stealing as much information as possible, they first strengthened their position inside the environment. Investigators found that they installed seven network sniffers—programs designed to capture usernames and passwords travelling across the network. Because many services of the period transmitted credentials without modern encryption, these sniffers could silently collect authentication data from legitimate users as they logged into other systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The delay therefore changed the nature of the breach. Instead of repeatedly exploiting technical vulnerabilities from outside the network, the attackers increasingly relied on stolen credentials, allowing them to appear to other systems as authorised users rather than obvious intruders.[GAO]gao.govUnited States General Accounting OfficeUnited States General Accounting OfficeMay 8, 2026…Published: May 8, 2026

Why the unauthorised file mattered

The breach came to light only because a systems administrator noticed an unauthorised file that did not belong on the machine. Contemporary GAO testimony describes this observation as the event that triggered the laboratory’s incident response and the involvement of the Air Force Information Warfare Center and the Air Force Office of Special Investigations.[GAO]gao.govUnited States General Accounting OfficeUnited States General Accounting Office…

The importance of that file was less about its contents than what it revealed. By the time it was detected, investigators discovered that the compromise was no longer confined to one machine. Security logs showed the intrusion had already existed for several days, meaning administrators were responding to an established internal presence rather than intercepting an initial break-in.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

This illustrates a recurring lesson in incident response: the first visible sign of compromise often appears well after attackers have completed their most valuable preparatory work. In Rome Laboratory’s case, the unauthorised file exposed activity that had already progressed from initial access to credential harvesting and lateral movement.

Detection Gap illustration 2

How delayed detection increased the damage

The additional five days produced consequences that multiplied throughout the network rather than remaining confined to a single computer.

Credential collection expanded rapidly. The seven sniffers ultimately compromised more than 100 user accounts by recording usernames and passwords. Once these credentials had been captured, attackers no longer depended solely on their original method of entry. They could authenticate as legitimate users, making further movement through the network more difficult to distinguish from normal activity.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The compromise spread across Rome Laboratory. Senate investigators reported that the sniffers enabled compromise of 30 Rome Laboratory systems containing sensitive research and development information. User email was reportedly read, copied and deleted, while sensitive but unclassified battlefield simulation data was accessed and copied.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The laboratory became a platform for additional attacks. Once sufficient credentials had been collected, Rome Laboratory itself was used as a trusted launching point for attacks against other military, government, academic and commercial organisations. Because connections originated from an established Air Force research facility, downstream targets often saw traffic coming from a system they already trusted rather than from an unknown external source.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Recovery became substantially more expensive. By the time investigators regained control, restoring confidence in the network required systems to be isolated, verified, patched and gradually returned to service. GAO testimony estimated direct government costs at more than US$500,000, excluding the value of compromised research or the potential strategic value of stolen information.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security ArchiveOCR of the Document | National Security ArchiveMay 22, 1996…Published: May 22, 1996

Why the detection gap mattered more than the initial intrusion

The Rome Laboratory case is frequently remembered because of later investigations into individuals linked to the attacks, including discussions surrounding UFO-related motivations associated with Mathew Bevan. From a cybersecurity perspective, however, the more enduring lesson is operational rather than biographical.

The initial penetration created an opportunity, but the five undetected days transformed that opportunity into a network-wide compromise. During that window, the attackers established persistence, harvested credentials, expanded privileges and positioned themselves to exploit trusted relationships beyond Rome Laboratory itself. Had the intrusion been identified immediately after the first entry on 23 March, investigators would likely have been dealing with a much smaller containment exercise rather than a compromise involving dozens of systems, more than one hundred accounts and numerous connected organisations.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The incident therefore became an influential early example of a principle that still shapes modern cyber defence: the speed of detection can matter as much as preventing the initial breach. Once attackers have enough uninterrupted time to establish persistence and collect legitimate credentials, the difficulty and cost of recovery increase dramatically, even if the original method of entry was comparatively unsophisticated.[GAO]gao.govUnited States General Accounting OfficeUnited States General Accounting OfficeMay 8, 2026…Published: May 8, 2026

Detection Gap illustration 3

Amazon book picks

Further Reading

Books and field guides related to How Five Quiet Days Changed the Rome Breach. Use these as the next step if you want deeper reading beyond the article.

BookCover for Sandworm

Sandworm

By Andy Greenberg

"With the nuance of a reporter and the pace of a thriller writer, Andy Greenberg gives us a glimpse of the cyberwars of the future while...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromretro computer poster oneBay.co.uk.

Endnotes

1. Source: gao.gov
Title: United States General Accounting Office
Link:https://www.gao.gov/assets/t-aimd-96-92.pdf

Source snippet

United States General Accounting Office...

2. Source: gao.gov
Title: United States General Accounting Office
Link:https://www.gao.gov/assets/aimd-96-84.pdf

Source snippet

United States General Accounting OfficeMay 8, 2026...

Published: May 8, 2026

3. Source: intelligence.senate.gov
Title: hearings nro headquarters project august 10 1994
Link:https://www.intelligence.senate.gov/1994/08/10/hearings-nro-headquarters-project-august-10-1994/

4. Source: intelligence.senate.gov
Title: hearings counterintelligence may 3 1994
Link:https://www.intelligence.senate.gov/1994/05/03/hearings-counterintelligence-may-3-1994/

5. Source: intelligence.senate.gov
Title: hearings joint security commission march 3 1994
Link:https://www.intelligence.senate.gov/1994/03/03/hearings-joint-security-commission-march-3-1994/

6. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

7. Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr

Source snippet

National Security ArchiveOCR of the Document | National Security ArchiveMay 22, 1996...

Published: May 22, 1996

8. Source: irp.fas.org
Link:https://irp.fas.org/gao/aim96084.htm

Source snippet

At worst, they are a serious threat to national security. Attackers have seized control of entire Defense systems, many of w...

9. Source: irp.fas.org
Title: ssci ames
Link:https://irp.fas.org/congress/1994_rpt/ssci_ames.htm

10. Source: irp.fas.org
Link:https://irp.fas.org/eprint/snyder/infowarfare.htm

Additional References

11. Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/tag/datastream-cowboy/

Source snippet

» Datastream CowboyJune 26, 2008 — Air Force’s premier command-and- control research facility. Rome Lab researchers collaborate with univ...

Published: June 26, 2008

12. Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/

Source snippet

» Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter SixJune 26, 2008 — They also end up in the headlines bec...

Published: June 26, 2008

13. Source: youtube.com
Title: The Importance of Dwell Time in Defending Against Cyber Attacks
Link:http://www.youtube.com/watch?v=rn3VEiAQ4lc

Source snippet

[Richard Pryce]({{ 'richard-pryce/' | relative_url }}) Datastream Cowboy hack THE HACKER WHO EXPOSED THE PENTAGON'S GREATEST WEAKNESS KRYPT Files...

14. Source: youtube.com
Title: THE HACKER WHO EXPOSED THE PENTAGON’S GREATEST WEAKNESS
Link:http://www.youtube.com/watch?v=ltNqoeAEx20

Source snippet

A 17-Year-Old Hacked Apple, Microsoft And The Pentagon From His Bedroom...

15. Source: youtube.com
Title: A 17-Year-Old Hacked Apple, Microsoft And The Pentagon From His Bedroom
Link:http://www.youtube.com/watch?v=5QpwxXPo1Kk

Source snippet

Gary Mckinnon: The Hacker Who Found UFOs...

16. Source: airandspaceforces.com
Title: Five days had p
Link:https://www.airandspaceforces.com/article/0198cyber/

Source snippet

War in Cyberspace | Air & Space Forces MagazineJanuary 1, 1998 — | The Datastream Cowboy and Kuji The best known of all attacks on Air Fo...

Published: January 1, 1998

17. Source: youtube.com
Title: Gary Mc Kinnon: The UFO Hunter Who Hacked the Pentagon
Link:http://www.youtube.com/watch?v=Gb5dvf6ZCYY

Source snippet

The Importance of Dwell Time in Defending Against Cyber Attacks...

18. Source: archive.epic.org
Title: GAO DOD security
Link:https://archive.epic.org/security/GAO_DOD_security.html

Source snippet

Following are examples of attacks to date. The first attack we highlight, on Rome Laboratory, New York, was well-documented...

19. Source: all.net
Link:https://all.net/books/iw/iwarstuff/www.af.mil/news/airman/0496/hacker.htm

20. Source: youtube.com
Title: Gary Mckinnon: The Hacker Who Found UFOs
Link:http://www.youtube.com/watch?v=8_1DuqeU8hw

Source snippet

Gary McKinnon: The UFO Hunter Who Hacked the Pentagon...