Within British Connection

Why Rome Laboratory Looked Like a Spy Attack

The scale, routing and defence connections of the Rome Laboratory attack made amateur hacking resemble a foreign intelligence operation.

39 sources 3 graphics
Preview for Why Rome Laboratory Looked Like a Spy Attack

On this page

  • What made the intrusion appear strategically serious
  • How routed connections obscured the attackers' origin
  • Why the amateur explanation emerged only later

Introduction

The 1994 intrusions into the US Air Force’s Rome Laboratory were initially treated as a potential espionage operation rather than ordinary computer trespassing because almost every observable characteristic resembled the tradecraft of a sophisticated intelligence service. More than 150 separate intrusions targeted one of the Air Force’s most important command-and-control research centres, the attackers concealed their identities through complex international routing, installed tools designed for long-term covert access, and stole sensitive military research while using compromised systems to pivot into other defence networks. Only after an extended multinational investigation did authorities conclude that the principal intruders were young British hackers rather than a state-sponsored espionage team. Even then, investigators acknowledged that the techniques employed demonstrated how amateur hackers could convincingly imitate the operational profile of a foreign intelligence service.[Global Security]globalsecurity.orgglobalsecurity.orgGlobal Security GAOGlobal SecurityGAO - Information Security: Computer Attacks at Department of Defense Pose IncreasingMay 22, 1996…Published: May 22, 1996

Espionage Alarm illustration 1

What made the intrusion appear strategically serious

Rome Laboratory was not an ordinary military office. It served as the US Air Force’s leading research centre for command, control, communications and intelligence technologies, including artificial intelligence, radar guidance, target detection and battlefield management systems. Because of its role in developing operational military capabilities, any successful intrusion immediately raised concerns that an adversary might be attempting to collect defence research rather than merely vandalise computer systems.[Global Security]globalsecurity.orgglobalsecurity.orgGlobal Security GAOGlobal SecurityGAO - Information Security: Computer Attacks at Department of Defense Pose IncreasingMay 22, 1996…Published: May 22, 1996

Several aspects of the attack reinforced that concern.

  • The attackers entered the laboratory more than 150 times during March and April 1994.
  • They installed password-capturing “sniffer” software instead of merely viewing files.
  • They deployed Trojan horse programs that allowed persistent access after initial entry.
  • They gained administrative control over parts of the laboratory’s operational network.
  • They used Rome Laboratory itself as a launch point for attacks on other military, government and contractor systems.[globalsecurity.org]globalsecurity.orgglobalsecurity.orgGlobal Security GAOGlobal SecurityGAO - Information Security: Computer Attacks at Department of Defense Pose IncreasingMay 22, 1996…Published: May 22, 1996

Those actions were consistent with intelligence collection rather than casual exploration. Password theft, covert persistence and lateral movement remain classic indicators of espionage-oriented network operations because they maximise future access while reducing the need for repeated break-ins.

The targets added to the suspicion. Investigators found evidence that the attackers reached systems connected with NASA, Wright-Patterson Air Force Base and defence contractors after compromising Rome Laboratory. From the viewpoint of Air Force investigators in 1994, this looked less like random curiosity and more like systematic expansion across strategically valuable networks.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security ArchiveOCR of the Document | National Security ArchiveMay 22, 1996…Published: May 22, 1996

How routed connections obscured the attackers’ origin

One of the strongest reasons the incident resembled espionage was the deliberate effort to disguise where the attacks originated.

Instead of connecting directly from Britain, the intruders routed their traffic through numerous intermediate systems and international telecommunications links. Official Air Force and Government Accountability Office accounts describe attack paths passing through commercial networks, overseas telephone exchanges and multiple countries before finally reaching Rome Laboratory. This made immediate attribution extremely difficult and initially obscured the attackers’ true location.[Global Security]globalsecurity.orgglobalsecurity.orgGlobal Security GAOGlobal SecurityGAO - Information Security: Computer Attacks at Department of Defense Pose IncreasingMay 22, 1996…Published: May 22, 1996

To investigators in the mid-1990s, such routing techniques resembled the operational security expected from professional intelligence organisations. At the time, international Internet tracing was slow, legally complex and technically limited. Every additional intermediary reduced confidence that the apparent source was genuine.

The attackers also attempted to erase traces of their activity and maintain covert access. Rather than conducting one-off intrusions, they repeatedly harvested passwords, reused compromised accounts and established mechanisms for returning later without exploiting the same vulnerability again. These behaviours aligned closely with intelligence collection priorities: preserve access, remain unnoticed and expand opportunities for future collection.[Global Security]globalsecurity.orgglobalsecurity.orgGlobal Security GAOGlobal SecurityGAO - Information Security: Computer Attacks at Department of Defense Pose IncreasingMay 22, 1996…Published: May 22, 1996

Espionage Alarm illustration 2

Why investigators initially considered foreign espionage

The broader security climate also shaped the investigation.

By 1994, American defence planners were becoming increasingly concerned that foreign governments were exploring information warfare. Senior officials recognised that military research facilities connected to the Internet could become targets for intelligence gathering long before armed conflict. Against that backdrop, a sustained attack against the Air Force’s premier command-and-control laboratory naturally triggered suspicion that a hostile state might be involved.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security ArchiveOCR of the Document | National Security ArchiveMay 22, 1996…Published: May 22, 1996

The Government Accountability Office later noted that investigators could not initially determine whether the attacks posed a national security threat and acknowledged that at least one attacker could theoretically have been working on behalf of a foreign country seeking military research. That uncertainty itself became part of the lesson: technical evidence alone could not distinguish between espionage and sophisticated civilian hacking.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security ArchiveOCR of the Document | National Security ArchiveMay 22, 1996…Published: May 22, 1996

Contemporary defence studies reinforced this concern by warning that structured information warfare could be disguised as apparently unstructured hacker activity. The Rome Laboratory incident therefore became an example of how difficult attribution could be when technically competent individuals used methods commonly associated with intelligence operations.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security ArchiveOCR of the Document | National Security ArchiveMay 22, 1996…Published: May 22, 1996

Why the amateur explanation emerged only later

Only after weeks of technical monitoring and international cooperation did investigators identify the principal suspects as British hackers using the online names “Datastream Cowboy” (Richard Pryce) and “Kuji” (Mathew Bevan).

Rather than immediately disconnecting the attackers, Air Force investigators created what became known as an “electronic fishbowl”: an isolated environment that allowed them to observe the intruders’ behaviour while limiting the damage they could inflict. Continued surveillance, combined with cooperation between the Air Force Office of Special Investigations and New Scotland Yard, eventually traced much of the activity back to Britain.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security ArchiveOCR of the Document | National Security ArchiveMay 22, 1996…Published: May 22, 1996

This did not mean the incident had been harmless. Air Force estimates placed the recovery costs at more than US$500,000, excluding the strategic value of compromised research. Officials also reported that if one affected air tasking order research project had required complete reconstruction, replacing it could have taken roughly three years and cost around US$4 million.[National Security Archive]nsarchive.gwu.eduNational Security Archive Jack LBrock, General Accounting Office, GAO/T-AIMD-96-92, Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…

The amateur explanation therefore changed who appeared responsible, not how serious the vulnerabilities had been.

Espionage Alarm illustration 3

The lasting lesson for later “UFO hacker” cases

Within the broader history of British hackers targeting American defence systems, the Rome Laboratory investigation became a warning that motivation and capability are not always closely linked.

Mathew Bevan would later become associated with claims that his interests included concealed UFO information, placing him in the same broad historical lineage as Gary McKinnon. Yet the Rome Laboratory investigation demonstrated that investigators could not infer motivation from technical behaviour alone. The intrusion techniques—persistent access, password harvesting, concealed routing and movement through interconnected defence networks—looked indistinguishable from professional espionage regardless of whether the attackers were intelligence officers, financially motivated criminals or individuals pursuing unconventional personal interests.[gwu.edu]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security ArchiveOCR of the Document | National Security ArchiveMay 22, 1996…Published: May 22, 1996

For cyber security professionals, this became one of the enduring lessons of the case. Attribution cannot rest solely on technical indicators. The Rome Laboratory breach showed that relatively young civilian hackers, operating from Britain with modest resources, could create an operational picture that initially convinced experienced investigators they might be confronting a foreign intelligence service rather than unauthorised enthusiasts.

Amazon book picks

Further Reading

Books and field guides related to Why Rome Laboratory Looked Like a Spy Attack. Use these as the next step if you want deeper reading beyond the article.

BookCover for Cyber War

Cyber War

By Richard A. Clarke, Robert K. Knake

Rating: 3.0/5 from 96 Google Books ratings

An essential, eye-opening book about cyberterrorism, cyber war, and the next great threat to our national security. " Cyber War may be th...

BookCover for Sandworm

Sandworm

By Andy Greenberg

"With the nuance of a reporter and the pace of a thriller writer, Andy Greenberg gives us a glimpse of the cyberwars of the future while...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromUS Air Force patch oneBay.co.uk.

Endnotes

1. Source: globalsecurity.orgglobalsecurity.org
Title: Global Security GAO
Link:https://www.globalsecurity.orgwww.globalsecurity.org/security/library/report/gao/aim96084.htm

Source snippet

Global SecurityGAO - Information Security: Computer Attacks at Department of Defense Pose IncreasingMay 22, 1996...

Published: May 22, 1996

2. Source: nsarchive.gwu.edu
Title: National Security Archive Jack L
Link:https://nsarchive.gwu.edu/document/21407-document-10b

Source snippet

Brock, General Accounting Office, GAO/T-AIMD-96-92, Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...

3. Source: pbs.org
Title: The Risks
Link:https://www.pbs.org/wgbh/pages/frontline/shows/hackers/risks/dodattacks.html

Source snippet

The Risks - Computer Attacks At Department Of Defense Pose Increasing Risks | Hackers | FRONTLINE | PBS...

4. Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr

Source snippet

National Security ArchiveOCR of the Document | National Security ArchiveMay 22, 1996...

Published: May 22, 1996

5. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a

Source snippet

National Security ArchiveGovernment Accounting Office, GAO/AIMD- 96-84, Information Security: Computer Attacks at Department of Defense P...

6. Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/

7. Source: irp.fas.org
Link:https://irp.fas.org/gao/aim96084.htm

Additional References

8. Source: kujimedia.com
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/

Source snippet

Kuji Media Corporation Ltd. » Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter Six...

9. Source: forensicmag.com
Title: Positive Identification Made in ‘Man in the Well’ Case
Link:https://www.forensicmag.com/580282-Positive-Identification-Made-in-Man-in-the-Well-Case/

Source snippet

October 20, 2021 — POSITIVE IDENTIFICATION MADE IN 'MAN IN THE WELL' CASE October 20, 2021 Image: 580282.jpg In 1984, Lester Rome, who wa...

Published: October 20, 2021

10. Source: archaeologyuk.org
Title: He is an editor of The Bloomsbury Handbook
Link:https://www.archaeologyuk.org/resource/roman-experimental-archaeology-from-the-bottom-up.html

Source snippet

Roman experimental archaeology, from the bottom up Council for British ArchaeologyJuly 16, 2024 — 16 Jul 2024 ROMAN EXPERIMENTAL ARCHAEOL...

Published: July 16, 2024

11. Source: issues.org
Title: in Science and Technology An Electronic Pearl Harbor? Not Likely
Link:https://issues.org/smith-2/

Source snippet

Issues in Science and TechnologyAn Electronic Pearl Harbor? Not Likely...

12. Source: youtube.com
Title: A Tale of Two UFO Hackers: Matthew Bevan & Gary Mc Kinnon | True Crime
Link:https://www.youtube.com/watch?v=rksYZZgSPcY

Source snippet

The Untold Story of Gary McKinnon: Biggest Military Hack Ever...

13. Source: youtube.com
Title: The Untold Story of Gary Mc Kinnon: Biggest Military Hack Ever!
Link:https://www.youtube.com/watch?v=-_tzaIKGnYw

Source snippet

The 1994 Rome Laboratory Cyber Attack Raleigh Guevarra · 27 views...

14. Source: youtube.com
Title: Unveiling the Untold Saga of Kuji and Datastream Cowboy
Link:https://www.youtube.com/watch?v=n_iLfffJbzo

Source snippet

A Tale of Two UFO Hackers: Matthew Bevan & Gary McKinnon | True Crime...

15. Source: intelligence.senate.gov
Link:https://www.intelligence.senate.gov/1994/11/01/publications-assessment-aldrich-h-ames-espionage-case-and-its-implications-us-intelligence-november/

16. Source: intelligence.senate.gov
Link:https://www.intelligence.senate.gov/1995/01/18/publications-special-report-committee-activities-select-committee-intelligence-january-4-1993/

17. Source: britishmuseum.org
Link:https://www.britishmuseum.org/our-work/departments/greece-and-rome