Within Richard Pryce
Why One Korean Intrusion Raised Diplomatic Fears
A stolen-data transfer briefly raised fears that an apparent US military intrusion might be mistaken for state-sponsored espionage.
On this page
- What happened on 15 April 1994
- Why investigators first feared a North Korean target
- What the official record says about the actual risk
Page outline Jump by section
Introduction
Among the many intrusions associated with Richard Pryce (“Datastream Cowboy”) and his online associate known as “Kuji”, one episode stood out because it briefly appeared capable of creating an international security incident rather than merely exposing weak computer security. On 15 April 1994, while US Air Force investigators were covertly monitoring the hackers inside Rome Laboratory’s network, one of the intruders copied data from a Korean atomic-research system onto the compromised Air Force computers. For several hours, investigators could not determine whether the victim was in North Korea or South Korea. That uncertainty mattered because the United States was simultaneously engaged in delicate negotiations with North Korea over its nuclear programme. If the target had been North Korean, the transfer could have appeared to be a US military intelligence operation rather than the work of civilian hackers.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
What happened on 15 April 1994
By mid-April 1994, Air Force investigators and New Scotland Yard had already identified Datastream Cowboy and were preparing to execute a search warrant in the United Kingdom. Rather than arrest him immediately, they delayed the operation so they could continue monitoring his activity and gather stronger evidence against everyone involved in the intrusion campaign.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
During that surveillance, investigators observed an unexpected development. The intruder connected from the compromised Rome Laboratory systems to an atomic research institute in Korea, obtained its stored data and copied it back onto the Rome Laboratory network. Because the Air Force systems were acting as an intermediate platform, the apparent source of the activity would have appeared to be a legitimate US military installation rather than a teenager operating from Britain through a chain of compromised systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
This incident differed from many other attacks in the case. Earlier intrusions had targeted NASA, defence contractors and military research networks. The Korean transfer, however, involved a facility associated with nuclear research, immediately raising questions that extended beyond ordinary computer crime.
Why investigators first feared a North Korean target
The official Air Force case study explains that investigators initially could not establish whether the compromised atomic-research system belonged to North Korea or South Korea. That distinction was critical because of the political situation in April 1994.
At the time:
- The United States and North Korea were engaged in highly sensitive negotiations over North Korea’s suspected nuclear weapons programme.
- Relations on the Korean Peninsula were tense following disputes over international inspections of North Korean nuclear facilities.
- Any apparent US military penetration of a North Korean nuclear organisation could have been interpreted as intelligence gathering or preparation for hostile action.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
The investigators’ concern therefore was not that the hackers themselves posed a military threat, but that attribution could fail. Because the stolen files had been routed through a genuine US Air Force computer, a victim examining network logs might conclude that the intrusion originated from the United States military.
This illustrates a problem that later became central to cyber-security policy: an attacker can deliberately exploit another organisation’s computers so that responsibility appears to belong to someone else. In modern terminology, the Rome Laboratory systems had effectively become an unwitting launch platform for operations against third parties.
The diplomatic risk was one of perception
The official record does not suggest that Pryce or his associate intended to provoke an international crisis. Instead, the danger arose from the combination of three circumstances:
- Compromised military infrastructure. The attack appeared to originate from an authentic US Air Force research facility.
- A nuclear-related victim. The destination involved atomic research, making any unauthorised access especially sensitive.
- A tense geopolitical moment. US diplomacy with North Korea was already under intense pressure over nuclear issues.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Had the victim actually been a North Korean nuclear organisation, investigators feared that the apparent US origin of the intrusion might be interpreted as a deliberate American espionage operation. The concern was therefore diplomatic and strategic rather than technical.
What the official record says about the actual risk
The uncertainty did not last long. According to the Air Force investigative history, investigators established within hours that the compromised organisation was the South Korean Atomic Research Institute, not a North Korean facility. Once that determination was made, the immediate diplomatic concern subsided.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
The record does not indicate that the data transfer triggered a diplomatic incident or altered US policy. Instead, it prompted investigators to continue monitoring the hackers while expanding cooperation with British authorities before carrying out the planned search of Pryce’s residence.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Equally important, no official source claims that the hackers obtained classified North Korean nuclear information or penetrated North Korean government systems. Later retellings sometimes blur this distinction, but the contemporaneous investigative report is explicit that the alarm arose from initial uncertainty over the victim’s identity, not from evidence of a successful intrusion into North Korea itself.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Why this incident became historically significant
Within the wider Datastream Cowboy case, the Korean atomic-research episode became memorable because it demonstrated how relatively unsophisticated intruders could create strategic confusion far beyond the value of the information they actually stole.
The episode highlighted several lessons that later became fundamental to cyber-security:
- Compromised government networks can be abused to attack unrelated third parties.
- Attribution based solely on network origin can be dangerously misleading.
- Cyber incidents can acquire diplomatic significance even when the perpetrators are not acting on behalf of any government.
- Investigators must rapidly distinguish criminal hacking from state-sponsored espionage before policymakers respond.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
In retrospect, the Korean incident was less important because of the data that were copied than because it exposed the possibility that a teenager’s intrusion could briefly resemble an international intelligence operation. That prospect, occurring during an already fragile nuclear dispute on the Korean Peninsula, explains why investigators regarded this single event as one of the most alarming moments in the entire Rome Laboratory investigation.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Amazon book picks
Further Reading
Books and field guides related to Why One Korean Intrusion Raised Diplomatic Fears. Use these as the next step if you want deeper reading beyond the article.
The Cuckoo's Egg: Tracking a Spy Through the Maze of Computer...
This is the true story of how a systems manager at Lawrence Berkeley Lab singlehandedly tracked down and helped capture a computer hacker...
Dark Territory: The Secret History of Cyber War
“An important, disturbing, and gripping history” (Kirkus Reviews, starred review), the never-before-told story of the computer scientists...
The Perfect Weapon: War, Sabotage, and Fear in the Cyber Age
From Russia’s tampering with the US election to the WannaCry hack that temporarily crippled Britain’s NHS, cyber has become the weapon of...
Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin'...
"With the nuance of a reporter and the pace of a thriller writer, Andy Greenberg gives us a glimpse of the cyberwars of the future while...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromretro computer poster oneBay.co.uk.
Endnotes
1.
Source: issues.org
Title: An Electronic Pearl Harbor? Not Likely
Link:https://issues.org/smith-2/
2.
Source: history.state.gov
Title: two koreas
Link:https://history.state.gov/milestones/1993-2000/two-koreas
3.
Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm
Source snippet
Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...
4.
Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr
5.
Source: nsarchive.gwu.edu
Title: new evidence clinton negotiations north korea
Link:https://nsarchive.gwu.edu/briefing-book/nuclear-vault/korea/2020-06-16/new-evidence-clinton-negotiations-north-korea
Source snippet
23, 2000, file photo, North Korean Leader Kim Jong Il, right, and U.S. Secretary of State Madeleine Albright, left, w...
6.
Source: nsarchive.gwu.edu
Title: united states north korea nuclear threat
Link:https://nsarchive.gwu.edu/briefing-book/korea-nuclear-vault/2019-02-26/united-states-north-korea-nuclear-threat
Source snippet
United States and the North Korea Nuclear Threat | National Security ArchiveFebruary 26, 2019 — Image: National-Security-Archive-Doc-04-D...
Published: February 26, 2019
7.
Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB474/
Source snippet
President Kim held an historic summit meeting with North Korean leader Kim Jong Il in June 200...
8.
Source: nsarchive2.gwu.edu
Title: (Official Wh
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB421/
Source snippet
the North Korean Tea Leaves: The Perpetual Struggle to Fathom Pyongyang's Motives and GoalsApril 11, 2013 — Image President Barack Obama...
Published: April 11, 2013
9.
Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB87/
10.
Source: congress.gov
Link:https://www.congress.gov/event/106th-congress/senate-event/LC18520/text
11.
Source: nsarchive.gwu.edu
Title: 18229 national security archive doc 11 dprk not much
Link:https://nsarchive.gwu.edu/document/18229-national-security-archive-doc-11-dprk-not-much
12.
Source: nsarchive.gwu.edu
Title: 18240 national security archive doc 07 memorandum
Link:https://nsarchive.gwu.edu/document/18240-national-security-archive-doc-07-memorandum
Additional References
13.
Source: korben.info
Title: Deux ados cherchant des OVNIS ont failli lancer la WW3
Link:https://korben.info/kuji-datastream-cowboy-pentagone-hack-1996-histoire-complete.html
Source snippet
sauf pour deux ados obsédés par X-Files Si comme moi, vous êtes fans de X-Files, vous allez kiffer cette histoire. [Mathew Bevan]({{ 'mathew-bevan/' | relative_url }}), alias "K...
14.
Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/
Source snippet
» Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter SixJune 26, 2008 — Almost immediately, monitoring disclo...
Published: June 26, 2008
15.
Source: youtube.com
Title: UK hacker’s extradition to US blocked
Link:https://www.youtube.com/watch?v=v4Js8DF80HY
Source snippet
This selection highlights historical cyber security cases where network compromises involving US military servers triggered major nationa...
16.
Source: youtube.com
Title: Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub
Link:https://www.youtube.com/watch?v=z7OjzYT_-Zo
Source snippet
Top 10 Most Dangerous Hackers Of All Time | Simplilearn...
17.
Source: atomicarchive.com
Link:https://www.atomicarchive.com/resources/documents/deterrence/agreed-framework.html
18.
Source: kujimedia.com
Link:https://www.kujimedia.com/articles/
19.
Source: youtube.com
Title: The Man Who Hacked the U.S. Government
Link:https://www.youtube.com/watch?v=ND0zQX1rGdg
Source snippet
Hacking for UFOs and fighting for his life. Who is Gary McKinnon?...
20.
Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Blog Archive » THE SCHOOLBOY SPY. Sunday Times
Link:https://www.kujimedia.com/the-schoolboy-spy-sunday-times/
21.
Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ
Source snippet
UK hacker's extradition to US blocked...
22.
Source: intelligence.senate.gov
Title: hearings nro headquarters project august 10 1994
Link:https://www.intelligence.senate.gov/1994/08/10/hearings-nro-headquarters-project-august-10-1994/



