Within Richard Pryce

Why One Korean Intrusion Raised Diplomatic Fears

A stolen-data transfer briefly raised fears that an apparent US military intrusion might be mistaken for state-sponsored espionage.

38 sources 3 graphics
Preview for Why One Korean Intrusion Raised Diplomatic Fears

On this page

  • What happened on 15 April 1994
  • Why investigators first feared a North Korean target
  • What the official record says about the actual risk

Introduction

Among the many intrusions associated with Richard Pryce (“Datastream Cowboy”) and his online associate known as “Kuji”, one episode stood out because it briefly appeared capable of creating an international security incident rather than merely exposing weak computer security. On 15 April 1994, while US Air Force investigators were covertly monitoring the hackers inside Rome Laboratory’s network, one of the intruders copied data from a Korean atomic-research system onto the compromised Air Force computers. For several hours, investigators could not determine whether the victim was in North Korea or South Korea. That uncertainty mattered because the United States was simultaneously engaged in delicate negotiations with North Korea over its nuclear programme. If the target had been North Korean, the transfer could have appeared to be a US military intelligence operation rather than the work of civilian hackers.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Korean Incident illustration 1

What happened on 15 April 1994

By mid-April 1994, Air Force investigators and New Scotland Yard had already identified Datastream Cowboy and were preparing to execute a search warrant in the United Kingdom. Rather than arrest him immediately, they delayed the operation so they could continue monitoring his activity and gather stronger evidence against everyone involved in the intrusion campaign.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

During that surveillance, investigators observed an unexpected development. The intruder connected from the compromised Rome Laboratory systems to an atomic research institute in Korea, obtained its stored data and copied it back onto the Rome Laboratory network. Because the Air Force systems were acting as an intermediate platform, the apparent source of the activity would have appeared to be a legitimate US military installation rather than a teenager operating from Britain through a chain of compromised systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

This incident differed from many other attacks in the case. Earlier intrusions had targeted NASA, defence contractors and military research networks. The Korean transfer, however, involved a facility associated with nuclear research, immediately raising questions that extended beyond ordinary computer crime.

Why investigators first feared a North Korean target

The official Air Force case study explains that investigators initially could not establish whether the compromised atomic-research system belonged to North Korea or South Korea. That distinction was critical because of the political situation in April 1994.

At the time:

  • The United States and North Korea were engaged in highly sensitive negotiations over North Korea’s suspected nuclear weapons programme.
  • Relations on the Korean Peninsula were tense following disputes over international inspections of North Korean nuclear facilities.
  • Any apparent US military penetration of a North Korean nuclear organisation could have been interpreted as intelligence gathering or preparation for hostile action.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The investigators’ concern therefore was not that the hackers themselves posed a military threat, but that attribution could fail. Because the stolen files had been routed through a genuine US Air Force computer, a victim examining network logs might conclude that the intrusion originated from the United States military.

This illustrates a problem that later became central to cyber-security policy: an attacker can deliberately exploit another organisation’s computers so that responsibility appears to belong to someone else. In modern terminology, the Rome Laboratory systems had effectively become an unwitting launch platform for operations against third parties.

Korean Incident illustration 2

The diplomatic risk was one of perception

The official record does not suggest that Pryce or his associate intended to provoke an international crisis. Instead, the danger arose from the combination of three circumstances:

  • Compromised military infrastructure. The attack appeared to originate from an authentic US Air Force research facility.
  • A nuclear-related victim. The destination involved atomic research, making any unauthorised access especially sensitive.
  • A tense geopolitical moment. US diplomacy with North Korea was already under intense pressure over nuclear issues.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Had the victim actually been a North Korean nuclear organisation, investigators feared that the apparent US origin of the intrusion might be interpreted as a deliberate American espionage operation. The concern was therefore diplomatic and strategic rather than technical.

What the official record says about the actual risk

The uncertainty did not last long. According to the Air Force investigative history, investigators established within hours that the compromised organisation was the South Korean Atomic Research Institute, not a North Korean facility. Once that determination was made, the immediate diplomatic concern subsided.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The record does not indicate that the data transfer triggered a diplomatic incident or altered US policy. Instead, it prompted investigators to continue monitoring the hackers while expanding cooperation with British authorities before carrying out the planned search of Pryce’s residence.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Equally important, no official source claims that the hackers obtained classified North Korean nuclear information or penetrated North Korean government systems. Later retellings sometimes blur this distinction, but the contemporaneous investigative report is explicit that the alarm arose from initial uncertainty over the victim’s identity, not from evidence of a successful intrusion into North Korea itself.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Korean Incident illustration 3

Why this incident became historically significant

Within the wider Datastream Cowboy case, the Korean atomic-research episode became memorable because it demonstrated how relatively unsophisticated intruders could create strategic confusion far beyond the value of the information they actually stole.

The episode highlighted several lessons that later became fundamental to cyber-security:

  • Attribution based solely on network origin can be dangerously misleading.
  • Cyber incidents can acquire diplomatic significance even when the perpetrators are not acting on behalf of any government.
  • Investigators must rapidly distinguish criminal hacking from state-sponsored espionage before policymakers respond.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

In retrospect, the Korean incident was less important because of the data that were copied than because it exposed the possibility that a teenager’s intrusion could briefly resemble an international intelligence operation. That prospect, occurring during an already fragile nuclear dispute on the Korean Peninsula, explains why investigators regarded this single event as one of the most alarming moments in the entire Rome Laboratory investigation.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Amazon book picks

Further Reading

Books and field guides related to Why One Korean Intrusion Raised Diplomatic Fears. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromretro computer poster oneBay.co.uk.

Endnotes

1. Source: issues.org
Title: An Electronic Pearl Harbor? Not Likely
Link:https://issues.org/smith-2/

2. Source: history.state.gov
Title: two koreas
Link:https://history.state.gov/milestones/1993-2000/two-koreas

3. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

4. Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr

5. Source: nsarchive.gwu.edu
Title: new evidence clinton negotiations north korea
Link:https://nsarchive.gwu.edu/briefing-book/nuclear-vault/korea/2020-06-16/new-evidence-clinton-negotiations-north-korea

Source snippet

23, 2000, file photo, North Korean Leader Kim Jong Il, right, and U.S. Secretary of State Madeleine Albright, left, w...

6. Source: nsarchive.gwu.edu
Title: united states north korea nuclear threat
Link:https://nsarchive.gwu.edu/briefing-book/korea-nuclear-vault/2019-02-26/united-states-north-korea-nuclear-threat

Source snippet

United States and the North Korea Nuclear Threat | National Security ArchiveFebruary 26, 2019 — Image: National-Security-Archive-Doc-04-D...

Published: February 26, 2019

7. Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB474/

Source snippet

President Kim held an historic summit meeting with North Korean leader Kim Jong Il in June 200...

8. Source: nsarchive2.gwu.edu
Title: (Official Wh
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB421/

Source snippet

the North Korean Tea Leaves: The Perpetual Struggle to Fathom Pyongyang's Motives and GoalsApril 11, 2013 — Image President Barack Obama...

Published: April 11, 2013

9. Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB87/

10. Source: congress.gov
Link:https://www.congress.gov/event/106th-congress/senate-event/LC18520/text

11. Source: nsarchive.gwu.edu
Title: 18229 national security archive doc 11 dprk not much
Link:https://nsarchive.gwu.edu/document/18229-national-security-archive-doc-11-dprk-not-much

12. Source: nsarchive.gwu.edu
Title: 18240 national security archive doc 07 memorandum
Link:https://nsarchive.gwu.edu/document/18240-national-security-archive-doc-07-memorandum

Additional References

13. Source: korben.info
Title: Deux ados cherchant des OVNIS ont failli lancer la WW3
Link:https://korben.info/kuji-datastream-cowboy-pentagone-hack-1996-histoire-complete.html

Source snippet

sauf pour deux ados obsédés par X-Files Si comme moi, vous êtes fans de X-Files, vous allez kiffer cette histoire. [Mathew Bevan]({{ 'mathew-bevan/' | relative_url }}), alias "K...

14. Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/

Source snippet

» Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter SixJune 26, 2008 — Almost immediately, monitoring disclo...

Published: June 26, 2008

15. Source: youtube.com
Title: UK hacker’s extradition to US blocked
Link:https://www.youtube.com/watch?v=v4Js8DF80HY

Source snippet

This selection highlights historical cyber security cases where network compromises involving US military servers triggered major nationa...

16. Source: youtube.com
Title: Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub
Link:https://www.youtube.com/watch?v=z7OjzYT_-Zo

Source snippet

Top 10 Most Dangerous Hackers Of All Time | Simplilearn...

17. Source: atomicarchive.com
Link:https://www.atomicarchive.com/resources/documents/deterrence/agreed-framework.html

18. Source: kujimedia.com
Link:https://www.kujimedia.com/articles/

19. Source: youtube.com
Title: The Man Who Hacked the U.S. Government
Link:https://www.youtube.com/watch?v=ND0zQX1rGdg

Source snippet

Hacking for UFOs and fighting for his life. Who is Gary McKinnon?...

20. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Blog Archive » THE SCHOOLBOY SPY. Sunday Times
Link:https://www.kujimedia.com/the-schoolboy-spy-sunday-times/

21. Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ

Source snippet

UK hacker's extradition to US blocked...

22. Source: intelligence.senate.gov
Title: hearings nro headquarters project august 10 1994
Link:https://www.intelligence.senate.gov/1994/08/10/hearings-nro-headquarters-project-august-10-1994/