Within British Connection
How One Rome Breach Opened Wider Defence Networks
Compromised accounts, sniffers and trusted network links let the attackers use one vulnerable system as a route into a wider defence environment.
On this page
- How stolen credentials enabled further access
- How sniffers and Trojan horses extended control
- Why trusted connections multiplied the danger
Page outline Jump by section
Introduction
The 1994 Rome Laboratory intrusion became a landmark cyber-security case not simply because attackers entered a sensitive US Air Force research facility, but because they demonstrated how one compromised system could become a launching point into a much wider network of military, government and commercial organisations. Rather than treating Rome Laboratory as a final target, the intruders turned it into a trusted platform for further attacks by harvesting passwords, installing covert software and exploiting existing trust relationships between connected systems. This mechanism—now commonly described as network pivoting or lateral movement—helped reshape how defence organisations understood cyber risk. The lesson was clear: securing individual computers was insufficient if a single breach could provide access to an entire connected environment.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…
How stolen credentials enabled further access
The attackers’ most valuable achievement was not merely gaining entry to Rome Laboratory but acquiring legitimate user credentials. Investigators found that they installed password-sniffing programs designed to capture usernames and passwords as authorised users logged into networked systems. Because the captured credentials belonged to genuine users, later activity could appear to originate from trusted personnel rather than obvious intruders.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
This dramatically expanded the attackers’ reach. Once valid credentials had been collected, they no longer needed to exploit the original vulnerability repeatedly. Instead, they authenticated as legitimate users across connected computers, allowing them to:
- access additional research systems;[cyber.tap.purdue.edu]cyber.tap.purdue.eduhackers of the 90sHe and Bevan became good friends via e-mail never revealing their real identity to one another. Whi…
- move between hosts without attracting immediate suspicion;
- read and copy sensitive files; and
- establish persistent access that survived the initial compromise.
The Senate Permanent Subcommittee on Investigations reported that seven sniffer programs ultimately compromised more than 100 user accounts, illustrating how a relatively small number of malicious programs could rapidly multiply an attacker’s privileges across an interconnected environment.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
How sniffers and Trojan horses extended control
The Rome Laboratory incident demonstrated the complementary roles of two common attack techniques of the era.
Sniffers harvested trust
A network sniffer quietly monitored network traffic, capturing credentials as users authenticated. Because many protocols of the early internet transmitted passwords without modern encryption, sniffers could collect valuable login information simply by observing communications across the network.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
The compromise therefore became self-reinforcing. Every additional user who logged into an infected system potentially supplied another credential that could be reused elsewhere.
Trojan horses created lasting access
Investigators also found Trojan horse programs installed on compromised systems. Unlike a sniffer, which primarily gathered information, a Trojan horse allowed attackers to maintain concealed access or execute commands later without repeating the original intrusion process. According to the Government Accountability Office (GAO), the attackers used both sniffers and Trojan horses to access and control Rome Laboratory’s operational network while establishing hidden methods of returning after the initial breach.[Justia GAO Reports]gao.justia.comGAO Reports United States General Accounting OfficeJustia GAO ReportsUnited States General Accounting OfficeFebruary 28, 2025…
The combination was particularly effective:
- sniffers collected new credentials;
- Trojan horses maintained covert access;
- compromised accounts enabled movement to additional machines; and
- each newly compromised machine could itself become another collection point.
Rather than a single isolated intrusion, the attack evolved into a chain of interconnected compromises.
Why trusted connections multiplied the danger
Rome Laboratory collaborated extensively with universities, defence contractors and research organisations. Those legitimate relationships, essential for scientific collaboration, also expanded the potential attack surface. Once attackers appeared to be authorised Rome users, trusted network relationships could work in their favour instead of acting as barriers.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…
Investigators found that the intruders used Rome Laboratory as an internet launching platform against numerous other military, government, commercial and academic systems. The Senate investigation described how compromised Rome systems became stepping stones from which attackers installed additional sniffers, captured more credentials and downloaded data from newly penetrated organisations.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
One example highlighted during the investigation involved aerospace contractors whose credentials were captured through the Rome compromise. When those contractors later connected to their own home or company systems, the attackers reused the harvested credentials to masquerade as authorised users, extending the compromise beyond the Air Force laboratory itself.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
This was a critical shift in understanding cyber risk. The primary danger no longer lay in a single vulnerable computer but in the network relationships surrounding it.
Pivoting through intermediate systems
The attackers also complicated the investigation by routing their activity through numerous intermediary systems before reaching Rome Laboratory. According to the GAO, they traversed international telephone switches and commercial internet providers rather than connecting directly to their target. This routing concealed their true origin while making forensic reconstruction far more difficult.[Justia GAO Reports]gao.justia.comGAO Reports United States General Accounting OfficeJustia GAO ReportsUnited States General Accounting OfficeFebruary 28, 2025…
Once inside Rome Laboratory, they effectively repeated the same strategy in reverse. Instead of treating Rome as the destination, they treated it as another intermediary node from which to attack further organisations. Modern cyber-security terminology describes this as pivoting—using one compromised system to gain access to others that would otherwise be unreachable.
The Rome Laboratory case is one of the clearest early public demonstrations of this technique against a major defence research environment.
Why the mechanism mattered beyond Rome Laboratory
Within the broader history of British intrusions into American defence networks—including cases later associated with UFO-related motivations such as Mathew Bevan and, years afterwards, Gary McKinnon—the Rome Laboratory incident stands out because it exposed a systemic weakness rather than a single security failure.
The investigation showed that:
- compromised credentials were often more valuable than the original exploit;
- trusted relationships between organisations could unintentionally extend an attacker’s reach;
- password capture could rapidly multiply access across connected networks; and
- defenders needed to monitor lateral movement inside networks, not simply prevent initial entry.
These lessons influenced later defence thinking about authentication, network segmentation, intrusion detection and the dangers of assuming that activity originating from a trusted internal system was necessarily legitimate. The Rome Laboratory breach therefore became significant not only for what was stolen, but for demonstrating how one successful compromise could cascade into many others through inherited trust and reused credentials.[fas.org]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…
Amazon book picks
Further Reading
Books and field guides related to How One Rome Breach Opened Wider Defence Networks. Use these as the next step if you want deeper reading beyond the article.
The Practice of Network Security Monitoring
Network security is not simply about building impenetrable walls—determined attackers will eventually overcome traditional defenses. The...
The Web Application Hacker's Handbook
This book is a practical guide to discovering and exploiting security flaws in web applications. The authors explain each category of vul...
Cyber War
Rating: 3.0/5 from 96 Google Books ratings
An essential, eye-opening book about cyberterrorism, cyber war, and the next great threat to our national security. " Cyber War may be th...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromcybersecurity t shirt oneBay.co.uk.
Endnotes
1.
Source: gao.justia.com
Title: GAO Reports United States General Accounting Office
Link:https://gao.justia.com/department-of-defense/1996/5/information-security-aimd-96-84/AIMD-96-84-full-report.pdf
Source snippet
Justia GAO ReportsUnited States General Accounting OfficeFebruary 28, 2025...
Published: February 28, 2025
2.
Source: files.gao.gov
Link:https://files.gao.gov/reports/GAO-26-107668/index.html
Source snippet
gao.govGAO-26-107668, TELECOMMUNICATIONS: Selected Agencies Have Taken Steps to Address Risks of Equipment Linked to ChinaMay 19, 2026 —...
Published: May 19, 2026
3.
Source: gao.justia.com
Title: information security aimd 96 84
Link:https://gao.justia.com/department-of-defense/1996/5/information-security-aimd-96-84/
4.
Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm
Source snippet
Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996...
Published: May 22, 1996
5.
Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm
Source snippet
Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion...
Additional References
6.
Source: youtube.com
Title: Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub
Link:https://www.youtube.com/watch?v=z7OjzYT_-Zo
Source snippet
Rome Laboratory hack 1994 How to rescue secret Bloodborne character in Astro’s Playroom 🤖 #astrosplayroom PlayStation Access...
7.
Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/tag/datastream-cowboy/
Source snippet
» Datastream CowboyJune 26, 2008 — Air Force’s premier command-and- control research facility. Rome Lab researchers collaborate with univ...
Published: June 26, 2008
8.
Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/
Source snippet
» Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter SixJune 26, 2008 — The sysadmins informed the Defense In...
Published: June 26, 2008
9.
Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/the-schoolboy-spy-sunday-times/
Source snippet
» Blog Archive » THE SCHOOLBOY SPY. Sunday TimesJune 26, 2008 — “I used to get software off the bulletin boards and from one of them I go...
Published: June 26, 2008
10.
Source: cyber.tap.purdue.edu
Title: hackers of the 90s
Link:https://cyber.tap.purdue.edu/blog/articles/hackers-of-the-90s/
Source snippet
He and Bevan became good friends via e-mail never revealing their real identity to one another. Whi...
11.
Source: youtube.com
Title: A Tale of Two UFO Hackers: Matthew Bevan & Gary Mc Kinnon | True Crime
Link:https://www.youtube.com/watch?v=rksYZZgSPcY
Source snippet
Gary Mckinnon: The Hacker Who Found UFOs...
12.
Source: youtube.com
Title: UFO Hacker Gary Mc Kinnon talks about NASA Hack
Link:https://www.youtube.com/watch?v=ZKfKIUXhqSM
Source snippet
Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub...
13.
Source: legistorm.com
Link:https://www.legistorm.com/reports/view/gao/26571/Computer_Attacks_at_Department_of_Defense_Pose_Increasing_Risks.html
14.
Source: youtube.com
Title: Gary Mckinnon: The Hacker Who Found UFOs
Link:https://www.youtube.com/watch?v=8_1DuqeU8hw
Source snippet
UFO Hacker Gary McKinnon talks about NASA Hack...
15.
Source: youtube.com
Title: The Kuji Interview
Link:https://www.youtube.com/watch?v=bHtItL-lNAE
Source snippet
A Tale of Two UFO Hackers: Matthew Bevan & Gary McKinnon | True Crime...


