Within Mathew Bevan
What the Official Record Actually Proves
Government records verify repeated network penetrations, stolen credentials and costly disruption, but they do not verify any Roswell discovery.
On this page
- The documented scale of the intrusions
- Systems reached through compromised networks
- Claims absent from official investigations
Page outline Jump by section
Introduction
Official investigations into Mathew Bevan’s hacking campaign establish a clear distinction between documented computer intrusions and later claims about UFO-related discoveries. United States government records confirm that Bevan, using the handle “Kuji”, participated in repeated unauthorised penetrations of sensitive military research networks during 1994. Those records describe stolen credentials, compromised systems, significant operational disruption and costly recovery efforts. They do not, however, conclude that the intrusions uncovered evidence connected to Roswell, recovered extraterrestrial technology or any comparable claim. The official record therefore supports the reality and seriousness of the hacking campaign while leaving Bevan’s later interpretation of what he believed he found entirely unverified.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…
The documented scale of the intrusions
The most authoritative public descriptions of the attacks come from the US General Accounting Office (now the Government Accountability Office), congressional testimony, and Air Force reporting reproduced through official archives. These documents describe a sustained campaign against the Air Force’s Rome Laboratory during March and April 1994 rather than an isolated break-in. More than 150 separate intrusions were identified over roughly 26 days.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…
According to the GAO testimony, the attackers employed well-known techniques of the period, including Trojan horse programs and network “sniffers” that captured usernames and passwords travelling across military networks. By harvesting credentials rather than relying on a single vulnerability, they expanded their access beyond the initial target and maintained persistence inside affected systems.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
The official documents also describe the operational consequences. Investigators reported that the attackers temporarily seized control of parts of the Rome Laboratory network, forcing all 33 subnetworks offline while administrators restored trusted system states, installed security patches and verified that critical systems had not been altered. Air Force estimates placed the immediate recovery costs at more than US$500,000, excluding the potential value of any compromised research. Officials further noted that rebuilding one affected research project from scratch could have cost several million dollars if the data had proved irrecoverable.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
The records treat the incident primarily as a national security and information assurance failure. At the time, investigators could not determine with certainty whether the stolen information had been retained, copied onward or supplied to another party, leaving open concerns about possible intelligence value even though no evidence established foreign state direction.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
Systems reached through compromised networks
Official investigations show that Rome Laboratory was not the endpoint of the campaign. Once inside the Air Force network, the attackers used compromised credentials and trusted connections to pivot into additional organisations.
Government testimony specifically identifies access attempts or successful intrusions involving:
- NASA’s Goddard Space Flight Center.
- Wright-Patterson Air Force Base.[archives.gov]archives.govProject BLUE BOOKProject BLUE BOOK
- Defence contractors.
- Other interconnected military and research systems reachable through trusted network relationships.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
This pattern is important because it explains why Wright-Patterson later became associated with Bevan’s Roswell narrative. The official documents confirm that systems linked to Wright-Patterson were reached through the broader intrusion campaign. They do not suggest that Wright-Patterson itself was singled out because investigators believed it contained UFO material. Instead, the records portray the base as one of several connected organisations exposed through compromised military networks.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
The investigations also document how difficult attribution remained in the mid-1990s. The attackers routed connections through numerous intermediate systems and international telephone exchanges before reaching US targets, complicating efforts to identify those responsible. This became one of the case studies later cited by government agencies when arguing that internet-based attacks could conceal an attacker’s true location and intent.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…
Claims absent from official investigations
The most significant limitation of the official record is what it does not say.
Neither the GAO reports, congressional testimony, nor publicly released Air Force accounts state that investigators recovered evidence of files concerning Roswell, recovered alien technology, anti-gravity propulsion or any comparable subject. Their focus remains on network compromise, stolen military research, incident response and weaknesses in Department of Defense cybersecurity.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
Bevan later described accessing material that he personally interpreted as relating to advanced propulsion technology, connecting it with long-standing stories about Wright-Patterson Air Force Base and the alleged Roswell crash. Those statements originated from Bevan himself and were not corroborated by forensic evidence preserved in the official investigations. No publicly released investigative report identifies the files he described, confirms their contents or concludes that such material existed on the systems involved.
The contrast is especially notable because the US government separately conducted formal inquiries into Roswell during the 1990s. Those inquiries searched government records relating to the 1947 incident and discussed record preservation, archival evidence and alleged secret documents, but they did not identify evidence supporting recovered extraterrestrial technology. Consequently, there is no official bridge connecting Bevan’s hacking case with any verified Roswell discovery.[GAO]gao.govnsiadGovernment Records: Results of a Search for Records Concerning the 1947 Crash Near Roswell, New Mexico | U.S. GAOJuly 28, 1995…
What the official record actually proves
Taken together, the documentary evidence supports several conclusions with a high degree of confidence.
Proven by official records:
- Bevan participated in repeated unauthorised intrusions into US military computer systems.
- The campaign relied on stolen credentials, Trojan horses and password-sniffing software.
- Sensitive defence research networks were compromised.
- Wright-Patterson Air Force Base was among the organisations reached through the compromised networks.
- The attacks caused substantial operational disruption and significant financial recovery costs.
- The incident became an influential early case in US government thinking about network security and cyber defence.[gwu.edu]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
Not established by official records:
- That Bevan discovered evidence of Roswell.
- That investigators recovered files proving extraterrestrial technology.
- That any government inquiry validated Bevan’s interpretation of the material he claimed to have seen.
- That the hacking campaign uncovered evidence supporting UFO-related conspiracy theories.[gwu.edu]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
For historians of UFO-motivated hacking, this distinction is crucial. The official record documents one of the most significant military network intrusions of the early internet era, but it does not transform Bevan’s later Roswell interpretation into verified fact. The evidence confirms the hacking campaign itself; the alleged UFO discovery remains an uncorroborated personal claim rather than an official finding.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
Amazon book picks
Further Reading
Books and field guides related to What the Official Record Actually Proves. Use these as the next step if you want deeper reading beyond the article.
The Cuckoo's Egg
This is the true story of how a systems manager at Lawrence Berkeley Lab singlehandedly tracked down and helped capture a computer hacker...
The Hacker Crackdown
The bestselling cyberpunk author "has produced by far the most stylish report from the computer outlaw culture since Steven Levy's Hacker...
The Demon-Haunted World
NEW YORK TIMES BESTSELLER • From the renowned astronomer and author of Cosmos comes a “powerful [and] stirring defense of informed ration...
UFOs and Government
Governments around the world have had to deal with the UFO phenomenon for a good part of a century. How and why they did so is the subjec...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromUFO memorabilia oneBay.co.uk.
Endnotes
1.
Source: gao.gov
Title: nsiad 95 187
Link:https://www.gao.gov/products/nsiad
Source snippet
Government Records: Results of a Search for Records Concerning the 1947 Crash Near Roswell, New Mexico | U.S. GAOJuly 28, 1995...
Published: July 28, 1995
2.
Source: gao.gov
Title: [Comments on Majestic 12 Material] | U.S. GAO
Link:https://www.gao.gov/products/154832
Source snippet
GAO[Comments on Majestic 12 Material] | U.S. GAO...
3.
Source: files.gao.gov
Link:https://files.gao.gov/reports/GAO-26-107544/index.html
4.
Source: archives.gov
Title: Project BLUE BOOK
Link:https://www.archives.gov/research/military/air-force/ufos
5.
Source: gao.gov
Title: 18 197t
Link:https://www.gao.gov/products/gao-18-197t
6.
Source: gao.gov
Link:https://www.gao.gov/products/gao
7.
Source: gao.gov
Link:https://www.gao.gov/products/gao-16-871t
8.
Source: archives.gov
Link:https://www.archives.gov/iwg/declassified-records/rg-226-oss/rg-226-disclosure-act-documents.html
9.
Source: archives.gov
Link:https://www.archives.gov/press/press-releases/2007/nr07-143
10.
Source: gao.gov
Link:https://www.gao.gov/products/t-aimd
11.
Source: gao.gov
Title: rced 89 31
Link:https://www.gao.gov/products/rced
12.
Source: gao.gov
Title: rced 83 108
Link:https://www.gao.gov/products/rced
13.
Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm
Source snippet
Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996...
Published: May 22, 1996
14.
Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr
15.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a
Source snippet
National Security ArchiveGovernment Accounting Office, GAO/AIMD- 96-84, Information Security: Computer Attacks at Department of Defense P...
16.
Source: nsarchive2.gwu.edu
Title: National Security Archive Cyberwarfare
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/docs/Cyber-014.pdf
17.
Source: nationalarchives.gov.uk
Link:https://www.nationalarchives.gov.uk/news/document-releases/latest-release-of-files-from-mi5/
Source snippet
Latest release of files from MI5 - The National ArchivesJanuary 14, 2025 — LATEST RELEASE OF FILES FROM MI5 Today we have made available...
Published: January 14, 2025
18.
Source: nsarchive.gwu.edu
Title: cybersecurity when hackers went hill revisiting l0pht hearings 1998
Link:https://nsarchive.gwu.edu/briefing-book/cyber-vault/2019-01-09/cybersecurity-when-hackers-went-hill-revisiting-l0pht-hearings-1998
19.
Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/
20.
Source: irp.fas.org
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm
21.
Source: nsarchive.gwu.edu
Title: 21407 document 10b
Link:https://nsarchive.gwu.edu/document/21407-document-10b
22.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/index.php/document/28379-document-21-wendell-l-bevan-director-special-activities-cia-memorandum-deputy
23.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/28379-document-21-wendell-l-bevan-director-special-activities-cia-memorandum-deputy
24.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/
25.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/search?page=85&s=cost+of+fc+coins+Visit+Buyfc26coins.com+Kedvezm%C3%A9nyek+t%C3%B6meges+v%C3%A1s%C3%A1rl%C3%A1sokra..JHrE
26.
Source: nationalarchives.gov.uk
Title: Amanda Bevan
Link:https://www.nationalarchives.gov.uk/people/amanda-bevan/
Additional References
27.
Source: youtube.com
Link:https://www.youtube.com/watch?v=Itopz-raZSY
Source snippet
Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub...
28.
Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon? | Nord VPN
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ
Source snippet
Ancient Aliens: Hacking NASA Secrets (Season 12, Episode 9) | History...
29.
Source: youtube.com
Title: Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub
Link:https://www.youtube.com/watch?v=z7OjzYT_-Zo
Source snippet
Hacking for UFOs and fighting for his life. Who is Gary McKinnon? | NordVPN...
30.
Source: youtube.com
Title: UFO Hackers Claim Government Coverup | Thom Hastings
Link:https://www.youtube.com/watch?v=Knj9TplZ158
Source snippet
Top 10 Most Dangerous Hackers Of All Time | Top 10 Hackers In The World | Simplilearn...
31.
Source: publications.parliament.uk
Link:https://publications.parliament.uk/pa/jt5901/jtselect/jtnatsec/1414/report.html
Source snippet
cases and the Official Secrets ActsDecember 3, 2025 — ESPIONAGE CASES AND THE OFFICIAL SECRETS ACTS This is a Joint Committee report, wit...
Published: December 3, 2025
32.
Source: gao.justia.com
Link:https://gao.justia.com/department-of-justice/2001/6/fbi-official-s-congressional-testimony-was-inaccurate-because-he-failed-to-present-certain-information-that-had-been-made-available-to-him-about-the-wen-ho-lee-investigation-gao-01-869r
33.
Source: gao.justia.com
Title: justice s handling of alleged disclosure retaliation osi 96 7r
Link:https://gao.justia.com/department-of-justice/1996/9/justice-s-handling-of-alleged-disclosure-retaliation-osi-96-7r/
34.
Source: youtube.com
Title: Ancient Aliens: Hacking NASA Secrets (Season 12, Episode 9) | History
Link:https://www.youtube.com/watch?v=20rWFDfh68Y
35.
Source: ieee-security.org
Title: GA O Reports Do D SBU Computer Security Inadequate
Link:https://www.ieee-security.org/Cipher/Newsbriefs/1996/960522.GAOrept.html
36.
Source: justice.gov
Title: Manual | 9-5.000
Link:https://www.justice.gov/jm/jm-9-5000-issues-related-trials-and-other-court-proceedings


