Within Rome Laboratory

Why Stolen Logins Mattered More Than the First Hack

Sniffers on seven Rome systems captured usernames and passwords that attackers reused to enter dozens of machines as legitimate users.

18 sources 3 graphics
Preview for Why Stolen Logins Mattered More Than the First Hack

On this page

  • How network sniffers captured credentials
  • Why reused passwords defeated the perimeter
  • How trusted accounts enabled lateral movement

Introduction

The decisive step in the 1994 Rome Laboratory intrusion was not simply gaining an initial foothold but turning ordinary user accounts into a reliable means of expansion. After compromising seven systems, the attackers installed network password sniffers that silently captured usernames and passwords as legitimate users logged in. Those stolen credentials allowed the intruders to authenticate as trusted researchers, administrators and contractors, making subsequent access appear legitimate rather than obviously malicious. Official investigations concluded that the sniffers compromised more than 100 user accounts and enabled access to around 30 Rome Laboratory systems before the attackers pivoted into connected military, government and contractor networks.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Password Sniffers illustration 1

This mechanism mattered because the network’s trust relationships became more valuable than the original compromise. Instead of repeatedly exploiting software flaws, the attackers increasingly relied on valid credentials, demonstrating how intercepted passwords could defeat a strong perimeter once an attacker was already inside.

How network sniffers captured credentials

A network sniffer is a program that observes traffic flowing across a network interface. On many institutional networks in the early 1990s, usernames and passwords were routinely transmitted in plain text through protocols such as Telnet, FTP and remote shell services. Anyone with sufficient access to a shared network segment could quietly record those authentication exchanges.

According to the US Senate Permanent Subcommittee on Investigations, the Rome Laboratory attackers installed sniffers on seven compromised systems. The software was designed to collect the beginning of each new login session, which typically contained both the destination system and the user’s login credentials. The captured information was stored in hidden files that the attackers later retrieved, allowing them to impersonate authorised users without needing to crack passwords or trigger repeated intrusion attempts.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The timing amplified the damage. Investigators determined that the attackers first penetrated Rome Laboratory on 23 March 1994, but the compromise was not detected until 28 March. During those five days, the sniffers operated continuously, collecting credentials from normal daily activity rather than forcing users into revealing passwords through deception or brute force.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Why reused passwords defeated the perimeter

The sniffers became so effective because users authenticated to multiple systems with credentials that were either identical or trusted across connected environments. Once a password had been intercepted, the attackers no longer needed to bypass technical security controls on every additional machine.

Official investigators found that the seven sniffers ultimately compromised over 100 user accounts and enabled the attackers to take control of approximately 30 Rome Laboratory systems. Because every successful login appeared to originate from a genuine account using the correct password, many subsequent actions blended into ordinary network activity. User email was reportedly read, copied and deleted, while sensitive but unclassified research data was accessed through legitimate-looking sessions.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

This illustrates an important distinction between authentication and trust. The systems correctly verified the supplied usernames and passwords, but they had no practical way to distinguish between the real account holder and someone who had intercepted those credentials. The security boundary therefore shifted from the external firewall to the secrecy of individual passwords.

Password Sniffers illustration 2

How trusted accounts enabled lateral movement

The greatest operational advantage came after the attackers had accumulated enough valid credentials to move through the network as authorised users.

Rather than launching noisy attacks against each new target, they could:

  • Log into additional Rome Laboratory systems using genuine usernames and passwords.
  • Access files and email using the permissions already granted to legitimate users.
  • Install additional sniffers on newly compromised machines, increasing the pool of captured credentials.
  • Use Rome Laboratory itself as a trusted launching point for attacks against external organisations.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The Senate investigation documented that, after establishing control of Rome Laboratory systems, the attackers used them to attack military, commercial, academic and government networks worldwide. Because the traffic originated from a respected Air Force research facility and employed valid user accounts, distinguishing authorised activity from malicious activity became considerably more difficult.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

A particularly revealing example involved an aerospace contractor. Investigators reported that when contractor personnel connected from Rome Laboratory to their home systems, the sniffers recorded not only their usernames and passwords but also the addresses of those remote systems. The attackers later used those captured credentials to masquerade as the contractors and compromise multiple contractor computers in California and Texas. The compromise therefore propagated through trust relationships rather than through repeated exploitation of software vulnerabilities.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Why stolen credentials were more valuable than the first compromise

The Rome Laboratory incident demonstrated that the initial intrusion created opportunity, but stolen credentials created persistence and scale.

Trojan horse programs and other intrusion techniques gave the attackers their first foothold, yet the sniffers transformed that limited access into broad operational control. Once enough legitimate credentials had been collected, the attackers no longer depended on exploiting additional technical weaknesses. Every successful login reinforced the appearance that authorised users were carrying out routine work.[GAO]gao.govUnited States General Accounting OfficeUnited States General Accounting OfficeNovember 20, 2024…Published: November 20, 2024

This explains why official reviews consistently highlighted the sniffers as one of the defining features of the incident. The General Accounting Office concluded that the attackers used Trojan horses together with sniffers to access and control the operational network while masquerading as trusted users, illustrating how credential theft could undermine even sensitive defence research environments connected to wider networks.[GAO]gao.govUnited States General Accounting OfficeUnited States General Accounting Office…

Password Sniffers illustration 3

The lasting security lesson

Although the Rome Laboratory intrusion occurred in 1994, its central lesson remains relevant. Modern enterprise networks encrypt authentication traffic far more extensively than those of the early Internet, making classic network password sniffing much less effective. However, the underlying principle has not changed: once attackers obtain legitimate credentials—whether through malware, phishing, token theft or other means—they often bypass perimeter defences by appearing to be authorised users.

The Rome Laboratory case became an early demonstration that credential theft can be more strategically valuable than the initial compromise itself. The attackers did not need to defeat every connected organisation independently. By collecting trusted logins and reusing them, they converted one successful intrusion into a chain of authenticated access across dozens of systems, exposing the weakness of relying on passwords alone as the foundation of network trust.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Amazon book picks

Further Reading

Books and field guides related to Why Stolen Logins Mattered More Than the First Hack. Use these as the next step if you want deeper reading beyond the article.

BookCover for The Art of Deception

The Art of Deception

By Kevin D. Mitnick, William L. Simon

The world's most infamous hacker offers an insider's view of the low-tech threats to high-tech security Kevin Mitnick's exploits as a cyb...

eBay marketplace picks

Marketplace Samples

Example marketplace items related to this page. Use the search link to explore similar finds on eBay.

UsingUSA

Selected fromUFO decal oneBay.co.uk.

Endnotes

1. Source: gao.gov
Title: United States General Accounting Office
Link:https://www.gao.gov/assets/aimd-96-84.pdf

Source snippet

United States General Accounting Office...

2. Source: gao.gov
Title: United States General Accounting Office
Link:https://www.gao.gov/assets/t-aimd-96-92.pdf

Source snippet

United States General Accounting OfficeNovember 20, 2024...

Published: November 20, 2024

3. Source: jec.senate.gov
Link:https://www.jec.senate.gov/archive/Documents/Hearings/cross22300.htm

Source snippet

Steve CrossFebruary 23, 2000 — The sniffer program records many kinds of information for later retrieval by the intruder. Of specific int...

Published: February 23, 2000

4. Source: intelligence.senate.gov
Title: Hrg. 103-997 Download
Link:https://www.intelligence.senate.gov/1994/08/10/hearings-nro-headquarters-project-august-10-1994/

Source snippet

Headquarters Project (August 10, 1994) | Senate Select Committee on IntelligenceAugust 10, 1994 — NRO HEADQUARTERS PROJECT (AUGUST 10, 19...

Published: August 10, 1994

5. Source: intelligence.senate.gov
Title: hearings counterintelligence may 3 1994
Link:https://www.intelligence.senate.gov/1994/05/03/hearings-counterintelligence-may-3-1994/

Source snippet

(May 3, 1994) | Senate Select Committee on IntelligenceMay 3, 1994 — COUNTERINTELLIGENCE (MAY 3, 1994) Print 103rd Congress | All Hearing...

Published: May 3, 1994

6. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

7. Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm

Source snippet

Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...

8. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a

Source snippet

Unclassified. | National Security ArchiveMay 22, 1996 — GOVERNMENT ACCOUNTING OFFICE, GAO/AIMD- 96-84, INFORMATION SECURITY: COMPUTER ATT...

Published: May 22, 1996

Additional References

9. Source: gao.justia.com
Title: committee on governmental affairs osi 94 30
Link:https://gao.justia.com/national-aeronautics-and-space-administration/1994/7/committee-on-governmental-affairs-osi

Source snippet

GAO Reports - OSI-94-30 - Committee on Governmental Affairs - National Aeronautics and Space AdministrationJuly 1, 1994 — COMMITTEE ON GO...

Published: July 1, 1994

10. Source: issues.org
Title: An Electronic Pearl Harbor?
Link:https://issues.org/smith-2/

Source snippet

Not LikelyOctober 1, 1998 — HACKERS AS NUISANCES What about the direct effects of system-hacking intruders? To examine this issue, it is...

Published: October 1, 1998

11. Source: nsarchive.gwu.edu
Title: 21407 document 10b
Link:https://nsarchive.gwu.edu/document/21407-document-10b

Source snippet

Brock, General Accounting Office, GAO/T-AIMD-96-92, Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...

12. Source: youtube.com
Title: Wireshark Packet Sniffing Usernames, Passwords, and Web Pages
Link:https://www.youtube.com/watch?v=r0l_54thSYU

Source snippet

Wireshark Tutorial - Installation and Password sniffing...

13. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/media/21407/ocr

Source snippet

BROCK, GENERAL ACCOUNTING OFFICE, GAO/T-AIMD-96-92, INFORMATION SECURITY: COMPUTER ATTACKS AT DEPARTMENT OF DEFENSE POSE INCREASING RISKS...

14. Source: youtube.com
Link:https://www.youtube.com/watch?v=V_FLyP-iqWg

Source snippet

Wireshark Packet Sniffing Usernames, Passwords, and Web Pages...

15. Source: pbs.org
Title: The Risks
Link:https://www.pbs.org/wgbh/pages/frontline/shows/hackers/risks/dodattacks.html

Source snippet

General Accounting Office, May 1996 GAO/AIMD-96-84 Defense Information Security, 1996 Image Image Image Image I...

Published: May 1996

16. Source: youtube.com
Title: Wireshark Tutorial
Link:https://www.youtube.com/watch?v=4_7A8Ikp5Cc

Source snippet

Packet Sniffing 101 - Ethical Hacking...

17. Source: youtube.com
Title: Packet Sniffing 101
Link:https://www.youtube.com/watch?v=y7_77KjSvdo

Source snippet

What is Packet Sniffing?...

18. Source: youtube.com
Title: What is Packet Sniffing?
Link:https://www.youtube.com/watch?v=5oioSbgBQ8I