Within Richard Pryce

How Stolen Passwords Spread the Rome Laboratory Breach

Password-capturing software on Rome Laboratory systems exposed contractor credentials that could be reused against additional organisations.

25 sources 3 graphics
Preview for How Stolen Passwords Spread the Rome Laboratory Breach

On this page

  • How network sniffers captured login details
  • Why contractor connections widened the damage
  • How reused credentials created a cascading breach

Introduction

The Rome Laboratory intrusion became far more damaging than a single compromise because the attackers did not stop after obtaining access to one network. Instead, they installed password-sniffing software that silently collected login credentials from legitimate users as they authenticated across connected systems. Those stolen credentials allowed the intruders to impersonate trusted researchers, administrators and contractors, extending the compromise into military, government, commercial and academic networks without needing to discover new software vulnerabilities each time. In the Datastream Cowboy case, this mechanism transformed one successful intrusion into a chain of secondary compromises, demonstrating how trust relationships between organisations could become a force multiplier for attackers rather than a security advantage.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Password Sniffers illustration 1

How Network Sniffers Captured Login Details

The critical tool in the Rome Laboratory incident was the network “sniffer”. In the context of the early Internet, a sniffer was a covert program designed to intercept network traffic and record authentication data passing across a local network. At the time, many common network services such as Telnet, FTP and remote login protocols transmitted usernames and passwords in plain text. Anyone controlling a system on the same network segment could therefore capture credentials simply by monitoring traffic.

The official Senate investigation described the Rome Laboratory sniffer as recording the first part of each new login session, including the destination system, username and password. These details were stored in hidden files that were difficult for ordinary system administrators to detect. The attackers later returned to retrieve the collected credentials and could then log in while appearing to be legitimate users.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Investigators found that the attackers did not install a single sniffer. Instead, they placed sniffers on seven compromised Rome Laboratory computers. Those seven installations ultimately exposed activity across approximately thirty laboratory systems and captured more than one hundred user accounts, dramatically increasing the attackers’ reach without requiring additional exploitation of software flaws.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Why Contractor Connections Widened the Damage

Rome Laboratory’s mission depended on extensive collaboration with universities, defence contractors and other government organisations. Researchers routinely authenticated from remote locations and accessed partner systems through trusted network connections. These everyday working practices created opportunities for credential theft.

Once the sniffers began collecting passwords, they did not distinguish between Air Force personnel and outside collaborators. If a contractor logged into Rome Laboratory before connecting to a company network or home workstation, the credentials needed for those additional systems could also be exposed. The value of the stolen passwords therefore extended well beyond the laboratory itself.

Contemporary investigative accounts describe one particularly significant example. A defence contractor authenticated through Rome Laboratory, allowing the attackers to capture credentials that were later reused against the contractor’s own systems in California and Texas. Because the attackers logged in using genuine credentials rather than exploiting new vulnerabilities, they could masquerade as authorised users and compromise multiple contractor computers with comparatively little additional effort.[Kujimedia]kujimedia.comKuji Media Corporation Ltd. » Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter SixJune 26, 2008…Published: June 26, 2008

This illustrated a broader security weakness that was common during the period: organisations often trusted authenticated users from partner institutions, while password reuse across related systems made one successful credential theft valuable in many different environments.

Password Sniffers illustration 2

How Reused Credentials Created a Cascading Breach

The Rome Laboratory case demonstrated that stolen passwords could become stepping stones rather than end goals.

After compromising user accounts, investigators concluded that the attackers:

  • Logged into additional Rome Laboratory systems using legitimate credentials.
  • Installed further sniffers to harvest even more passwords.
  • Used compromised Air Force machines as trusted launching points for attacks elsewhere.
  • Accessed military, government, contractor and research systems that accepted the captured credentials or trusted connections originating from Rome Laboratory.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Each newly compromised machine increased the pool of available credentials, allowing the attack to expand in a self-reinforcing cycle. Instead of repeatedly breaking through perimeter defences, the intruders increasingly relied on authentic identities stolen from previous victims.

This cascading effect explains why investigators regarded the sniffers as one of the most dangerous aspects of the incident. The password-capture software was not merely a surveillance tool; it became the mechanism that enabled lateral movement across interconnected organisations.

Why the Attack Was Difficult to Detect

Credential theft through sniffers was especially effective because successful logins generated little immediate suspicion. A system administrator reviewing authentication logs would often see valid usernames entering from expected locations or from trusted Air Force systems, making malicious activity difficult to distinguish from legitimate work.

The official investigation also noted that the sniffer files themselves were deliberately hidden. In the Rome Laboratory incident, the compromise was discovered only after one sniffer generated enough captured data to fill a disk and trigger a system failure, drawing administrators’ attention to the infected machine. Without that operational problem, the credential collection might have continued for much longer.[Kujimedia]kujimedia.comKuji Media Corporation Ltd. » Datastream CowboyKuji Media Corporation Ltd. » Datastream CowboyJune 26, 2008…Published: June 26, 2008

Because the attackers combined stolen credentials with indirect routing through commercial Internet providers and international telephone networks, investigators faced two separate challenges: identifying who possessed valid passwords and tracing the true origin of the connections. Both factors slowed attribution while allowing additional compromises to occur.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Password Sniffers illustration 3

The Lasting Security Lesson

Within the broader Richard Pryce and Datastream Cowboy case, the password-sniffer component proved more significant than any single intrusion into Rome Laboratory itself. It demonstrated that the greatest damage often came not from the initial break-in but from the theft of trusted identities.

The incident became an influential example in later congressional discussions about Department of Defense information security because it showed how one compromised research network could expose partner organisations through shared credentials and trusted relationships. The lesson remains relevant today: protecting passwords, limiting credential reuse, encrypting authentication traffic and restricting privileged access are often more effective at preventing cascading compromises than focusing solely on the first point of entry.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…

Amazon book picks

Further Reading

Books and field guides related to How Stolen Passwords Spread the Rome Laboratory Breach. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromUFO disclosure print oneBay.co.uk.

Endnotes

1. Source: kujimedia.com
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/

Source snippet

Kuji Media Corporation Ltd. » Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter SixJune 26, 2008...

Published: June 26, 2008

2. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Datastream Cowboy
Link:https://www.kujimedia.com/tag/datastream-cowboy/

Source snippet

Kuji Media Corporation Ltd. » Datastream CowboyJune 26, 2008...

Published: June 26, 2008

3. Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/the-schoolboy-spy-sunday-times/

Source snippet

» Blog Archive » THE SCHOOLBOY SPY. Sunday TimesJune 26, 2008 — He was also planting “sniffer files” to pick up every password used in th...

Published: June 26, 2008

4. Source: intelligence.senate.gov
Title: hearings congressional notification september 5 1996
Link:https://www.intelligence.senate.gov/1996/09/05/hearings-congressional-notification-september-5-1996/

5. Source: kujimedia.com
Link:https://www.kujimedia.com/articles/

6. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

7. Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm

Source snippet

Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...

8. Source: congress.gov
Title: ASSESSIN G ANTHRAX DETECTION METHODS | Congress.gov | Library of Congress
Link:https://www.congress.gov/event/109th-congress/house-event/LC13317/text

Source snippet

ASSESSING ANTHRAX DETECTION METHODS | Congress.gov | Library of CongressApril 5, 2005 — laboratories, but the laboratory, to answer your...

Published: April 5, 2005

9. Source: congress.gov
Link:https://www.congress.gov/event/106th-congress/senate-event/LC19196/text

Source snippet

106-1040 — CONTINUATION OF OVERSIGHT OF THE WEN HO LEE CASE | Congress.gov | Library of CongressSeptember 27, 2000 — spoke to Secretary R...

Published: September 27, 2000

10. Source: congress.gov
Title: house report
Link:https://www.congress.gov/committee-report/104th-congress/house-report/874

Source snippet

Rept. 104-874 - ACTIVITIES OF THE HOUSE COMMITTEE ON GOVERNMENT REFORM AND OVERSIGHT ONE HUNDRED FOURTH CONGRESS FIRST AND SECOND SESSION...

11. Source: gao.gov
Title: b 270259
Link:https://www.gao.gov/products/b-270259

Additional References

12. Source: youtube.com
Title: The Untold Story of Gary Mc Kinnon: Biggest Military Hack Ever!
Link:http://www.youtube.com/watch?v=-_tzaIKGnYw

Source snippet

how Hackers SNiFF (capture) network traffic // MiTM attack...

13. Source: ojp.gov
Link:https://www.ojp.gov/ncjrs/virtual-library/abstracts/clandestine-laboratory-operators

14. Source: youtube.com
Title: how Hackers SNi FF (capture) network traffic // Mi TM attack
Link:http://www.youtube.com/watch?v=-rSqbgI7oZM

Source snippet

How Hackers Steal Passwords: 5 Attack Methods Explained...

15. Source: nist.gov
Title: temreverberating chamber electromagnetic radiation test facility rome laboratory
Link:https://www.nist.gov/publications/temreverberating-chamber-electromagnetic-radiation-test-facility-rome-laboratory

16. Source: youtube.com
Title: Matthew Bevan y Richard Pryce- Hackers Famosos
Link:http://www.youtube.com/watch?v=A0sCmWAUaZo

Source snippet

The Untold Story of Gary McKinnon: Biggest Military Hack Ever...

17. Source: all.net
Link:https://all.net/books/iw/iwarstuff/www.af.mil/news/airman/0496/hacker.htm

18. Source: youtube.com
Title: How Hackers Steal Passwords: 5 Attack Methods Explained
Link:http://www.youtube.com/watch?v=vKPGZHoHX8k

Source snippet

Gary Mckinnon: The Hacker Who Found UFOs...

19. Source: youtu.be
Link:https://youtu.be/RWOPezHfZuM

Source snippet

Cyber Pross...

20. Source: youtube.com
Title: Gary Mckinnon: The Hacker Who Found UFOs
Link:http://www.youtube.com/watch?v=8_1DuqeU8hw

Source snippet

Matthew Bevan y Richard Pryce- Hackers Famosos...

21. Source: ieee-security.org
Title: GA O Reports Do D SBU Computer Security Inadequate
Link:https://www.ieee-security.org/Cipher/Newsbriefs/1996/960522.GAOrept.html