Within Case Timeline

How 950 Passwords Deepened the Earle Intrusion

Prosecutors said McKinnon returned in June 2001 and obtained about 950 passwords, turning an earlier foothold into prolonged network access.

23 sources 3 graphics
Preview for How 950 Passwords Deepened the Earle Intrusion

On this page

  • The June 18 21 return visits
  • What the password files enabled
  • Why the alleged theft changed the case

Introduction

According to the United States indictment covering the Naval Weapons Station (NWS) Earle allegations, the alleged intrusion did not end with the initial access obtained in April 2001. Prosecutors argued that Gary McKinnon returned to the same network between 18 and 21 June 2001, using software previously installed on the system to obtain approximately 950 passwords stored on connected servers. This alleged credential theft transformed what had been a single compromise into a much broader and more persistent ability to re-enter the network.[Department of Justice]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

Password Theft illustration 1

The June activity became a key part of the prosecution’s narrative because it illustrated repeated access over time rather than an isolated break-in. Instead of relying on the original vulnerability alone, investigators alleged that McKinnon acquired credentials that could be reused to authenticate to multiple systems, laying the foundation for later access to the Earle network in September 2001.[Department of Justice]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

The June 18–21 Return Visits

The New Jersey indictment alleged that McKinnon first entered the Port Services computer at NWS Earle on 7 April 2001, installing the commercial remote-administration program RemotelyAnywhere on that machine and others connected to the network. Prosecutors claimed this software remained available for later use, allowing him to reconnect remotely without repeating the original compromise.[Department of Justice]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

The indictment then identified a separate period between 18 June and 21 June 2001. During these return visits, prosecutors alleged that McKinnon:

  • accessed the Port Services computer on several occasions through the internet;
  • used the previously installed RemotelyAnywhere software;
  • copied approximately 950 passwords stored on server computers connected to the Earle network.[Department of Justice]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

The charging documents present these June events as a distinct stage in the alleged intrusion. Rather than focusing on software installation or initial entry, this phase centred on collecting credentials that could be used across the wider network.

What the Password Files Enabled

The indictments do not suggest that the value of the June activity lay simply in the number of passwords copied. Instead, prosecutors argued that possession of those credentials fundamentally changed the nature of the intrusion.

In a Windows network of that period, administrative password files could provide authorised-looking access to multiple systems once the credentials were recovered or otherwise used. According to the government’s case, the stolen passwords reduced the need to exploit the original entry point repeatedly and enabled continued movement within the network.[Department of Justice]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

The broader Virginia indictment described a similar pattern across numerous military and NASA systems: once administrative access had been obtained, investigators alleged that McKinnon copied password files, installed remote-control software and then used compromised machines to locate additional targets. The Earle allegations fit that wider prosecution theory, but the New Jersey indictment uniquely specifies the June theft of approximately 950 passwords.[Department of Justice]justice.govDepartment of JusticeLondon, England Hacker Indicted Under Computer Fraud and Abuse Act For Accessing Military Computers (November 12, 2002)…Published: November 12, 2002

Password Theft illustration 2

Why the Alleged Theft Changed the Case

From the prosecution’s perspective, the June password theft was significant for three closely related reasons.

First, it demonstrated continuity. The alleged conduct showed that the April intrusion was not treated as a one-off event but as the beginning of repeated access over several months.[Department of Justice]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

Second, it established persistence. By alleging that McKinnon relied on previously installed remote-access software and stolen credentials, prosecutors portrayed him as maintaining an enduring foothold inside the network rather than repeatedly discovering fresh vulnerabilities.[Department of Justice]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

Third, it linked directly to the later allegations concerning 23 September 2001. The New Jersey indictment explicitly states that the September access was achieved by using the previously installed RemotelyAnywhere software together with the stolen passwords, making the June credential theft a central connecting event between the initial compromise and the later alleged network damage.[Department of Justice]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

The Place of the June Allegations in the Overall Evidence

The allegation concerning approximately 950 passwords appears consistently in the principal legal documents associated with the case. The New Jersey indictment identifies the June 18–21 period as the time when the passwords were allegedly obtained, while later judicial summaries in the extradition proceedings refer to McKinnon copying password files from multiple government computers, including approximately 950 passwords from servers at Naval Weapons Station Earle.[justice.gov]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

At the same time, it is important to distinguish between the allegations and matters tested in court. Because McKinnon’s extradition was ultimately halted and no US criminal trial took place, the prosecution’s account of how the June password theft occurred and how the credentials were subsequently used was never examined through a full criminal trial with witnesses and cross-examination. The indictments therefore remain formal allegations rather than judicial findings of guilt.[vLex]vlex.co.ukv Lex Mc Kinnon v United States of AmericaMcKinnon v United States of America - vLex United Kingdom…

Password Theft illustration 3

Amazon book picks

Further Reading

Books and field guides related to How 950 Passwords Deepened the Earle Intrusion. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromhacker t shirt oneBay.co.uk.

Endnotes

1. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict2.htm

Source snippet

Department of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N...

2. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict.htm

Source snippet

Department of JusticeLondon, England Hacker Indicted Under Computer Fraud and Abuse Act For Accessing Military Computers (November 12, 2002)...

Published: November 12, 2002

3. Source: justice.gov
Title: Attorney’s Office,
Link:https://www.justice.gov/usao-nj/pr/russian-national-charged-largest-known-data-breach-conspiracy-extradited-face-indictment

Source snippet

District of New Jersey | Russian National Charged in Largest Known Data Breach Conspiracy Extradited to Face Indictment in New Jersey | U...

4. Source: vlex.co.uk
Title: v Lex Mc Kinnon v United States of America
Link:https://vlex.co.uk/vid/mckinnon-v-united-states-793612009

Source snippet

McKinnon v United States of America - vLex United Kingdom...

5. Source: vlex.co.uk
Title: v Lex Mc Kinnon v United States of America
Link:https://vlex.co.uk/vid/mckinnon-v-usa-818719549

Source snippet

McKinnon v United States of America - vLex United KingdomJuly 30, 2008 — 12 The 97 computers the appellant accessed were: 53 army compute...

Published: July 30, 2008

6. Source: GOV.UK
Title: latest on [gary mckinnon case]({{ ‘mc-kinnon-case/’ | relative_url }})
Link:https://www.gov.uk/government/news/latest-on-gary-mckinnon-case

Source snippet

on Gary McKinnon case - GOV.UKNovember 4, 2010 — LATEST ON GARY MCKINNON CASE Find out the latest position on the Glasgow-born systems ad...

Published: November 4, 2010

Additional References

7. Source: standard.co.uk
Link:https://www.standard.co.uk/hp/front/british-ufo-fan-in-biggest-us-military-hack-of-all-time-faces-60-years-in-jail-after-losing-extradition-fight-6892900.html

Source snippet

The StandardApril 13, 2012 — BRITISH UFO FAN IN 'BIGGEST US MILITARY HACK OF ALL TIME' FACES 60 YEARS IN JAIL AFTER LOSING EXTRADITION FI...

Published: April 13, 2012

8. Source: youtube.com
Link:https://www.youtube.com/watch?v=NngEZrsqRFs

Source snippet

The Most Dangerous File the Hacker Found on NASA Servers... (Aliens?!) covers background details regarding Gary McKinnon's military and N...

9. Source: computerworld.com
Link:https://www.computerworld.com/article/1564524/former-prosecutor-ufo-hack-looked-like-terrorist-attack.html

Source snippet

Former prosecutor: UFO hack looked like terrorist attack – ComputerworldAugust 7, 2008 — Image: Sharon Gaudin by Sharon Gaudin FORMER PRO...

Published: August 7, 2008

10. Source: theguardian.com
Link:https://www.theguardian.com/technology/2002/nov/13/hacking.internetcrime

11. Source: the-independent.com
Link:https://www.the-independent.com/news/uk/crime/briton-who-hacked-into-us-military-fights-extradition-225073.html

12. Source: youtube.com
Title: UK hacker to learn extradition fate
Link:https://www.youtube.com/watch?v=LEvGU1b4ysw

Source snippet

The Most Dangerous File the Hacker Found on NASA Servers... (Aliens?!)...

13. Source: youtube.com
Title: UK Hacker extradition to US blocked
Link:https://www.youtube.com/watch?v=Y5jtyps4oaY

Source snippet

Dan Bull - Free Gary [an open letter to the Home Secretary]...

14. Source: youtube.com
Title: Dan Bull
Link:https://www.youtube.com/watch?v=p6fYMzKvXxg

Source snippet

Nicholls Montgomery and Knowles on the Law of Extradition and...

15. Source: theguardian.com
Title: ‘Military computer hacker’ faces extradition to US | US news | The Guardian
Link:https://www.theguardian.com/world/2005/jun/08/usa.uk

16. Source: youtube.com
Link:https://www.youtube.com/watch?v=6Ka4l7jdeQw

Source snippet

UK Hacker extradition to US blocked...