Within British Connection
How a London Teen Reached Rome Laboratory
Pryce's exploration of Rome Laboratory systems shows how a teenage British hacker became central to a major US defence breach.
On this page
- How Pryce entered and moved through connected systems
- Why investigators first feared foreign espionage
- How his motives differed from Bevan's UFO search
Page outline Jump by section
Introduction
Richard Pryce, better known by the online handle Datastream Cowboy, played the central operational role in the 1994 intrusions into the United States Air Force’s Rome Laboratory. Although his name is often overshadowed by later British hacker Gary McKinnon or by his associate Mathew Bevan (“Kuji”), investigators concluded that Pryce carried out much of the technical penetration that transformed what initially appeared to be isolated break-ins into one of the most significant military cyber incidents of the early internet era. His activity demonstrated how a teenager in London could exploit weak authentication, move across interconnected defence networks and trigger fears that the United States was facing a foreign intelligence operation rather than an amateur hacker.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Within the wider story of British hackers targeting American defence systems, Pryce is important because his motivations differed markedly from those attributed to Bevan. Whereas Bevan became associated with searches for alleged hidden UFO information, Pryce’s documented interests centred on exploring computer systems, overcoming technical barriers and obtaining sensitive files rather than pursuing a sustained UFO-related agenda.[cyber.tap.purdue.edu]cyber.tap.purdue.eduHackers of the '90sHackers of the '90s
How Pryce entered and moved through connected systems
Rome Laboratory, located at Griffiss Air Force Base in New York, served as the Air Force’s principal research centre for command, control, communications and intelligence technologies. During March and April 1994, investigators recorded more than 150 separate intrusions attributed to Datastream Cowboy and the associated handle Kuji. Rather than attacking only one computer, Pryce exploited the trust relationships between connected systems to extend his access across military and civilian networks.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
According to official investigations, the attackers used techniques that were common in the hacker community but unusually effective against poorly defended government systems:
- They installed sniffer programs to capture usernames and passwords travelling across networks.
- They placed Trojan horse software that enabled repeated unauthorised access.
- They reused compromised credentials to pivot into additional military and research systems.
- They routed their connections through numerous intermediary computers across several countries, making attribution extremely difficult.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
This lateral movement proved more significant than the initial compromise itself. From Rome Laboratory, further intrusions reached systems belonging to organisations including NASA, Wright-Patterson Air Force Base and defence contractors. The incident illustrated how compromising one trusted node could expose an entire networked environment long before modern concepts such as zero-trust security became widespread.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
Why investigators first feared foreign espionage
One reason the Rome Laboratory case became historically significant was the uncertainty surrounding the attackers’ identity. During the early stages of the investigation, Air Force personnel could see sophisticated intrusion techniques but had no reliable way to determine whether they were confronting teenage hackers, organised criminals or a hostile intelligence service.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
The concern intensified when investigators observed stolen files from the Korea Atomic Energy Research Institute being copied through Rome Laboratory’s systems. Initially, officials were unsure whether the target belonged to North Korea or South Korea. Had it involved North Korea, the transfer might have appeared to originate from the United States Air Force itself, creating the possibility of a serious diplomatic or military misunderstanding. Later investigation established that the compromised system belonged to South Korea, removing the immediate geopolitical risk.[Air & Space Forces Magazine]airandspaceforces.comAir & Space Forces MagazineAt War With Sweepers, Sniffers, Trapdoors, and Worms | Air & Space Forces MagazineMarch 1, 1997…
The broader lesson for American defence planners was that the technical characteristics of the attack resembled what might be expected from state-sponsored espionage. Even after Pryce was identified, the Government Accountability Office noted that investigators could not initially rule out the possibility that one or more participants were collecting military research on behalf of a foreign government.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
How investigators identified Datastream Cowboy
Pryce’s identification did not result from advanced digital forensics alone. Instead, investigators combined technical monitoring with traditional investigative methods.
A breakthrough came when an informant supplied Air Force investigators with earlier email correspondence in which Datastream Cowboy described himself as a 16-year-old from the United Kingdom who enjoyed attacking “.mil” systems and even shared the telephone number for his bulletin board service. Working with New Scotland Yard, investigators linked the telephone number to Richard Pryce’s family home and monitored telephone activity. They observed repeated episodes of “phone phreaking”—manipulating telephone systems to obtain free international calls—that coincided with the timing of the Rome Laboratory intrusions.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
The investigation also reconstructed the complex routes Pryce used to disguise his location. Rather than connecting directly from London to New York, his sessions passed through systems in multiple countries before reaching Rome Laboratory, demonstrating techniques that would later become familiar in sophisticated cyber intrusions.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
How Pryce’s motives differed from Bevan’s UFO search
Although Richard Pryce and Mathew Bevan are frequently discussed together, available evidence suggests their motivations were not identical.
Bevan has consistently been associated with an interest in alleged government concealment of UFO information and other conspiracy theories, leading him to search military and research systems for related material. That interest forms an important link between the Rome Laboratory episode and later British UFO-oriented hacking cases such as Gary McKinnon’s.[cyber.tap.purdue.edu]cyber.tap.purdue.eduHackers of the '90sHackers of the '90s
Pryce, by contrast, has generally described his activities as a technical challenge. Contemporary interviews and later accounts portray him as fascinated by overcoming security barriers, downloading sensitive information and demonstrating access rather than pursuing evidence of extraterrestrial technology. He reportedly progressed from attacking university systems to military networks because they represented increasingly difficult targets.[Kujimedia]kujimedia.comKuji Media Corporation Ltd. » Blog Archive » THE SCHOOLBOY SPY. Sunday TimesKuji Media Corporation Ltd. » Blog Archive » THE SCHOOLBOY SPY. Sunday Times…
This distinction matters because it explains why Pryce occupies a different place in the history of British defence hacking. He became central to the Rome Laboratory investigation through his operational role rather than through any documented campaign to uncover alleged UFO secrets.
The lasting importance of Pryce’s role
Richard Pryce’s significance lies less in the quantity of information stolen than in what his actions revealed about military cybersecurity during the early internet era.
The Rome Laboratory investigation exposed weaknesses in password management, trust between interconnected networks and incident detection. Air Force investigators estimated that recovering from the attacks required extensive forensic work, security patching and restoration efforts costing hundreds of thousands of dollars, while the incident became a prominent case study in later congressional reviews of Department of Defense information security.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
For the broader history of British hackers targeting American defence systems, Pryce represents the technical counterpart to Bevan. Bevan’s alleged UFO-related motivations attracted public attention, but Pryce demonstrated how a skilled teenager operating from a London home could penetrate one of the US Air Force’s premier research facilities and briefly convince investigators that they might be witnessing the opening stages of a hostile foreign cyber operation rather than the work of an individual hacker.[gwu.edu]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
Amazon book picks
Further Reading
Books and field guides related to How a London Teen Reached Rome Laboratory. Use these as the next step if you want deeper reading beyond the article.
Ghost in the Wires
In this "intriguing, insightful and extremely educational" novel, the world's most famous hacker teaches you easy cloaking and counter-me...
Cyber War
Rating: 3.0/5 from 96 Google Books ratings
An essential, eye-opening book about cyberterrorism, cyber war, and the next great threat to our national security. " Cyber War may be th...
Countdown to Zero Day
Top cybersecurity journalist Kim Zetter tells the story behind the virus that sabotaged Iran’s nuclear efforts and shows how its existenc...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromretro computer poster oneBay.co.uk.
Endnotes
1.
Source: cyber.tap.purdue.edu
Title: Hackers of the ’90s
Link:https://cyber.tap.purdue.edu/blog/articles/hackers-of-the-90s/
2.
Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Blog Archive » THE SCHOOLBOY SPY. Sunday Times
Link:https://www.kujimedia.com/the-schoolboy-spy-sunday-times/
Source snippet
Kuji Media Corporation Ltd. » Blog Archive » THE SCHOOLBOY SPY. Sunday Times...
3.
Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/tag/richard-pryce/page/2/
Source snippet
» Richard PryceJune 26, 2008 — By the end of the second week of their attempt to outwit him, their windowless basement room was a mess of...
Published: June 26, 2008
4.
Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Datastream Cowboy
Link:https://www.kujimedia.com/tag/datastream-cowboy/page/2/
5.
Source: kujimedia.com
Link:https://www.kujimedia.com/british-teenager-fined-after-hacking-into-us-defence-system/
6.
Source: kujimedia.com
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/
7.
Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Datastream Cowboy
Link:https://www.kujimedia.com/tag/datastream-cowboy/
8.
Source: kujimedia.com
Link:https://www.kujimedia.com/articles/
9.
Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm
Source snippet
Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...
10.
Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr
11.
Source: airandspaceforces.com
Link:https://www.airandspaceforces.com/article/0397sweepers/
Source snippet
Air & Space Forces MagazineAt War With Sweepers, Sniffers, Trapdoors, and Worms | Air & Space Forces MagazineMarch 1, 1997...
Published: March 1, 1997
12.
Source: airandspaceforces.com
Title: Air & Space Forces Magazine War in Cyberspace | Air & Space Forces Magazine
Link:https://www.airandspaceforces.com/article/0198cyber/
13.
Source: soldierx.com
Link:https://www.soldierx.com/hdb/Datastream-Cowboy
Additional References
14.
Source: eandt.theiet.org
Title: hacking through years brief history cyber crime
Link:https://eandt.theiet.org/2017/03/13/hacking-through-years-brief-history-cyber-crime
Source snippet
through the years: a brief history of cyber crime | Engineering and Technology MagazineMarch 13, 2017 — On 28 March 1994, administrators...
Published: March 13, 2017
15.
Source: guardia.school
Title: Son nom est souvent associé
Link:https://guardia.school/boite-a-outils/richard-pryce-le-hacker-adolescent-implique-dans-le-piratage-du-pentagone-avec-mathew-bevan.html
Source snippet
Richard Pryce, le hacker adolescent impliqué dans le piratage du Pentagone avec Mathew Bevan - Guardia Cybersecurity SchoolOctober 13, 20...
16.
Source: youtube.com
Title: UFO Hacker Shares New Secrets | Gary Mc Kinnon
Link:https://www.youtube.com/watch?v=_SOTGFj7BwI
Source snippet
Richard Pryce Datastream Cowboy hacker Unveiling the Untold Saga of Kuji and Datastream Cowboy CyberCrime...
17.
Source: youtube.com
Title: THE HACKER WHO EXPOSED THE PENTAGON’S GREATEST WEAKNESS
Link:https://www.youtube.com/watch?v=ltNqoeAEx20
Source snippet
A Tale of Two UFO Hackers: Matthew Bevan & Gary McKinnon | True Crime...
18.
Source: youtube.com
Title: A Tale of Two UFO Hackers: Matthew Bevan & Gary Mc Kinnon | True Crime
Link:https://www.youtube.com/watch?v=rksYZZgSPcY
Source snippet
Gary Mckinnon: The Hacker Who Found UFOs...
19.
Source: youtube.com
Title: Unveiling the Untold Saga of Kuji and Datastream Cowboy
Link:https://www.youtube.com/watch?v=n_iLfffJbzo
Source snippet
THE HACKER WHO EXPOSED THE PENTAGON'S GREATEST WEAKNESS...
20.
Source: youtube.com
Title: Gary Mckinnon: The Hacker Who Found UFOs
Link:https://www.youtube.com/watch?v=8_1DuqeU8hw
Source snippet
UFO Hacker Shares New Secrets | Gary McKinnon...
21.
Source: independent.co.uk
Title: Fine for boy who hacked into Pentagon | The Independent | The Independent
Link:https://www.independent.co.uk/news/fine-for-boy-who-hacked-into-pentagon-1274204.html
22.
Source: issues.org
Title: An Electronic Pearl Harbor? Not Likely
Link:https://issues.org/smith-2/
23.
Source: time.com
Title: ESPIONAG E: Stealing the Company Store
Link:https://time.com/archive/6880994/espionage-stealing-the-company-store/



