Within Richard Pryce

How Datastream Cowboy Was Traced to a Bedroom

An informant's email, a bulletin-board telephone number and monitored calls connected the online handle to Pryce's family home.

25 sources 3 graphics
Preview for How Datastream Cowboy Was Traced to a Bedroom

On this page

  • The identifying clues Pryce left online
  • How British Telecom linked calls to intrusions
  • Why poor operational security proved decisive

Introduction

Richard Pryce, better known by the online handle Datastream Cowboy, was not identified through sophisticated cyber-tracking alone. Although his attacks on Rome Laboratory and other American systems were routed through multiple countries to disguise their origin, investigators ultimately traced him to his family home in north London through a combination of human intelligence, ordinary telecommunications records and a series of operational security mistakes. The investigation is an early example of how traditional detective work proved as important as technical network forensics. Rather than defeating every layer of electronic obfuscation, investigators exploited information Pryce had voluntarily revealed, then used British telephone records and coordinated surveillance to connect the online identity with a physical address.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Richard Pryce, Better Known By The Online Handle **Datastream... illustration 1

The identifying clues Pryce left online

The decisive breakthrough did not originate from tracing internet packets across international networks. Instead, investigators from the United States Air Force Office of Special Investigations (AFOSI) relied on information supplied by an informant from within the online hacking community.

According to the official Rome Laboratory case study, on 5 April 1994 an informant provided investigators with an earlier email exchange in which Datastream Cowboy had disclosed several highly identifying details. He reportedly described himself as a 16-year-old from the United Kingdom and boasted that he targeted American “.mil” systems because they were “so insecure”. Most importantly, he supplied the telephone number of his own hacker bulletin-board system (BBS).[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

That seemingly casual disclosure proved far more valuable than weeks of technical monitoring. The attackers had successfully concealed their network location by bouncing connections through numerous intermediate systems, but a domestic telephone number could be investigated using conventional records.

The episode illustrates a recurring lesson in computer crime investigations: anonymity often fails because of information voluntarily disclosed outside the attack itself. Investigators later described this indiscretion as the key reason the case was solved.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

How British Telecom linked calls to the intrusions

Once AFOSI obtained the telephone number, the investigation shifted to British authorities.

New Scotland Yard identified the household associated with the bulletin-board number and arranged for British Telecom to install a pen register on the line. Unlike content interception, a pen register recorded the numbers dialled from the residence, allowing investigators to compare telephone activity with the timing of intrusions occurring in the United States.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The monitoring quickly revealed two significant patterns:

  • someone at the residence was using phone phreaking, manipulating telephone systems to obtain free international calls;
  • these calls repeatedly coincided with unauthorised access to Rome Laboratory computers.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The timing mattered as much as the destination. Investigators observed that whenever Rome Laboratory experienced an intrusion, the London telephone line was simultaneously being used to establish the international connections necessary for the attack. The telephone evidence therefore linked the household to the hacking activity even though the internet traffic itself appeared to originate elsewhere.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Richard Pryce, Better Known By The Online Handle **Datastream... illustration 2

Following the international route without losing the origin

The attackers did not connect directly from London to American military computers.

Official accounts describe attack paths that travelled through systems in South America, multiple European countries, Mexico and Hawaii before reaching Rome Laboratory. Once inside Rome, the compromised Air Force computers became launching points for further intrusions into NASA facilities and other networks.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

This routing strategy complicated immediate attribution because every intermediate computer appeared to be the next apparent source of the attack. In modern terminology, the attackers were using compromised systems as stepping stones or pivots.

However, investigators did not need to reconstruct every technical hop perfectly. By correlating:

  • the informant’s identifying email,
  • the BBS telephone number,
  • British Telecom call records,
  • and the timing of the intrusions,

they established an evidential chain leading back to the London residence despite the complex international routing.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Richard Pryce, Better Known By The Online Handle **Datastream... illustration 3

Why poor operational security proved decisive

The case is often remembered as an illustration that operational security failures can outweigh sophisticated technical concealment.

Pryce had taken considerable steps to obscure his network location through international dial-up routes and compromised systems. Yet he undermined that anonymity by:

  • revealing his age and country during online correspondence;
  • distributing the telephone number of his own bulletin-board system;
  • continuing to use his home telephone line while conducting attacks;
  • leaving investigators able to correlate telephone activity with hacking sessions.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

None of these actions individually identified him beyond doubt. Together they formed a coherent evidential picture linking the online persona “Datastream Cowboy” to Richard Pryce.

From surveillance to arrest

After weeks of monitoring, British and American investigators coordinated the final stage of the operation.

Rather than immediately searching the property, police waited until AFOSI confirmed that Datastream Cowboy was actively online. British Telecom also confirmed that the home’s telephone line was then engaged in an international phone-phreaking connection consistent with the established pattern. Officers entered the north London house and found Pryce at his computer in an upstairs room. Contemporary accounts state that investigators believed he had only just disconnected from a remote system when they entered.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The search recovered computer equipment and documents referring to numerous military and NASA systems. During questioning, Pryce admitted to multiple intrusions into Rome Laboratory and other Air Force systems, although the investigation into his associate using the handle “Kuji” continued separately.[Kujimedia]kujimedia.comKuji Media Corporation Ltd. » Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter Six…

The lasting investigative lesson

The tracing of Datastream Cowboy remains significant because it demonstrated that early cyber investigations depended on combining digital evidence with conventional policing. International routing, compromised intermediary computers and dial-up obfuscation slowed investigators, but they were ultimately defeated by human error rather than by breaking the technical routing itself.

The investigation showed that attribution can emerge from small pieces of corroborating evidence—a boast in an email, a publicly shared telephone number, telecommunications records and carefully synchronised monitoring—forming a chain that connected anonymous online activity to a teenager’s bedroom in north London.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Amazon book picks

Further Reading

Books and field guides related to How Datastream Cowboy Was Traced to a Bedroom. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromhacker t shirt oneBay.co.uk.

Endnotes

1. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Datastream Cowboy
Link:https://www.kujimedia.com/tag/datastream-cowboy/

Source snippet

Kuji Media Corporation Ltd. » Datastream Cowboy...

2. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Blog Archive » THE SCHOOLBOY SPY. Sunday Times
Link:https://www.kujimedia.com/the-schoolboy-spy-sunday-times/

Source snippet

» Blog Archive » THE SCHOOLBOY SPY. Sunday TimesJune 26, 2008 — He was also planting “sniffer files” to pick up every password used in th...

Published: June 26, 2008

3. Source: kujimedia.com
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/

Source snippet

Kuji Media Corporation Ltd. » Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter Six...

4. Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/tag/richard-pryce/page/2/

Source snippet

» Richard PryceJune 26, 2008 — In the space of a few weeks he had caused more harm than the KGB, in the view of the American military, an...

Published: June 26, 2008

5. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Datastream Cowboy
Link:https://www.kujimedia.com/tag/datastream-cowboy/page/2/

6. Source: kujimedia.com
Link:https://www.kujimedia.com/british-teenager-fined-after-hacking-into-us-defence-system/

7. Source: kujimedia.com
Link:https://www.kujimedia.com/articles/

8. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

9. Source: kclpure.kcl.ac.uk
Title: King’s College London This electronic thesis or dissertation has been
Link:https://kclpure.kcl.ac.uk/portal/files/179736269/2014_Guitton_Clement_1016638_ethesis.pdf

10. Source: irp.fas.org
Title: Intelligence Resource Program Information Warfare
Link:https://irp.fas.org/eprint/snyder/infowarfare.htm

11. Source: soldierx.com
Link:https://www.soldierx.com/hdb/Datastream-Cowboy

Additional References

12. Source: korben.info
Title: Deux ados cherchant des OVNIS ont failli lancer la WW3
Link:https://korben.info/kuji-datastream-cowboy-pentagone-hack-1996-histoire-complete.html

Source snippet

Ils laissent des traces partout, copient des gigaoctets de données sans discrimination, et communi...

13. Source: youtube.com
Title: Ancient Aliens: Hacking NASA Secrets
Link:https://www.youtube.com/watch?v=20rWFDfh68Y

Source snippet

This selection provides detailed coverage on landmark investigations into UK-based UFO hackers and military system intrusions, highlighti...

14. Source: slidetodoc.com
Link:https://slidetodoc.com/introducing-digital-forensics-peter-sommer-london-school-of/

15. Source: slidetodoc.com
Link:https://slidetodoc.com/introducing-digital-forensics-peter-sommer-london-school-of-2/

16. Source: linkedin.com
Link:https://www.linkedin.com/posts/jamesmcmurry_throwbackthursday-cyberhistory-romelabhack-activity-7371961568449724416-NRP_

17. Source: linkedin.com
Link:https://www.linkedin.com/posts/threathunter_throwbackthursday-cyberhistory-romelabhack-activity-7371961570274451456-Pff5

18. Source: youtube.com
Title: The Man Who Hacked the U.S. Government
Link:https://www.youtube.com/watch?v=ND0zQX1rGdg

Source snippet

Hacking for UFOs and fighting for his life. Who is Gary McKinnon?...

19. Source: independent.co.uk
Title: Fine for boy who hacked into Pentagon | The Independent | The Independent
Link:https://www.independent.co.uk/news/fine-for-boy-who-hacked-into-pentagon-1274204.html

20. Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ

Source snippet

UK hacker's extradition to US blocked...

21. Source: airandspaceforces.com
Title: Air & Space Forces Magazine A Presidential commission warns that we
Link:https://www.airandspaceforces.com/PDF/MagazineArchive/Documents/1998/January%201998/0198cyber.pdf