Within UFO Hackers

Who Was the Datastream Cowboy?

Teenager Richard Pryce became linked to a major defence-network intrusion whose importance lay in its reach, not in verified UFO discoveries.

70 sources 3 graphics
Preview for Who Was the Datastream Cowboy?

On this page

  • Pryce's role in the intrusions
  • Connections to wider network access
  • UFO interest versus documented impact

Introduction

Richard Pryce, the London teenager known online as Datastream Cowboy, became the identifiable figure in a 1994 intrusion campaign that reached across United States defence-research networks, NASA systems, military contractors and an atomic-research institute in South Korea. He was only 16 when investigators traced the activity to his family home, yet the case exposed weaknesses serious enough to become evidence in congressional reviews of Pentagon computer security.

Overview image for Richard Pryce

Pryce is sometimes grouped with “UFO hackers” because his more experienced online associate, Mathew Bevan, later described an interest in UFO secrecy and government cover-ups. The surviving official record, however, does not establish that Pryce discovered UFO material, or even that searching for it was his principal motive. His historical importance rests on something better documented: exploiting poorly protected networks, using compromised military machines to reach further systems, and demonstrating how a teenager with modest equipment could create uncertainty about espionage, stolen research and international responsibility.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

Pryce’s Role in the Intrusions

The attacks centred on Rome Laboratory at Griffiss Air Force Base in New York, then a leading US Air Force research facility for command-and-control technologies. Its work included artificial intelligence, radar guidance, target detection and systems for preparing air tasking orders—the operational messages used to communicate targeting, intelligence and battle instructions to aircrews. The laboratory depended heavily on internet connections with universities, contractors and other government facilities, creating useful research links but also multiple routes for an intruder.[National Security Archive]nsarchive2.gwu.eduOpen source on gwu.edu.

During March and April 1994, investigators recorded more than 150 intrusions associated with two handles: Datastream Cowboy and Kuji. The official Air Force case study identified Datastream as Pryce but initially treated Kuji as an unknown and more technically sophisticated collaborator. Monitoring suggested that Pryce would sometimes fail to penetrate a system, hold a private online conversation with Kuji, and then return with a successful method. Investigators therefore believed that Kuji was tutoring him and receiving copied information in return. Pryce later said that the two had never met physically and communicated only by telephone or online.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

The intrusions were not a simple case of directly dialling one military computer. Pryce used fraudulent telephone access—then commonly called “phone phreaking”—and routed connections through systems in several countries. British investigators found that activity on his family’s telephone line corresponded with intrusions at Rome Laboratory. The chain could pass through South America, Europe, Mexico, Hawaii and commercial internet providers before reaching the Air Force network, making immediate tracing difficult and obscuring the attacker’s actual location.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

His identification ultimately owed as much to poor operational security as to advanced forensic work. An informant gave Air Force investigators an earlier email in which Datastream Cowboy reportedly described himself as a 16-year-old from the United Kingdom who targeted military domains because they were insecure. He had also supplied a telephone number connected with his own bulletin-board system. Scotland Yard and British Telecom were then able to associate the number with Pryce’s residence and monitor outgoing calls.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

Richard Pryce illustration 1

How Rome Laboratory Became a Gateway

The most consequential feature of the case was its reach. After gaining control of Rome Laboratory systems, the intruders could appear to other networks as trusted users originating from a legitimate US Air Force facility. That allowed them to use Rome not merely as a target, but as a platform for attacks elsewhere.

According to the congressional case study and the US General Accounting Office, compromised Rome systems were used to reach or probe facilities including NASA’s Goddard Space Flight Center, the Jet Propulsion Laboratory, Wright-Patterson Air Force Base, the Army Corps of Engineers, defence contractors and private organisations. Investigators also documented access connected with the National Aero-Space Plane Joint Program Office and a successful attack on a system associated with NATO’s SHAPE Technical Centre.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

The attackers installed or exploited sniffers, programs that record network traffic and can capture usernames and passwords. When authorised contractors connected from Rome Laboratory to systems belonging to their employers, those credentials could be intercepted and reused. Five contractor systems—four in California and one in Texas—were reportedly compromised in this way. The intruders also used scanning software to identify operating systems, locate password files and determine which known attack methods might work against additional machines.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

This created a cascading problem. A weak account on one research computer could expose credentials for another organisation, whose systems could then be used to penetrate a third. The value of the original access therefore lay less in any single file than in the trust relationships connecting military laboratories, contractors and civilian research networks.

The GAO concluded that the attackers had seized control of Rome’s support systems for several days and copied material including air-tasking-order research data. It also stressed the limits of the investigation: because the authorities could not reconstruct everything that had been viewed, copied or altered, they could not conclusively determine the full extent of the damage.[National Security Archive]nsarchive2.gwu.eduOpen source on gwu.edu.

The Korean Atomic Research Incident

The case’s most alarming moment occurred while British and American investigators were already monitoring Pryce and preparing to execute a search warrant. On 15 April 1994, Datastream used a Rome Laboratory computer to access a system identified as belonging to a Korean atomic-research institute and transferred its stored data onto the Air Force network.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

Investigators initially did not know whether the institution was in North Korea or South Korea. That distinction mattered because the United States was engaged in sensitive negotiations over North Korea’s nuclear programme. Officials feared that, had a North Korean system been penetrated through an apparent US Air Force connection, Pyongyang might interpret the event as state-sponsored American espionage or an aggressive military act. Within hours, the system was identified as belonging to South Korea, removing the immediate diplomatic danger.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

Later accounts have sometimes exaggerated this episode into a claim that Pryce “almost started World War Three”. The official evidence supports a narrower conclusion. Investigators briefly feared that an unauthorised intrusion might be misattributed to the United States during a tense diplomatic period. There is no evidence that North Korean authorities detected the event, prepared retaliation or came close to initiating war. The genuine lesson is still significant: an intruder could make hostile activity appear to originate from a military network belonging to another country.

The episode also illustrates why the case was more than a harmless exploration of publicly accessible machines. Even without access to formally classified material, the combination of stolen credentials, copied research and misleading network origins created risks that neither the intruder nor the victim organisation could readily control.

Richard Pryce illustration 2

From Suspected Foreign Agent to London Schoolboy

Before Pryce was identified, the scale and routing of the activity encouraged speculation that the intruders might be intelligence operatives. Connections appeared to originate through places including Latvia, while the attackers showed interest in military and aerospace research. Congressional and defence discussions consequently examined the possibility of foreign sponsorship or organised espionage.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

The eventual discovery that Datastream Cowboy was a teenager using an inexpensive home computer changed the public framing of the case. Reporting from Pryce’s 1997 court appearance described a basic desktop machine in an upstairs room at his family home, rather than the equipment of a foreign intelligence service. His defence argued that the incident revealed exceptionally lax protection within American military networks and characterised his actions as a schoolboy prank rather than subversion.[The Independent]independent.co.ukOpen source on independent.co.uk.

That contrast should not obscure the uneven division of expertise between Pryce and Kuji. The Air Force investigators considered Kuji more careful and technically capable. He reportedly limited the duration of connections, avoided the personal disclosures that exposed Pryce and appeared to direct some of Pryce’s activity. At the time of the 1996 congressional testimony, officials still did not know Kuji’s identity or what had happened to information passed to him.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

Kuji was later identified as Welsh hacker Mathew Bevan. The prosecution of Bevan ultimately ended without a conviction when the Crown Prosecution Service offered no evidence, whereas Pryce pleaded guilty. That difference matters when recounting the case: the monitoring record documented interaction between the two handles, but the final legal outcomes did not establish every broader allegation made during the investigation.

The Conviction and the Disputed Damage

Pryce was arrested in May 1994, but his case was not concluded until 21 March 1997. At Bow Street Magistrates’ Court he pleaded guilty to 12 offences of unauthorised access under the Computer Misuse Act 1990. He was fined £1,200 and ordered to pay £250 in costs. Contemporary reports described him by then as a music student who had abandoned computing in favour of studying the double bass.[independent.co.uk]independent.co.ukOpen source on independent.co.uk.

The financial consequences of the intrusions were described differently in different official assessments. The Air Force case study cited a Rome Laboratory loss of $211,722, excluding investigative costs and losses at other affected agencies. A broader Air Force Information Warfare Center estimate reported by the GAO placed the cost at more than $500,000 when system disconnection, integrity checks, security repairs, restoration work, investigation and lost staff time were included. These figures measure different categories and should not be treated as contradictory versions of a single bill.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

More dramatic claims require greater caution. The Independent reported that US officials ultimately maintained that Pryce had not reached classified information, while his defence denied that he had subverted defence operations or acted for profit. The GAO nevertheless found that valuable research had been copied and that Rome Laboratory personnel could not be certain whether lasting damage or hidden alteration had occurred. The strongest evidence therefore supports neither the idea of a harmless visit nor claims that Pryce stole America’s most closely guarded secrets.[The Independent]independent.co.ukOpen source on independent.co.uk.

The uncertainty itself was part of the damage. Once attackers had obtained elevated access, installed monitoring tools and moved through connected systems, administrators had to assume that credentials, software and research data might be compromised. Restoration required far more than removing one known account.

Richard Pryce illustration 3

UFO Interest Versus Documented Impact

Pryce is frequently included in lists of hackers who searched military networks for UFO secrets, but the evidence needs to be divided between his own documented conduct and the later explanation given by Bevan.

Bevan has said that his hacking interests were influenced by collections of material about UFOs, government cover-ups and conspiracy theories. Later cybersecurity summaries commonly describe him as attempting to investigate or prove a UFO conspiracy. Some also group Pryce into that motivation because the two exchanged information and worked against many of the same networks.[Kujimedia]kujimedia.comDatastream Cowboy - Kuji Media Corporation Ltd.What I found on his system were hundreds of documents about UFOs, government cove…

The stronger sources on Pryce himself give a different emphasis. The Air Force investigative account records his statement that he liked attacking military domains because they were insecure. Contemporary reporting described the removal of files concerning artificial intelligence and battle management, not extraterrestrial craft. A modern Purdue University cybersecurity account likewise distinguishes Bevan’s UFO interest from Pryce’s broader interest in gaining access to government systems and obtaining sensitive information.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

No authenticated UFO documents, photographs or alien-related records emerged from Pryce’s prosecution. The congressional testimony, GAO assessment and court reporting focus instead on network compromise, stolen passwords, air-warfare research, aerospace systems and the onward use of Rome Laboratory as an attack platform. Even the investigation’s unresolved question—what Kuji did with data received from Pryce—does not establish that it contained UFO evidence.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

The fairest classification is therefore that Pryce belonged to a hacking partnership with a documented UFO-curious associate, rather than that Pryce himself verified hidden extraterrestrial programmes. His case belongs beside Gary McKinnon’s because both involved British intruders penetrating American military or space-related systems amid a wider culture of secrecy and UFO speculation. The evidential outcomes, however, were similar in one crucial respect: access to government networks did not produce independently verifiable proof of concealed alien technology.

What the Datastream Cowboy Case Established

The Datastream Cowboy case became influential because it converted an abstract warning about internet security into a concrete demonstration. A teenager with a modest home computer, publicly circulating attack tools and help from a remote associate could penetrate an important defence laboratory, capture reusable credentials and move across institutional boundaries. The attackers did not need to defeat a single fortress; they exploited a loosely defended web of trusted systems.

The Rome Laboratory incident also helped expose how poorly prepared large organisations were to detect intrusions. The GAO’s wider testing programme found that Defence Department assessors successfully penetrated systems in 65 per cent of attempted tests, while only a small fraction of successful attacks were detected and reported. Following the review, the GAO recommended compulsory incident reporting, routine risk assessments, rapid correction of weaknesses, improved staff training and wider deployment of network-monitoring technology. Several of those recommendations later became elements of department-wide defensive policy.[National Security Archive]nsarchive2.gwu.eduOpen source on gwu.edu.

For readers approaching Pryce through the history of UFO-motivated hacking, the central distinction is between motive, access and proof. UFO curiosity may have shaped the interests of his associate and the later mythology surrounding the pair. Access to military and NASA-linked systems is well documented. Verified UFO discoveries are not.

Pryce’s lasting significance therefore comes from the systems he reached and the vulnerabilities his activity revealed. Datastream Cowboy was not shown to have uncovered an extraterrestrial secret. He helped demonstrate that early networked defence research could be penetrated, repurposed and made to appear as the origin of attacks elsewhere—a lesson far more securely established, and ultimately more consequential, than the UFO claims attached to the story.

Amazon book picks

Further Reading

Books and field guides related to Who Was the Datastream Cowboy?. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromhacker t shirt oneBay.co.uk.

Endnotes

1. Source: spokesman.com
Title: Review Brit Fined For Hacking U.S
Link:https://www.spokesman.com/stories/1997/mar/22/brit-fined-for-hacking-us-military-computer/

Source snippet

Military Computer22 Mar 1997 — Richard Pryce pleaded guilty to 12 offenses under Britain's Computer Misuse Act and also was ordered to pa...

2. Source: kujimedia.com
Link:https://www.kujimedia.com/tag/datastream-cowboy/

Source snippet

Datastream Cowboy - Kuji Media Corporation Ltd.What I found on his system were hundreds of documents about UFOs, government cove...

3. Source: cyber.tap.purdue.edu
Title: Hackers of the ’90s
Link:https://cyber.tap.purdue.edu/blog/articles/hackers-of-the-90s/

4. Source: gao.gov
Link:https://www.gao.gov/products/aimd

5. Source: gao.gov
Link:https://www.gao.gov/assets/a280296.html

6. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Blog Archive » THE SCHOOLBOY SPY. Sunday Times
Link:https://www.kujimedia.com/the-schoolboy-spy-sunday-times/

7. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Datastream Cowboy
Link:https://www.kujimedia.com/tag/datastream-cowboy/page/2/

8. Source: kujimedia.com
Link:https://www.kujimedia.com/british-teenager-fined-after-hacking-into-us-defence-system/

9. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Richard Pryce
Link:https://www.kujimedia.com/tag/richard-pryce/page/2/

10. Source: kujimedia.com
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/

11. Source: gao.gov
Link:https://www.gao.gov/assets/a248580.html

12. Source: gao.gov
Link:https://www.gao.gov/assets/a241727.html

13. Source: gao.gov
Link:https://www.gao.gov/assets/a157449.html

14. Source: gao.gov
Link:https://www.gao.gov/products/b-291653-0

15. Source: gao.gov
Link:https://www.gao.gov/products/t-aimd

16. Source: gao.gov
Link:https://www.gao.gov/products/b-258713%2Cb-258714

17. Source: gao.gov
Title: nsiad 94 116
Link:https://www.gao.gov/products/nsiad

18. Source: gao.gov
Title: b 254506.2
Link:https://www.gao.gov/products/b-254506.2

19. Source: gao.gov
Title: b 254730
Link:https://www.gao.gov/products/b-254730

20. Source: gao.gov
Title: rced 93 6
Link:https://www.gao.gov/products/rced

21. Source: kujimedia.com
Link:https://www.kujimedia.com/articles/

22. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion...

23. Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/docs/Cyber-010a.pdf

24. Source: independent.co.uk
Link:https://www.independent.co.uk/news/fine-for-boy-who-hacked-into-pentagon-1274204.html

25. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a

26. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/media/21407/ocr

27. Source: irp.fas.org
Link:https://irp.fas.org/gao/aim96084.htm

28. Source: Wikipedia
Title: Mathew Bevan
Link:https://en.wikipedia.org/wiki/Mathew_Bevan

29. Source: christianespinosa.com
Title: richard pryce
Link:https://christianespinosa.com/blog/tag/richard-pryce/

Additional References

30. Source: usa.kaspersky.com
Link:https://usa.kaspersky.com/resource-center/threats/top-ten-greatest-hackers

Source snippet

Top 10 Most Notorious Hackers of All TimeBevan claims he was looking to prove a UFO conspiracy theory, and according to the BBC...

31. Source: youtube.com
Title: Who Is The Most Dangerous Hacker Ever? (Tier List)
Link:https://www.youtube.com/watch?v=z7OjzYT_-Zo

Source snippet

Hacking for UFOs and fighting for his life. Who is Gary McKinnon?...

32. Source: airandspaceforces.com
Link:https://www.airandspaceforces.com/PDF/MagazineArchive/Documents/1998/January%201998/0198cyber.pdf

Source snippet

Air & Space Forces MagazineWar in Cyberspaceby JT Correll · 1998 · Cited by 11 — On March 21, 1997, Datastream was sentenced in Bow Stree...

Published: March 21, 1997

33. Source: coloradosun.com
Link:https://coloradosun.com/2018/11/22/richard-estep-colorado-ufos-interview/

34. Source: airandspaceforces.com
Link:https://www.airandspaceforces.com/article/0397sweepers/

35. Source: ufohackers.org
Link:https://www.ufohackers.org/hackers

36. Source: facebook.com
Link:https://www.facebook.com/KendallsPlace/posts/he-hacked-nasa-looking-for-ufos-and-nearly-got-life-in-prison/1598324498636439/

37. Source: protelion.com
Link:https://protelion.com/resources/blog/the-cyberhall-of-fame-famous-faces-in-cybersecurity/

38. Source: trulyadventure.us
Link:https://www.trulyadventure.us/the-hacker

39. Source: kaspersky.com
Link:https://www.kaspersky.com/resource-center/threats/top-ten-greatest-hackers