Within Military Targets

How Rome Lab Became a UFO Hacking Precedent

The 1994 Rome Laboratory intrusion showed how UFO-motivated hackers could turn one Air Force foothold into access across government research networks.

34 sources 3 graphics
Preview for How Rome Lab Became a UFO Hacking Precedent

On this page

  • How the Rome Laboratory intrusion unfolded
  • Why investigators first suspected foreign espionage
  • How the case shaped later UFO hacking narratives

Introduction

The 1994 Rome Laboratory intrusion became one of the earliest and most influential demonstrations that a single compromise of a US military research network could cascade into access across numerous government, academic and aerospace systems. Although the attackers themselves were not primarily known for searching for UFO evidence, the incident became an important historical precedent for later UFO-motivated hackers because it revealed how interconnected defence research networks had become. Years later, British hacker Gary McKinnon would argue that similar military and NASA systems were worth targeting because they might contain evidence of concealed UFO programmes. The Rome Laboratory case therefore occupies an important place in the history of cyber intrusions: not because it uncovered evidence of extraterrestrial technology, but because it showed that apparently isolated defence networks could provide pathways into a much wider research infrastructure.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…Published: May 22, 1996

Rome Lab illustration 1

How the Rome Laboratory intrusion unfolded

Rome Laboratory, located at Griffiss Air Force Base in New York, served as the US Air Force’s principal command-and-control research centre. Its work included artificial intelligence, radar guidance, target tracking and advanced communications, while maintaining extensive Internet connections with universities, contractors and other government laboratories. Those connections, valuable for collaborative research, also expanded the laboratory’s attack surface.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…Published: May 22, 1996

The intrusion began in March 1994 when attackers exploited vulnerable systems and quietly installed password-sniffing software. Rather than immediately stealing classified files, they first harvested usernames and passwords, allowing them to expand their access across multiple machines. By the time administrators detected suspicious activity several days later, roughly thirty Rome Laboratory systems had been compromised, with more than one hundred user accounts exposed. Investigators documented over 150 separate intrusion events during the incident.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

The attackers also concealed their origin by routing their traffic through numerous intermediate systems, including compromised telephone exchanges and Internet providers across several countries. This technique, common today but comparatively sophisticated in 1994, complicated attribution and demonstrated how difficult it was for investigators to distinguish the original source from the chain of relay systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

Perhaps the most significant consequence was that Rome Laboratory itself became a launching platform. Once inside, the attackers pivoted to numerous external organisations, including NASA facilities, the Jet Propulsion Laboratory and the Goddard Space Flight Center, illustrating how one military foothold could provide access to an entire ecosystem of trusted research partners.[Air & Space Forces Magazine]airandspaceforces.comAir & Space Forces Magazine War in Cyberspace | Air & Space Forces MagazineAir & Space Forces Magazine War in Cyberspace | Air & Space Forces Magazine

Why investigators first suspected foreign espionage

From the perspective of US investigators in 1994, the attack initially resembled a classic espionage operation rather than recreational hacking.

Several features raised concern:

  • Rome Laboratory conducted sensitive defence research involving command-and-control technologies.
  • The attackers demonstrated patience and technical sophistication rather than obvious vandalism.
  • Compromised systems were used to reach additional military and scientific networks.
  • Password theft suggested an intention to maintain long-term access rather than conduct a brief intrusion.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

Investigators were especially alarmed when Rome Laboratory computers were used to access the Korean Atomic Research Institute. Early in the investigation there was uncertainty about precisely which Korean institution had been reached, raising fears that an intrusion appearing to originate from a US Air Force network could have serious diplomatic consequences if interpreted as an official American cyber operation.[Air & Space Forces Magazine]airandspaceforces.comAir & Space Forces Magazine War in Cyberspace | Air & Space Forces MagazineAir & Space Forces Magazine War in Cyberspace | Air & Space Forces Magazine

The Air Force Office of Special Investigations ultimately traced the activity to two young British hackers operating under the online aliases “Datastream Cowboy” and “Kuji”, rather than to a hostile intelligence service. Even so, the case illustrated how difficult attribution could be in international cyber investigations and how quickly criminal hacking could create strategic risks.[Air & Space Forces Magazine]airandspaceforces.comAir & Space Forces Magazine War in Cyberspace | Air & Space Forces MagazineAir & Space Forces Magazine War in Cyberspace | Air & Space Forces Magazine

Rome Lab illustration 2

How the breach foreshadowed later UFO hacking narratives

The Rome Laboratory incident acquired a second life within UFO-related discussions years later because it demonstrated a practical fact that UFO enthusiasts found significant: military research networks were interconnected with NASA and other scientific institutions.

For later hackers motivated by alleged UFO secrecy, this suggested that:

  • defence research laboratories might provide indirect routes into space-related systems;
  • sensitive information could be distributed across multiple agencies rather than stored in one location;
  • relatively ordinary network security weaknesses could expose highly important organisations.[Air & Space Forces Magazine]airandspaceforces.comAir & Space Forces Magazine War in Cyberspace | Air & Space Forces MagazineAir & Space Forces Magazine War in Cyberspace | Air & Space Forces Magazine

Gary McKinnon, who conducted his own intrusions between 2001 and 2002, publicly stated that he was searching specifically for evidence of UFOs, suppressed energy technologies and secret space programmes. He has consistently claimed that he targeted military and NASA systems because he believed those organisations possessed hidden information, citing public claims made by Disclosure Project witnesses as part of his motivation.[UFO Hackers]ufohackers.orgUFO Hackers Mc Kinnon Overview | www.ufohackers.orgUFO Hackers Mc Kinnon Overview | www.ufohackers.org

Although McKinnon’s objectives differed substantially from those of the Rome Laboratory intruders, the earlier breach had already demonstrated that British hackers could reach deeply into American defence networks from overseas. Within UFO literature, Rome Laboratory therefore became viewed less as a UFO incident than as proof that supposedly inaccessible military systems could, in practice, be penetrated.[Air & Space Forces Magazine]airandspaceforces.comAir & Space Forces Magazine War in Cyberspace | Air & Space Forces MagazineAir & Space Forces Magazine War in Cyberspace | Air & Space Forces Magazine

What the Rome Laboratory case did—and did not—show

One reason the Rome Laboratory breach is frequently cited alongside later UFO hacking stories is that readers sometimes blur together demonstrated network access and unverified claims about what those networks contained.

The historical record clearly supports several conclusions:

  • Rome Laboratory suffered a major, well-documented intrusion.
  • The attackers successfully moved from Air Force systems into other research networks.
  • NASA-related systems were among those reached from the compromised infrastructure.
  • The incident exposed significant weaknesses in Department of Defense cybersecurity and influenced later improvements in network monitoring and incident response.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…Published: May 22, 1996

However, the breach did not produce verified evidence of hidden UFO programmes or extraterrestrial technology. Contemporary investigative reports, congressional documentation and Government Accountability Office assessments discuss stolen passwords, compromised research systems and cybersecurity failures, not discoveries relating to alien spacecraft or secret extraterrestrial projects.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

That distinction became increasingly important after McKinnon publicised his own claims about what he believed he had observed on later military and NASA systems. Those claims remain personal testimony rather than independently verified findings, whereas the Rome Laboratory intrusion itself is extensively documented as a landmark cybersecurity incident.[UFO Hackers]ufohackers.orgUFO Hackers Mc Kinnon Overview | www.ufohackers.orgUFO Hackers Mc Kinnon Overview | www.ufohackers.org

Rome Lab illustration 3

Why Rome Laboratory remains an important precedent

Viewed historically, the Rome Laboratory breach marks the transition from isolated computer break-ins to modern network-based intrusions capable of spreading across interconnected research organisations. It demonstrated that compromising one trusted military institution could expose many others, including major aerospace facilities.

For researchers examining the history of UFO-motivated hacking, its significance is therefore indirect but substantial. The incident helped establish the practical belief that military and space-research networks were technically reachable, a lesson that later hackers—including Gary McKinnon—would interpret through a very different lens. The cybersecurity precedent is firmly documented; the later UFO narratives built upon it remain separate claims whose extraordinary conclusions have not been independently substantiated.[fas.org]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996…Published: May 22, 1996

Amazon book picks

Further Reading

Books and field guides related to How Rome Lab Became a UFO Hacking Precedent. Use these as the next step if you want deeper reading beyond the article.

BookCover for The Hacker Crackdown

The Hacker Crackdown

By Bruce Sterling

The bestselling cyberpunk author "has produced by far the most stylish report from the computer outlaw culture since Steven Levy's Hacker...

BookCover for The Hacker and the State

The Hacker and the State

By Ben Buchanan

Rating: 5.0/5 from 18 Google Books ratings

“A must-read...It reveals important truths.” —Vint Cerf, Internet pioneer “One of the finest books on information security published so f...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromcybersecurity wall art oneBay.co.uk.

Endnotes

1. Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm

Source snippet

Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing RisksMay 22, 1996...

Published: May 22, 1996

2. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion...

3. Source: airandspaceforces.com
Title: Air & Space Forces Magazine War in Cyberspace | Air & Space Forces Magazine
Link:https://www.airandspaceforces.com/article/0198cyber/

4. Source: ufohackers.org
Title: UFO Hackers Mc Kinnon Overview | www.ufohackers.org
Link:https://www.ufohackers.org/hackers/gary-mckinnon/mckinnon-overview

5. Source: airandspaceforces.com
Link:https://www.airandspaceforces.com/article/0397sweepers/

6. Source: ufohackers.org
Link:https://www.ufohackers.org/hackers

7. Source: ufohackers.org
Title: 2017 mufon symposium
Link:https://www.ufohackers.org/hackers/gary-mckinnon/2017-mufon-symposium

8. Source: ufohackers.org
Title: quentin overview
Link:https://www.ufohackers.org/hackers/quentin/quentin-overview

Additional References

9. Source: reddit.com
Link:https://www.reddit.com/r/UFOs/comments/t0imdw

Source snippet

Hi, i'm Gary Mckinnon. I was in the news for a decade after getting caught 'hacking' mil/gov systems looking for evidence of UFO/UA...

10. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a

Source snippet

National Security ArchiveGovernment Accounting Office, GAO/AIMD- 96-84, Information Security: Computer Attacks at Department of Defense P...

11. Source: theguardian.com
Title: Profile: Gary Mc Kinnon | Gary Mc Kinnon | The Guardian
Link:https://www.theguardian.com/technology/2009/jul/31/gary-mckinnon-hacking-extradition

Source snippet

Profile: Gary McKinnon | Gary McKinnon | The GuardianJuly 31, 2009 — Gary McKinnon This article is more than 16 years old Profile PROFILE...

Published: July 31, 2009

12. Source: kujimedia.com
Title: Kuji Media Corporation Ltd
Link:https://www.kujimedia.com/tag/datastream-cowboy/

Source snippet

» Datastream CowboyJune 26, 2008 — Air Force’s premier command-and- control research facility. Rome Lab researchers collaborate with univ...

Published: June 26, 2008

13. Source: spectrum.ieee.org
Title: the autistic hacker
Link:https://spectrum.ieee.org/the-autistic-hacker

Source snippet

McKinnon: The Autistic Hacker - IEEE SpectrumJune 27, 2011 — THE AUTISTIC HACKER GARY MCKINNON HACKED THOUSANDS OF GOVERNMENT COMPUTERS 1...

Published: June 27, 2011

14. Source: youtube.com
Title: The Copper City
Link:https://www.youtube.com/watch?v=hdlZhdtkCcQ

Source snippet

This video covers claims surrounding Gary McKinnon's hacking of military and NASA systems to find evidence of secret space programs and e...

15. Source: youtube.com
Title: Ancient Aliens: Hacking NASA Secrets (Season 12, Episode 9) | History
Link:https://www.youtube.com/watch?v=20rWFDfh68Y

Source snippet

Hacking for UFOs and fighting for his life. Who is Gary McKinnon?...

16. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict.htm

17. Source: all.net
Link:https://all.net/books/iw/iwarstuff/www.af.mil/news/airman/0496/hacker.htm

18. Source: kujimedia.com
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/