Within Mathew Bevan

How Rome Laboratory Opened the Wider Network

The Rome Laboratory breach gave Bevan and Richard Pryce a trusted foothold for reaching wider US military and space networks.

24 sources 3 graphics
Preview for How Rome Laboratory Opened the Wider Network

On this page

  • The March April 1994 intrusion campaign
  • How sniffers captured reusable credentials
  • Why Rome Laboratory enabled further access

Introduction

For Mathew Bevan and Richard Pryce, the 1994 compromise of the US Air Force’s Rome Laboratory was not merely a successful intrusion but the operational launch point that enabled access to a much wider collection of military, government and aerospace networks. Rather than attacking every target independently, the pair exploited a trusted research network, installed password-stealing software, and then used the credentials they harvested to move laterally into other organisations. This approach transformed one breach into a chain of compromises that eventually reached systems connected with NASA, defence contractors and Wright-Patterson Air Force Base—the installation that later became central to Bevan’s Roswell-related claims. Contemporary US investigations consistently describe Rome Laboratory as the pivotal staging ground from which the wider campaign expanded.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Rome Lab illustration 1

The March–April 1994 Intrusion Campaign

Rome Laboratory, located at Griffiss Air Force Base in New York, served as the Air Force’s principal command-and-control research facility. Its researchers collaborated extensively with universities, defence contractors and other government organisations, making it unusually well connected to external networks for its time. That connectivity also made it an attractive pivot point once attackers obtained a foothold.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Investigators determined that the initial penetration occurred on 23 March 1994, although administrators did not discover the compromise until 28 March after detecting an unauthorised network-monitoring program. By then, multiple systems had already been compromised. The subsequent investigation attributed more than 150 known intrusion attempts over a 26-day period to the campaign carried out by Richard Pryce (“Datastream Cowboy”) and Mathew Bevan (“Kuji”), although the precise division of activity between the two remained difficult to reconstruct from technical evidence alone.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Rather than simply copying files, the attackers sought to establish persistence. Once they controlled machines inside Rome Laboratory, they were able to return repeatedly while appearing to originate from a trusted Air Force network, greatly increasing the value of their initial compromise.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

How Sniffers Captured Reusable Credentials

The mechanism that made Rome Laboratory such an effective launch point was the installation of “sniffer” programs. At the time, many network protocols transmitted usernames and passwords without encryption. A sniffer quietly monitored network traffic and recorded those credentials as authorised users logged into remote systems.

According to the Senate investigation, seven separate sniffers were installed, compromising around 30 Rome Laboratory systems and capturing credentials from more than 100 user accounts. The software also enabled the attackers to read, copy and sometimes delete users’ email while collecting authentication details for future use.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The importance of these credentials went beyond Rome Laboratory itself. Researchers, contractors and administrators routinely authenticated to external organisations from within the Air Force network. As they logged into remote computers, the sniffers collected usernames, passwords and, in some cases, information identifying the destination systems. This effectively handed the attackers valid credentials for organisations that had never been directly breached.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

This method illustrates a broader security lesson from the early Internet era: compromising a trusted network often yielded access far beyond the original victim because authentication was frequently reused across interconnected systems.

Rome Lab illustration 2

Why Rome Laboratory Enabled Further Access

Rome Laboratory’s research mission made it unusually valuable as a stepping stone. It maintained operational relationships with defence contractors, NASA facilities, universities and other military organisations involved in command-and-control research. Once attackers possessed legitimate credentials harvested from Rome users, they could authenticate as authorised users elsewhere instead of relying solely on technical exploits.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

US investigators documented the attackers using Rome Laboratory as a launching platform against numerous additional networks. The campaign reached organisations including:

  • NASA’s Goddard Space Flight Center.
  • NASA’s Jet Propulsion Laboratory.
  • Wright-Patterson Air Force Base.
  • Multiple defence contractors.
  • Academic and commercial computer systems connected through the Internet.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

One example highlighted during the investigation involved an aerospace contractor whose employees remotely accessed Rome Laboratory. The sniffers captured the contractors’ home-system credentials as they logged in. The attackers then impersonated those users to compromise several contractor systems in California and Texas before conducting additional reconnaissance from those machines. This demonstrates that Rome Laboratory functioned less as an end target than as a trusted credential-collection hub.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Why This Launch Point Mattered for Bevan’s UFO-Motivated Searches

Within the broader story of Mathew Bevan’s Roswell-motivated hacking, Rome Laboratory’s importance lies in the pathway it created rather than in any alleged UFO material stored there.

Bevan later stated that his interest centred on Wright-Patterson Air Force Base because he believed it might contain information related to the alleged Roswell recovery. Contemporary government investigations, however, indicate that access to Wright-Patterson occurred after Rome Laboratory had already been compromised and was being used as an operational base for further movement through interconnected networks. The available evidence therefore supports a sequence in which Rome Laboratory enabled access to additional military systems; it does not suggest that Rome Laboratory itself was the object of Bevan’s Roswell-related interest.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

This distinction is important because it separates documented forensic evidence from Bevan’s later personal explanations. The documented record establishes how the attackers moved through networks and why Rome Laboratory was strategically valuable. Claims about searching specifically for evidence of recovered extraterrestrial technology arise primarily from Bevan’s later accounts rather than from forensic records recovered during the investigation.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Rome Lab illustration 3

A Turning Point in Military Network Security

The Rome Laboratory incident became one of the most influential early case studies in military cybersecurity because it demonstrated how a compromise of a single research institution could cascade through an interconnected defence ecosystem.

Government reviews concluded that the attackers temporarily gained control over important support systems, copied sensitive research data and forced extensive remediation efforts. The incident also exposed the risks created by clear-text authentication, trust relationships between organisations and inadequate monitoring of internal network traffic. These findings helped shape later improvements in intrusion detection, encrypted authentication and network segmentation across US defence systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…

Amazon book picks

Further Reading

Books and field guides related to How Rome Laboratory Opened the Wider Network. Use these as the next step if you want deeper reading beyond the article.

BookCover for The Cuckoo's Egg

The Cuckoo's Egg

By Cliff Stoll

This is the true story of how a systems manager at Lawrence Berkeley Lab singlehandedly tracked down and helped capture a computer hacker...

BookCover for The Hacker and the State

The Hacker and the State

By Ben Buchanan

Rating: 5.0/5 from 18 Google Books ratings

“A must-read...It reveals important truths.” —Vint Cerf, Internet pioneer “One of the finest books on information security published so f...

BookCover for The Hacker's Handbook

The Hacker's Handbook

By Hugo Cornwall

Covers everything from illegal aspects to understandable explanations of telecomputing for every modem user. . . .a reference book on man...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromhacker t shirt oneBay.co.uk.

Endnotes

1. Source: intelligence.senate.gov
Link:https://www.intelligence.senate.gov/1996/11/26/hearings-allegations-cia-connection-crack-cocaine-epidemic-october-23-and-november-26-1996/

Source snippet

of a CIA Connection to Crack Cocaine Epidemic (October 23 and November 26, 1996) | Senate Select Committee on IntelligenceNovember 26, 19...

Published: November 26, 1996

2. Source: intelligence.senate.gov
Link:https://www.intelligence.senate.gov/1996/09/25/hearings-intelligence-assessments-exposure-us-military-personnel-chemical-agents-during-operation/

Source snippet

Military Personnel to Chemical Agents During Operation Sesert Storm (September 25, 1996) | Senate Select Committee on IntelligenceSeptemb...

Published: September 25, 1996

3. Source: intelligence.senate.gov
Title: Hrg. 104-784 Download PDF
Link:https://www.intelligence.senate.gov/1996/08/01/hearings-international-terrorism-august-1-1996/

Source snippet

Terrorism (August 1, 1996) | Senate Select Committee on IntelligenceAugust 1, 1996 — INTERNATIONAL TERRORISM (AUGUST 1, 1996) Print 104th...

Published: August 1, 1996

4. Source: time.com
Title: The Pentagon’s Computer Security Problem
Link:https://time.com/archive/6928744/the-pentagons-computer-security-problem-2/

5. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

6. Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm

Source snippet

Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...

7. Source: irp.fas.org
Link:https://irp.fas.org/congress/1996_hr/s960605t.htm

Source snippet

SENATE PERMANENT SUBCOMMITTEE ON INVESTIGATIONS (Minority Staff) HEARINGS ON JUNE 5, 1996 TABLE O...

Published: June 5, 1996

8. Source: gao.gov
Link:https://www.gao.gov/products/t-rced

9. Source: gao.gov
Title: nsiad 94 248
Link:https://www.gao.gov/products/nsiad

10. Source: gao.gov
Title: nsiad 94 219
Link:https://www.gao.gov/products/nsiad

11. Source: gao.gov
Title: nsiad 94 220
Link:https://www.gao.gov/products/nsiad

12. Source: gao.gov
Title: osi 94 11
Link:https://www.gao.gov/products/osi

13. Source: pbs.org
Title: The Risks
Link:https://www.pbs.org/wgbh/frontline/wgbh/pages/frontline/shows/hackers/risks/dodattacks.html

14. Source: pbs.org
Title: The Risks
Link:https://www.pbs.org/wgbh/pages/frontline/shows/hackers/risks/dodattacks.html

Additional References

15. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a

Source snippet

May 22, 1996. Unclassified. | National Security Archive...

Published: May 22, 1996

16. Source: youtube.com
Link:https://www.youtube.com/watch?v=AcUauAwB_FM

Source snippet

[TOP 10] LEGVESZÉLYESEBB HACKER A VILÁGON Aki Hatalmas Káoszt Okozott...

17. Source: youtube.com
Title: [TOP 10] LEGVESZÉLYESEBB HACKER A VILÁGON Aki Hatalmas Káoszt Okozott!
Link:https://www.youtube.com/watch?v=5BCUMlUw3JA

Source snippet

Top 10 most dangerous hackers of all time...

18. Source: youtube.com
Title: Top 10 Cei mai Buni HACKERI
Link:https://www.youtube.com/watch?v=1OTAtROfi-I

Source snippet

15 ÉVESEN FELTÖRTE A NASA RENDSZERÉT, MAJD ELTŰNT! | A LEGVESZÉLYESEBB HACKEREK A VILÁGON...

19. Source: youtube.com
Title: Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub
Link:https://www.youtube.com/watch?v=z7OjzYT_-Zo

Source snippet

Top 10 Cei mai Buni HACKERI...

20. Source: gao.justia.com
Title: committee on governmental affairs osi 94 30
Link:https://gao.justia.com/national-aeronautics-and-space-administration/1994/7/committee-on-governmental-affairs-osi

21. Source: youtube.com
Title: Top 10 most dangerous hackers of all time
Link:https://www.youtube.com/watch?v=LGo2VSZUHDs

22. Source: nsarchive.gwu.edu
Title: 21407 document 10b
Link:https://nsarchive.gwu.edu/document/21407-document-10b

23. Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/

24. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/media/21407/ocr