Within Mathew Bevan
How Rome Laboratory Opened the Wider Network
The Rome Laboratory breach gave Bevan and Richard Pryce a trusted foothold for reaching wider US military and space networks.
On this page
- The March April 1994 intrusion campaign
- How sniffers captured reusable credentials
- Why Rome Laboratory enabled further access
Page outline Jump by section
Introduction
For Mathew Bevan and Richard Pryce, the 1994 compromise of the US Air Force’s Rome Laboratory was not merely a successful intrusion but the operational launch point that enabled access to a much wider collection of military, government and aerospace networks. Rather than attacking every target independently, the pair exploited a trusted research network, installed password-stealing software, and then used the credentials they harvested to move laterally into other organisations. This approach transformed one breach into a chain of compromises that eventually reached systems connected with NASA, defence contractors and Wright-Patterson Air Force Base—the installation that later became central to Bevan’s Roswell-related claims. Contemporary US investigations consistently describe Rome Laboratory as the pivotal staging ground from which the wider campaign expanded.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
The March–April 1994 Intrusion Campaign
Rome Laboratory, located at Griffiss Air Force Base in New York, served as the Air Force’s principal command-and-control research facility. Its researchers collaborated extensively with universities, defence contractors and other government organisations, making it unusually well connected to external networks for its time. That connectivity also made it an attractive pivot point once attackers obtained a foothold.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Investigators determined that the initial penetration occurred on 23 March 1994, although administrators did not discover the compromise until 28 March after detecting an unauthorised network-monitoring program. By then, multiple systems had already been compromised. The subsequent investigation attributed more than 150 known intrusion attempts over a 26-day period to the campaign carried out by Richard Pryce (“Datastream Cowboy”) and Mathew Bevan (“Kuji”), although the precise division of activity between the two remained difficult to reconstruct from technical evidence alone.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Rather than simply copying files, the attackers sought to establish persistence. Once they controlled machines inside Rome Laboratory, they were able to return repeatedly while appearing to originate from a trusted Air Force network, greatly increasing the value of their initial compromise.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
How Sniffers Captured Reusable Credentials
The mechanism that made Rome Laboratory such an effective launch point was the installation of “sniffer” programs. At the time, many network protocols transmitted usernames and passwords without encryption. A sniffer quietly monitored network traffic and recorded those credentials as authorised users logged into remote systems.
According to the Senate investigation, seven separate sniffers were installed, compromising around 30 Rome Laboratory systems and capturing credentials from more than 100 user accounts. The software also enabled the attackers to read, copy and sometimes delete users’ email while collecting authentication details for future use.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
The importance of these credentials went beyond Rome Laboratory itself. Researchers, contractors and administrators routinely authenticated to external organisations from within the Air Force network. As they logged into remote computers, the sniffers collected usernames, passwords and, in some cases, information identifying the destination systems. This effectively handed the attackers valid credentials for organisations that had never been directly breached.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
This method illustrates a broader security lesson from the early Internet era: compromising a trusted network often yielded access far beyond the original victim because authentication was frequently reused across interconnected systems.
Why Rome Laboratory Enabled Further Access
Rome Laboratory’s research mission made it unusually valuable as a stepping stone. It maintained operational relationships with defence contractors, NASA facilities, universities and other military organisations involved in command-and-control research. Once attackers possessed legitimate credentials harvested from Rome users, they could authenticate as authorised users elsewhere instead of relying solely on technical exploits.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
US investigators documented the attackers using Rome Laboratory as a launching platform against numerous additional networks. The campaign reached organisations including:
- NASA’s Goddard Space Flight Center.
- NASA’s Jet Propulsion Laboratory.
- Wright-Patterson Air Force Base.
- Multiple defence contractors.
- Academic and commercial computer systems connected through the Internet.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
One example highlighted during the investigation involved an aerospace contractor whose employees remotely accessed Rome Laboratory. The sniffers captured the contractors’ home-system credentials as they logged in. The attackers then impersonated those users to compromise several contractor systems in California and Texas before conducting additional reconnaissance from those machines. This demonstrates that Rome Laboratory functioned less as an end target than as a trusted credential-collection hub.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Why This Launch Point Mattered for Bevan’s UFO-Motivated Searches
Within the broader story of Mathew Bevan’s Roswell-motivated hacking, Rome Laboratory’s importance lies in the pathway it created rather than in any alleged UFO material stored there.
Bevan later stated that his interest centred on Wright-Patterson Air Force Base because he believed it might contain information related to the alleged Roswell recovery. Contemporary government investigations, however, indicate that access to Wright-Patterson occurred after Rome Laboratory had already been compromised and was being used as an operational base for further movement through interconnected networks. The available evidence therefore supports a sequence in which Rome Laboratory enabled access to additional military systems; it does not suggest that Rome Laboratory itself was the object of Bevan’s Roswell-related interest.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
This distinction is important because it separates documented forensic evidence from Bevan’s later personal explanations. The documented record establishes how the attackers moved through networks and why Rome Laboratory was strategically valuable. Claims about searching specifically for evidence of recovered extraterrestrial technology arise primarily from Bevan’s later accounts rather than from forensic records recovered during the investigation.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
A Turning Point in Military Network Security
The Rome Laboratory incident became one of the most influential early case studies in military cybersecurity because it demonstrated how a compromise of a single research institution could cascade through an interconnected defence ecosystem.
Government reviews concluded that the attackers temporarily gained control over important support systems, copied sensitive research data and forced extensive remediation efforts. The incident also exposed the risks created by clear-text authentication, trust relationships between organisations and inadequate monitoring of internal network traffic. These findings helped shape later improvements in intrusion detection, encrypted authentication and network segmentation across US defence systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…
Amazon book picks
Further Reading
Books and field guides related to How Rome Laboratory Opened the Wider Network. Use these as the next step if you want deeper reading beyond the article.
The Cuckoo's Egg
This is the true story of how a systems manager at Lawrence Berkeley Lab singlehandedly tracked down and helped capture a computer hacker...
Network Security Assessment
Covers offensive technologies by grouping and analyzing them at a higher level--from both an offensive and defensive standpoint--helping...
The Hacker and the State
Rating: 5.0/5 from 18 Google Books ratings
“A must-read...It reveals important truths.” —Vint Cerf, Internet pioneer “One of the finest books on information security published so f...
The Hacker's Handbook
Covers everything from illegal aspects to understandable explanations of telecomputing for every modem user. . . .a reference book on man...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromhacker t shirt oneBay.co.uk.
Endnotes
1.
Source: intelligence.senate.gov
Link:https://www.intelligence.senate.gov/1996/11/26/hearings-allegations-cia-connection-crack-cocaine-epidemic-october-23-and-november-26-1996/
Source snippet
of a CIA Connection to Crack Cocaine Epidemic (October 23 and November 26, 1996) | Senate Select Committee on IntelligenceNovember 26, 19...
Published: November 26, 1996
2.
Source: intelligence.senate.gov
Link:https://www.intelligence.senate.gov/1996/09/25/hearings-intelligence-assessments-exposure-us-military-personnel-chemical-agents-during-operation/
Source snippet
Military Personnel to Chemical Agents During Operation Sesert Storm (September 25, 1996) | Senate Select Committee on IntelligenceSeptemb...
Published: September 25, 1996
3.
Source: intelligence.senate.gov
Title: Hrg. 104-784 Download PDF
Link:https://www.intelligence.senate.gov/1996/08/01/hearings-international-terrorism-august-1-1996/
Source snippet
Terrorism (August 1, 1996) | Senate Select Committee on IntelligenceAugust 1, 1996 — INTERNATIONAL TERRORISM (AUGUST 1, 1996) Print 104th...
Published: August 1, 1996
4.
Source: time.com
Title: The Pentagon’s Computer Security Problem
Link:https://time.com/archive/6928744/the-pentagons-computer-security-problem-2/
5.
Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm
Source snippet
Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...
6.
Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm
Source snippet
Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...
7.
Source: irp.fas.org
Link:https://irp.fas.org/congress/1996_hr/s960605t.htm
Source snippet
SENATE PERMANENT SUBCOMMITTEE ON INVESTIGATIONS (Minority Staff) HEARINGS ON JUNE 5, 1996 TABLE O...
Published: June 5, 1996
8.
Source: gao.gov
Link:https://www.gao.gov/products/t-rced
9.
Source: gao.gov
Title: nsiad 94 248
Link:https://www.gao.gov/products/nsiad
10.
Source: gao.gov
Title: nsiad 94 219
Link:https://www.gao.gov/products/nsiad
11.
Source: gao.gov
Title: nsiad 94 220
Link:https://www.gao.gov/products/nsiad
12.
Source: gao.gov
Title: osi 94 11
Link:https://www.gao.gov/products/osi
13.
Source: pbs.org
Title: The Risks
Link:https://www.pbs.org/wgbh/frontline/wgbh/pages/frontline/shows/hackers/risks/dodattacks.html
14.
Source: pbs.org
Title: The Risks
Link:https://www.pbs.org/wgbh/pages/frontline/shows/hackers/risks/dodattacks.html
Additional References
15.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a
Source snippet
May 22, 1996. Unclassified. | National Security Archive...
Published: May 22, 1996
16.
Source: youtube.com
Link:https://www.youtube.com/watch?v=AcUauAwB_FM
Source snippet
[TOP 10] LEGVESZÉLYESEBB HACKER A VILÁGON Aki Hatalmas Káoszt Okozott...
17.
Source: youtube.com
Title: [TOP 10] LEGVESZÉLYESEBB HACKER A VILÁGON Aki Hatalmas Káoszt Okozott!
Link:https://www.youtube.com/watch?v=5BCUMlUw3JA
Source snippet
Top 10 most dangerous hackers of all time...
18.
Source: youtube.com
Title: Top 10 Cei mai Buni HACKERI
Link:https://www.youtube.com/watch?v=1OTAtROfi-I
Source snippet
15 ÉVESEN FELTÖRTE A NASA RENDSZERÉT, MAJD ELTŰNT! | A LEGVESZÉLYESEBB HACKEREK A VILÁGON...
19.
Source: youtube.com
Title: Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub
Link:https://www.youtube.com/watch?v=z7OjzYT_-Zo
Source snippet
Top 10 Cei mai Buni HACKERI...
20.
Source: gao.justia.com
Title: committee on governmental affairs osi 94 30
Link:https://gao.justia.com/national-aeronautics-and-space-administration/1994/7/committee-on-governmental-affairs-osi
21.
Source: youtube.com
Title: Top 10 most dangerous hackers of all time
Link:https://www.youtube.com/watch?v=LGo2VSZUHDs
22.
Source: nsarchive.gwu.edu
Title: 21407 document 10b
Link:https://nsarchive.gwu.edu/document/21407-document-10b
23.
Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/
24.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/media/21407/ocr



