Within Early Insecurity

When a Military Lab Became an Attack Platform

The Rome Laboratory breach revealed how attackers could turn one military network into a launch point for attacks on many others.

34 sources 3 graphics
Preview for When a Military Lab Became an Attack Platform

On this page

  • How attackers gained control at Rome Laboratory
  • Using compromised hosts to reach other sites
  • What the case revealed about internal trust

Introduction

The 1994 intrusion into the US Air Force’s Rome Laboratory became one of the earliest and most influential demonstrations of how a compromised military system could be turned into a platform for attacking many other organisations. Rather than treating the laboratory as the final target, the intruders used it as a trusted intermediary, allowing them to move through networks while appearing to be legitimate users. This incident highlighted a weakness that would later become central to modern cybersecurity: once attackers control a trusted host, the trust placed in that system can become a weapon against everyone connected to it.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Rome Lab illustration 1

Within the broader history of early internet insecurity—an environment that later enabled intrusions by figures such as Gary McKinnon—the Rome Laboratory case illustrated that the greatest danger often came not from breaking through every security barrier individually, but from exploiting the confidence that organisations placed in authenticated systems inside government and research networks.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

How attackers gained control at Rome Laboratory

Rome Laboratory, located at Griffiss Air Force Base in New York, was a major US Air Force research centre conducting work with defence contractors, universities and other government agencies. Because of these relationships, its computer systems maintained trusted connections with numerous external organisations, making them especially valuable once compromised.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Investigators determined that the attackers obtained unauthorised access and installed network sniffers—programs designed to capture usernames and passwords travelling across local networks. At the time, many network protocols transmitted credentials in clear text, allowing attackers to collect valid login information without having to crack encrypted passwords.

Once enough legitimate credentials had been harvested, the intruders no longer needed to rely on obvious break-in techniques. Instead, they logged in using genuine user accounts, making their activity resemble ordinary administrative or research traffic. According to congressional testimony and Air Force reporting, the intrusion remained undetected for several days before the discovery of the sniffer triggered an investigation involving the Defense Information Systems Agency (DISA), the Air Force Office of Special Investigations (AFOSI) and other specialists.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Using compromised hosts to reach other sites

The Rome Laboratory compromise became especially significant because the attackers did not stop at the laboratory itself. Investigators found that they used the laboratory’s computers as launch points for further intrusions into other government, contractor and private-sector systems.

According to the US Government Accountability Office, by masquerading as trusted Rome Laboratory users, the attackers successfully reached systems at:

  • Defence contractors.
  • Additional government organisations.
  • Various private-sector computer systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…

This technique offered several advantages.

Trusted network identity. Connections originating from Rome Laboratory appeared far less suspicious than traffic arriving directly from unknown overseas internet addresses.

Valid credentials. Because the attackers possessed legitimate usernames and passwords, many systems treated them as authorised users rather than intruders.

Reduced visibility. Security monitoring in the mid-1990s was largely focused on protecting organisational boundaries. Activity originating from another trusted military or research network often received less scrutiny.

The incident therefore demonstrated that compromising one respected institution could effectively expand an attacker’s reach far beyond the original breach.

Rome Lab illustration 2

What the case revealed about internal trust

The Rome Laboratory investigation exposed a broader architectural problem rather than a single technical flaw. Networks frequently assumed that authenticated users or trusted partner systems deserved broad access once inside.

Several weaknesses combined to make this possible:

  • Passwords could be captured because insecure protocols transmitted credentials without encryption.
  • Trust relationships between organisations were often generous and only lightly monitored.
  • Internal network traffic received less inspection than external traffic.
  • Authentication frequently established trust once, with relatively little ongoing verification of user behaviour.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Perhaps the most striking observation came from the Air Force’s own assessment, quoted by the Government Accountability Office. Investigators concluded that the attackers themselves had chosen not to cause lasting damage. The report warned that a more destructive intruder could have disabled systems before defenders even realised an attack was underway, leaving administrators effectively powerless to respond immediately.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…

Why the Rome Laboratory case became influential

Security professionals continue to cite the Rome Laboratory breach because it illustrated concepts that later became standard cybersecurity concerns.

First, it showed the importance of lateral movement—the process by which attackers use one compromised system to reach others rather than attacking every target directly.

Second, it demonstrated the danger of credential theft. Possessing legitimate usernames and passwords often proved more effective than exploiting additional software vulnerabilities.

Third, it revealed that trusted hosts could become liabilities. Organisations frequently invested heavily in defending their internet perimeter while assuming that authenticated internal systems could be relied upon. The Rome Laboratory incident showed that once an attacker controlled one trusted machine, that assumption could rapidly collapse.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Rome Lab illustration 3

Connection to later government intrusions

For readers examining the environment that later enabled UFO-motivated intrusions such as those associated with Gary McKinnon, the Rome Laboratory case provides an earlier and well-documented example of the same structural weakness. The central lesson was not that attackers possessed extraordinary capabilities, but that interconnected government networks often extended trust too broadly after an initial compromise.

The breach helped shift security thinking away from protecting only the network edge and towards protecting credentials, monitoring internal activity, and questioning whether any computer—even one inside a military network—should automatically be trusted simply because it had already been authenticated. Those principles later evolved into approaches such as network segmentation, stronger authentication and, ultimately, “zero trust” security models that assume every connection requires continuous verification rather than inherited trust.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Amazon book picks

Further Reading

Books and field guides related to When a Military Lab Became an Attack Platform. Use these as the next step if you want deeper reading beyond the article.

BookCover for The Hacker Crackdown

The Hacker Crackdown

By Bruce Sterling

The bestselling cyberpunk author "has produced by far the most stylish report from the computer outlaw culture since Steven Levy's Hacker...

BookCover for Ghost in the Wires

Ghost in the Wires

By Kevin Mitnick

In this "intriguing, insightful and extremely educational" novel, the world's most famous hacker teaches you easy cloaking and counter-me...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromUS Air Force patch oneBay.co.uk.

Endnotes

1. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

2. Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm

Source snippet

Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...

Additional References

3. Source: silicon.co.uk
Title: Moonlight Maze Attack Still Relevant Two Decades After Initial Debut
Link:https://www.silicon.co.uk/security/cyberwar/moonlight-maze-attack-208551

Source snippet

April 4, 2017 — MOONLIGHT MAZE ATTACK STILL RELEVANT TWO DECADES AFTER INITIAL DEBUT Attack code first used in 1996 is still in use by at...

Published: April 4, 2017

4. Source: wired.com
Title: meet the mad scientist who wrote the book on how to hunt hackers
Link:https://www.wired.com/story/meet-the-mad-scientist-who-wrote-the-book-on-how-to-hunt-hackers/

Source snippet

Meet Cliff Stoll, the Mad Scientist Who Invented the Art of Hunting Hackers | WIREDDecember 18, 2019 — Andy Greenberg The Big Story Dec 1...

Published: December 18, 2019

5. Source: afresearchlab.com
Title: Connecting warfighters at the edge with a RIPL | Air Force Research Laboratory
Link:https://afresearchlab.com/news/connecting-warfighters-at-the-edge-with-a-ripl/

Source snippet

(AFRL) — The Air Force Research Laboratory, or AFRL, demonstrated its robust information...

6. Source: rmmagazine.com
Title: Risk Management Magazine
Link:https://www.rmmagazine.com/articles/article/2011/10/01/-Hacking-the-Military-

Source snippet

Stevenson III | October 1, 2011 Not Even The Department of Defense is impervious Rome Laboratory, located in the rolling hills of Upstate...

Published: October 1, 2011

7. Source: archives.gov
Link:https://www.archives.gov/research/military/air-force/ufos

Source snippet

Project BLUE BOOK - Unidentified Flying Objects | National ArchivesJune 25, 2024 — THE "ROSWELL INCIDENT" The National Archives has been...

Published: June 25, 2024

8. Source: pindrop.com
Title: The origina
Link:https://www.pindrop.com/article/moonlight-maze-attacks-us-government-modern-campaigns/

Source snippet

Moonlight Maze Attacks to Modern Campaigns | PindropApril 3, 2017 — The new details come from a months-long analysis of data and logs fro...

Published: April 3, 2017

9. Source: usenix.org
Link:https://www.usenix.org/event/hotsec08/tech/full_papers/parno/parno_html/index.html

10. Source: usenix.org
Link:https://www.usenix.org/conference/usenixsecurity25/presentation/munteanu

11. Source: independent.co.uk
Link:https://www.independent.co.uk/news/government-inquiry-decides-satanic-abuse-does-not-exist-no-evidence-in-84-cases-of-alleged-black-magic-rituals-evangelical-christians-and-selfstyled-experts-blamed-for-scares-1372240.html

12. Source: independent.co.uk
Link:https://www.independent.co.uk/news/uk/satanic-abuse-dismissed-as-myth-by-government-inquiry-report-blames-evangelical-christians-and-specialists-for-the-scare-which-led-to-investigations-rosie-waterhouse-reports-1420013.html