Within UFO Hackers
How One Weak System Opened a Defence Network
The 1994 Rome Laboratory breach showed how one weak system could become a bridge into a much larger defence and research network.
On this page
- The initial Rome Laboratory access
- Expansion into connected systems
- Why the incident changed cybersecurity
Page outline Jump by section
Introduction
The 1994 Rome Laboratory breach showed how a compromise in one research network could become a gateway into a much wider government and defence ecosystem. Over a 26-day period beginning on 23 March, intruders repeatedly entered systems at the US Air Force’s principal command-and-control research centre in Rome, New York. They installed password-capturing software, gained control of dozens of machines and then used trusted Rome Laboratory connections to reach NASA, military contractors and other organisations. More than 150 known intrusions were recorded.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…

The incident is sometimes remembered mainly because one alleged participant, Mathew Bevan, was associated with a search for UFO-related secrets. Its greater historical importance, however, lies in the mechanism of the breach. The attackers did not need to defeat every organisation separately. Once established inside Rome Laboratory, they could collect credentials and present themselves to connected systems as legitimate users. The case therefore became an early demonstration that network security was only as strong as the weakest trusted machine.
The initial Rome Laboratory access
Rome Laboratory was not an ordinary office network. It conducted research into artificial intelligence, radar guidance, target detection and battlefield command systems, working with universities, commercial research centres and defence contractors. That collaboration made internet connectivity useful, but it also created routes between organisations that had very different security practices.[National Security Archive]nsarchive2.gwu.eduOpen source on gwu.edu.
Official accounts do not provide a complete, publicly documented reconstruction of the first exploit. They state that the intruders used familiar techniques of the period, including Trojan-horse programs and network “sniffers”, rather than describing a single spectacular software flaw. A Trojan horse appeared to perform an ordinary function while secretly granting privileges or preserving a hidden route back into the machine. A sniffer silently recorded traffic crossing a network, including usernames and passwords sent without strong protection.[GovInfo]govinfo.govGAOREPORTS T AIMDInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks…
The first confirmed penetration occurred on 23 March 1994. It remained undiscovered until 28 March, when a systems administrator noticed an unauthorised file. That five-day interval was critical. The attackers had time to establish themselves, download information and place sniffers on seven systems before defenders understood the scale of the intrusion.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
Those seven infected systems became credential-collection points. According to evidence presented to a US Senate investigation, their sniffers helped compromise 30 Rome Laboratory machines and more than 100 user accounts. The intruders could read captured credentials, return as authorised users and move through the environment without repeatedly breaking through its outer boundary. Emails were reportedly read, copied or deleted, while sensitive but unclassified battlefield-simulation material was accessed and copied.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
This was the central security failure. Initial access mattered, but the decisive advantage came from the network’s internal trust. Once the attackers could impersonate genuine researchers and contractors, ordinary logins became tools for expansion.
Expansion into connected systems
Rome Laboratory became both a victim and an involuntary launch platform. Investigators found that its machines had been used to attack the US Army Corps of Engineers in Mississippi, NASA facilities, Wright-Patterson Air Force Base, Brookhaven National Laboratory, defence contractors and other academic, commercial and government systems. Later summaries estimated that roughly 100 outside systems were targeted or penetrated from Rome.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
The expansion followed a repeatable pattern:
- Capture a legitimate login. Sniffers recorded the address, username and password used when a Rome Laboratory employee or contractor connected elsewhere.
- Impersonate the account holder. The intruders reused those details to enter the external organisation as an apparently trusted user.
- Install another sniffer or hidden access mechanism. The new machine became another source of credentials.
- Repeat the process. Each compromised system created possible routes into further networks.
One especially clear example involved aerospace contractors. Investigators reported that the attackers captured contractor credentials as employees connected from Rome Laboratory to systems in California and Texas. Those credentials were then used to masquerade as authorised users, compromising at least five contractor machines.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
The attackers also obscured their origin by routing communications through telephone systems and internet services in multiple countries. Official investigators traced activity through commercial providers in New York and Seattle, while British telephone monitoring indicated that connections had passed through parts of Europe, South America, Mexico and Hawaii. This did not make attribution impossible, but it prevented investigators from simply following one continuous electronic trail back to a home address.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
The investigation therefore combined technical surveillance with conventional detective work. Air Force personnel secured most compromised machines but deliberately left a limited area accessible, creating what the Government Accountability Office called an “electronic fishbowl”. Keystroke monitoring allowed investigators to watch the intruders’ activity while restricting the damage they could cause. Informants, email evidence, telephone records and cooperation with New Scotland Yard eventually helped identify the hacker using the name “Datastream Cowboy” as 16-year-old Richard Pryce.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
The Korean research-centre scare
The most dramatic episode occurred on 15 April 1994. From a Rome Laboratory computer, an intruder entered a machine identified as belonging to a Korean atomic research institute and transferred its files back into storage at Rome. Investigators observing the session could not immediately determine whether the target was in North Korea or South Korea.[Air & Space Forces Magazine]airandspaceforces.comAir & Space Forces Magazine
That uncertainty exposed a new kind of geopolitical danger. To the Korean organisation, the activity could appear to originate from a US Air Force research centre. The true operator’s age, location and motives would not have been visible in the network records. Officials briefly feared that an intrusion into a North Korean nuclear-research system might be interpreted as American espionage or an aggressive military act. The institute was eventually confirmed to be South Korean, so the feared confrontation did not materialise.[Air & Space Forces Magazine]airandspaceforces.comAir & Space Forces Magazine
The episode is important without accepting later claims that the teenagers nearly caused a world war. No retaliation occurred, and the target was not North Korean. The lasting lesson was narrower and more credible: a compromised military computer could give an independent intruder the apparent identity of the United States government. Network origin was not proof of state authorship.
What information was exposed
The attackers obtained material connected with air tasking orders. These are the operational instructions used to communicate targeting, intelligence and air-battle requirements to pilots and other weapons-system operators. The compromised files concerned research rather than a live wartime order, but their value lay in what they could reveal about the design and development of future command systems.[GovInfo]govinfo.govGAOREPORTS T AIMDInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks…
Rome officials estimated that the affected air-tasking-order project represented approximately three years of work and $4 million in investment. Investigators did not report that the entire project had been destroyed; rather, they warned that this was the likely reconstruction cost had the research become unusable. The distinction matters because some retellings blur compromised information, permanent destruction and direct operational damage.[National Security Archive]nsarchive2.gwu.eduOpen source on gwu.edu.
The documented recovery and investigation costs exceeded $500,000. This covered taking systems offline, checking their integrity, installing security patches, restoring service and deploying investigative personnel. It did not include the uncertain value of copied research or damage caused at outside organisations reached through Rome Laboratory.[GovInfo]govinfo.govGAOREPORTS T AIMDInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks…
Nor could investigators prove that every hidden modification had been found. The Air Force’s own technical assessment observed that defenders had depended on the intruders choosing not to destroy the network immediately. Government auditors added that officials could not be certain that no lasting damage remained or establish what ultimately happened to copied data.[National Security Archive]nsarchive2.gwu.eduOpen source on gwu.edu.
Where the UFO connection fits
The incident belongs in the history of UFO-motivated hacking because Mathew Bevan, identified by British authorities as “Kuji”, was later described as having an interest in UFO secrecy and advanced military technology. That connection resembles Gary McKinnon’s later explanation that he entered US government systems while looking for concealed evidence about UFOs and suppressed technology.
It should not dominate the explanation of the Rome Laboratory breach, however. Contemporary US reports concentrated on what the hackers did inside the network, not on proving a shared UFO mission. They initially treated Kuji’s identity and intentions as uncertain, even considering whether a foreign intelligence connection was possible. Later criminal proceedings against Bevan collapsed, while Pryce pleaded guilty to offences under the UK Computer Misuse Act and was fined.[govinfo.gov]govinfo.govGAOREPORTS T AIMDInformation Security: Computer Attacks at Department of Defense Pose Increasing Risks…
Nothing publicly documented from the Rome Laboratory investigation established the existence of alien technology, recovered spacecraft or a secret extraterrestrial programme. The verifiable discovery was instead the vulnerability of interconnected defence systems. The UFO interest helps explain why some hackers were attracted to military research networks; it does not authenticate the secrets they hoped to find.
Why the incident changed cybersecurity
Rome Laboratory became a landmark case because it concentrated several emerging risks into one event. A small number of people using ordinary home equipment exploited reusable credentials, weak internal controls and extensive network trust to gain influence far beyond the first compromised machine. The sophistication lay less in an exotic exploit than in chaining simple techniques across connected systems.
The case changed the security conversation in three important ways.
Detection became as important as prevention. Rome Laboratory did not recognise the intrusion for five days. Broader Department of Defense testing at the time found that military organisations detected only a small fraction of successful simulated penetrations. A secure perimeter was of limited value if activity inside it was not logged, reviewed and understood.[National Security Archive]nsarchive2.gwu.eduOpen source on gwu.edu.
Trusted connections became recognised attack paths. Partnerships with contractors, universities and other government organisations were operationally valuable, but every connection widened the area an attacker could explore. The incident demonstrated that credentials collected on one network could unlock another, and that a respected military address could disguise an outsider’s actions.
Incident response required coordination across borders and institutions. The inquiry involved laboratory administrators, the Defense Information Systems Agency, Air Force investigators, technical specialists, internet providers, informants, British Telecom and New Scotland Yard. The attackers crossed organisational and national boundaries more quickly than legal and investigative procedures could follow them.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion…
In the years that followed, the Air Force expanded central monitoring, emergency-response capabilities, security education and installation-level firewalls. Rome Laboratory was not the sole cause of those reforms, but it provided a concrete case that officials could use to demonstrate the consequences of poor detection, inconsistent patching and excessive network trust.[Air & Space Forces Magazine]airandspaceforces.comOpen source on airandspaceforces.com.
The incident’s most durable lesson is that a “weak system” need not contain the most valuable information itself. Its importance may come from who trusts it, whose credentials pass through it and which other networks accept its connections. At Rome Laboratory, the initial foothold opened not one isolated computer but a chain of relationships extending across the American defence and research community.
Amazon book picks
Further Reading
Books and field guides related to How One Weak System Opened a Defence Network. Use these as the next step if you want deeper reading beyond the article.
Dark Territory: The Secret History of Cyber War
“An important, disturbing, and gripping history” (Kirkus Reviews, starred review), the never-before-told story of the computer scientists...
The Hacker Crackdown: Law and Disorder on the Electronic Fron...
The bestselling cyberpunk author "has produced by far the most stylish report from the computer outlaw culture since Steven Levy's Hacker...
Cyberpunk: Outlaws and Hackers on the Computer Frontier
Using the exploits of three international hackers, "Cyberpunk" provides a fascinating tour of a bizarre subculture populated by outlaws w...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromhacker t shirt oneBay.co.uk.
Endnotes
1.
Source: govinfo.gov
Title: GAOREPORTS T AIMD 96 92
Link:https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-96-92/html/GAOREPORTS-T-AIMD-96-92.htm
Source snippet
Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...
2.
Source: airandspaceforces.com
Title: Air & Space Forces Magazine
Link:https://www.airandspaceforces.com/PDF/MagazineArchive/Documents/1998/January%201998/0198cyber.pdf
3.
Source: isc2.org
Title: CISSP30 30 Years After 2 Kids Broke into the Air Force
Link:https://www.isc2.org/Insights/2024/09/CISSP30-30-Years-After-2-Kids-Broke-into-the-Air-Force
Source snippet
ISC2#CISSP30: 30 Years After Two Kids Broke into the Air Force12 Sept 2024 — He was eventually convicted of 12 breaches of the U.K.'s Com...
4.
Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm
Source snippet
Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY Intrusion...
5.
Source: nsarchive2.gwu.edu
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/docs/Cyber-010a.pdf
6.
Source: airandspaceforces.com
Link:https://www.airandspaceforces.com/article/0397sweepers/
7.
Source: trulyadventure.us
Title: the hacker
Link:https://www.trulyadventure.us/the-hacker
8.
Source: kujimedia.com
Title: Richard Pryce
Link:https://www.kujimedia.com/tag/richard-pryce/page/2/
9.
Source: christianespinosa.com
Title: richard pryce
Link:https://christianespinosa.com/blog/tag/richard-pryce/
10.
Source: Wikipedia
Title: Mathew Bevan
Link:https://en.wikipedia.org/wiki/Mathew_Bevan
11.
Source: data.qld.gov.au
Link:https://www.data.qld.gov.au/datastore/dump/71d98015-6742-452d-82a9-836cebf86fd6?bom=True
Additional References
12.
Source: theguardian.com
Link:https://www.theguardian.com/technology/2002/nov/13/hacking.internetcrime
Source snippet
The GuardianUS seeks extradition of Briton accused of hacking into...12 Nov 2002 — Pryce was fined £1,200 in 1997 but the case against M...
13.
Source: youtube.com
Title: Gary Mc Kinnon: The UFO Hunter Who Hacked the Pentagon
Link:http://www.youtube.com/watch?v=Gb5dvf6ZCYY
Source snippet
Kaise Ek 16 Saal Ke Hacker Ne US Defense Ko Hila Diya The Darknet Hub · 5.2K views...
14.
Source: youtube.com
Link:http://www.youtube.com/watch?v=-1ATzz7Gfdc
Source snippet
Gary McKinnon: The UFO Hunter Who Hacked the Pentagon...
15.
Source: youtube.com
Title: THE HACKER WHO EXPOSED THE PENTAGON’S GREATEST WEAKNESS
Link:http://www.youtube.com/watch?v=ltNqoeAEx20
Source snippet
Unveiling the Untold Saga of Kuji and Datastream Cowboy...
16.
Source: youtube.com
Title: Gary Mckinnon: The Hacker Who Found UFOs
Link:http://www.youtube.com/watch?v=8_1DuqeU8hw
Source snippet
Hacker Gary McKinnon about NASAs UFOs and other technologies 2015...
17.
Source: facebook.com
Link:https://www.facebook.com/groups/1766641996918028/posts/4288399188075617/
18.
Source: facebook.com
Link:https://www.facebook.com/groups/253557958093480/posts/2527069564075630/
19.
Source: royalholloway.ac.uk
Link:https://www.royalholloway.ac.uk/media/7205/isg-1516-newsletter.pdf
20.
Source: youtube.com
Title: Unveiling the Untold Saga of Kuji and Datastream Cowboy
Link:http://www.youtube.com/watch?v=n_iLfffJbzo
Source snippet
Gary Mckinnon: The Hacker Who Found UFOs...
21.
Source: linkedin.com
Link:https://www.linkedin.com/posts/jamesmcmurry_throwbackthursday-cyberhistory-romelabhack-activity-7371961568449724416-NRP_



