Within Richard Pryce

Why a London Teenager Looked Like a Foreign Agent

International routing, military targets and aerospace interest made the campaign resemble organised espionage before investigators found a teenager.

27 sources 3 graphics
Preview for Why a London Teenager Looked Like a Foreign Agent

On this page

  • Why the intrusion pattern suggested espionage
  • How international routing obscured the attacker
  • How Pryce's identification changed the case narrative

Introduction

When United States investigators first examined the 1994 intrusions linked to the hacker known as Datastream Cowboy, they did not assume they were dealing with a curious teenager. The pattern of attacks looked far more like a coordinated intelligence operation. Sensitive Air Force research systems had been penetrated, military computers were being used as launch points into other government networks, and the connections appeared to originate through a complex chain of international telephone and internet systems. Before Richard Pryce was identified, investigators seriously considered whether the attacks were the work of a foreign intelligence service rather than an individual hacker.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Spy Suspicions illustration 1

This suspicion illustrates how difficult attribution was in the early internet era. The same technical features that helped attackers conceal their identities—international routing, compromised intermediary systems and anonymous online aliases—also made relatively unsophisticated hackers resemble professional espionage operators.

Why the intrusion pattern suggested espionage

Several characteristics of the campaign immediately raised the possibility of foreign intelligence involvement.

First, the targets were unusually sensitive. The primary victim was Rome Laboratory at Griffiss Air Force Base, one of the US Air Force’s leading command-and-control research facilities. Investigators found evidence that the attackers had accessed research relating to artificial intelligence, radar systems and air tasking orders—information with clear military value. They also used compromised Air Force computers to reach NASA facilities, defence contractors and other government systems.[gwu.edu]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

Second, the attackers behaved in ways consistent with professional concealment. Rather than connecting directly, they chained together multiple telephone and internet systems across different countries before reaching US military networks. At the time, such routing significantly complicated efforts to identify the true origin of the intrusion. To investigators seeing only fragments of the connection path, the activity appeared international by design rather than the work of someone sitting in a London bedroom.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Third, investigators believed there were at least two individuals involved. Air Force monitoring suggested that the user known as Datastream Cowboy sometimes failed to penetrate a system, contacted another hacker using the alias “Kuji”, and then returned with a successful technique. This led investigators to suspect a division of labour rather than a lone enthusiast. Some investigators even considered the possibility that one participant was acting as an intelligence collector while the other provided technical support.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

How international routing obscured the attacker

The methods used to hide the attacks reinforced the impression of an organised foreign operation.

British investigators later established that the intrusions coincided with telephone fraud carried out from Pryce’s home. The attack path frequently passed through multiple countries in South America and Europe before travelling via Mexico, Hawaii and commercial internet providers into US military networks. From Rome Laboratory itself, further attacks were launched against additional systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

This layering created several problems for investigators:

  • Every intermediary system obscured the attacker’s true location.
  • The traffic appeared to cross numerous national jurisdictions.
  • Military computers became unwitting staging points for additional intrusions, making later victims appear to have been attacked by the US Air Force itself.
  • The international nature of the routing resembled techniques already associated with espionage tradecraft, even though many hackers used similar methods simply to avoid detection.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The situation became particularly sensitive when Rome Laboratory was used to access the Korea Atomic Research Institute. According to later Air Force accounts, officials initially worried that if the target had been in North Korea, activity appearing to originate from an American military laboratory might have created diplomatic or even military misunderstandings during an already tense period on the Korean Peninsula.[Air & Space Forces Magazine]airandspaceforces.comAir & Space Forces Magazine War in Cyberspace | Air & Space Forces MagazineAir & Space Forces Magazine War in Cyberspace | Air & Space Forces Magazine

Spy Suspicions illustration 2

Why officials initially considered a foreign intelligence service

The broader security environment also shaped official thinking.

By the mid-1990s, US defence planners had become increasingly concerned that hostile states might use computer networks to steal military research without deploying traditional spies. Congressional testimony delivered after the Rome Laboratory incident repeatedly warned that foreign governments could disguise intelligence collection behind what looked like ordinary hacker activity. The Datastream Cowboy case became one of the leading examples used to explain this emerging threat.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

Government analysts could not immediately determine:

  • whether military research had been stolen on behalf of another country;
  • whether multiple attackers represented an organised intelligence team;
  • whether the international routing reflected operational necessity or deliberate deception; or
  • whether the stolen material had already been transferred beyond the identified attackers.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

These uncertainties made an espionage hypothesis appear plausible until investigators accumulated stronger attribution evidence.

How Pryce’s identification changed the case narrative

The turning point came through conventional investigative work rather than a dramatic technical breakthrough.

An informant supplied investigators with an earlier online conversation in which Datastream Cowboy claimed to be a 16-year-old from the United Kingdom who enjoyed attacking “.mil” systems because they were poorly secured. The same correspondence included a telephone number associated with the hacker’s bulletin board system. Scotland Yard linked that number to Richard Pryce’s home, while British Telecom monitoring showed that suspicious telephone activity coincided with the American intrusions.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

When British police searched Pryce’s home in May 1994, they found not an experienced foreign intelligence operative but a teenager using comparatively modest computer equipment. Investigators also recovered stolen files and evidence linking him to the intrusions. Although the technical impact of the attacks remained serious, the discovery forced a reassessment of assumptions about who could compromise high-value military networks.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The identification of Pryce did not eliminate every uncertainty. His associate “Kuji” remained unidentified for a longer period, allowing speculation about more sophisticated collaborators to continue. Nevertheless, the central narrative shifted from suspected state espionage to an illustration of how weak network security could allow young civilian hackers to create incidents with strategic consequences.[gwu.edu]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

Spy Suspicions illustration 3

The lasting lesson from the mistaken suspicion

The Datastream Cowboy investigation became an early demonstration of a problem that still affects cyber security today: technical evidence alone rarely reveals who is actually behind an intrusion.

International routing, military targets and apparent operational sophistication made the attacks resemble foreign espionage. Yet the investigation ultimately showed that many of those same characteristics could also arise from technically capable teenagers exploiting insecure networks while attempting to conceal their identities. The case therefore highlighted both the difficulty of cyber attribution and the danger of drawing strategic conclusions before investigators have identified the people responsible.[gwu.edu]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

Amazon book picks

Further Reading

Books and field guides related to Why a London Teenager Looked Like a Foreign Agent. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromretro computer art oneBay.co.uk.

Endnotes

1. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Datastream Cowboy
Link:https://www.kujimedia.com/tag/datastream-cowboy/

Source snippet

» Datastream CowboyJune 26, 2008 — Despite this extraordinary behaviour, Whitely served only two months in prison in 1990. 1990 Briton Ti...

Published: June 26, 2008

2. Source: kujimedia.com
Link:https://www.kujimedia.com/tales-of-digital-crime-from-the-shadows-of-cyberspace-chapter-six/

Source snippet

Kuji Media Corporation Ltd. » Blog Archive » Tales of Digital Crime from the Shadows of Cyberspace – Chapter Six...

3. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Blog Archive » THE SCHOOLBOY SPY. Sunday Times
Link:https://www.kujimedia.com/the-schoolboy-spy-sunday-times/

4. Source: kujimedia.com
Link:https://www.kujimedia.com/british-teenager-fined-after-hacking-into-us-defence-system/

5. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Datastream Cowboy
Link:https://www.kujimedia.com/tag/datastream-cowboy/page/2/

6. Source: kujimedia.com
Title: Kuji Media Corporation Ltd. » Richard Pryce
Link:https://www.kujimedia.com/tag/richard-pryce/page/2/

7. Source: kujimedia.com
Link:https://www.kujimedia.com/articles/

8. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

9. Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr

10. Source: airandspaceforces.com
Title: Air & Space Forces Magazine War in Cyberspace | Air & Space Forces Magazine
Link:https://www.airandspaceforces.com/article/0198cyber/

11. Source: airandspaceforces.com
Link:https://www.airandspaceforces.com/article/0397sweepers/

12. Source: irp.fas.org
Title: ssci ames
Link:https://irp.fas.org/congress/1994_rpt/ssci_ames.htm

Additional References

13. Source: toptensofall.wordpress.com
Title: Bevan began to lead a double-life, a normal school life during the day foll
Link:https://toptensofall.wordpress.com/[mathew-bevan

Source snippet

Bevan and Richard Price – toptensofallMay 19, 2015 — Having been told ways to negate the phone system, he could call anywhere in the worl...

Published: May 19, 2015

14. Source: korben.info
Title: Deux ados cherchant des OVNIS ont failli lancer la WW3
Link:https://korben.info/kuji-datastream-cowboy-pentagone-hack-1996-histoire-complete.html

Source snippet

Ils laissent des traces partout, copient des gigaoctets de données sans discrimination, et communi...

15. Source: youtube.com
Title: Nation-state hackers: Exploiting security flaws for cyber espionage
Link:https://www.youtube.com/watch?v=1V3gbsA9AZ4

Source snippet

Datastream Cowboy Pryce THE HACKER WHO EXPOSED THE PENTAGON'S GREATEST WEAKNESS KRYPT Files...

16. Source: youtube.com
Title: Unveiling the Untold Saga of Kuji and Datastream Cowboy
Link:https://www.youtube.com/watch?v=n_iLfffJbzo

Source snippet

A 17-Year-Old Hacked Apple, Microsoft And The Pentagon From His Bedroom...

17. Source: intelligence.senate.gov
Link:https://www.intelligence.senate.gov/1994/11/01/publications-assessment-aldrich-h-ames-espionage-case-and-its-implications-us-intelligence-november/

18. Source: youtube.com
Title: A 17-Year-Old Hacked Apple, Microsoft And The Pentagon From His Bedroom
Link:https://www.youtube.com/watch?v=5QpwxXPo1Kk

Source snippet

Gary Mckinnon: The Hacker Who Found UFOs...

19. Source: youtube.com
Title: THE HACKER WHO EXPOSED THE PENTAGON’S GREATEST WEAKNESS
Link:https://www.youtube.com/watch?v=ltNqoeAEx20

Source snippet

Unveiling the Untold Saga of Kuji and Datastream Cowboy...

20. Source: youtube.com
Title: Gary Mckinnon: The Hacker Who Found UFOs
Link:https://www.youtube.com/watch?v=8_1DuqeU8hw

Source snippet

Nation-state hackers: Exploiting security flaws for cyber espionage...

21. Source: all.net
Link:https://all.net/books/iw/iwarstuff/www.af.mil/news/airman/0496/hacker.htm

22. Source: independent.co.uk
Link:https://www.independent.co.uk/news/fine-for-boy-who-hacked-into-pentagon-1274204.html