Within Richard Pryce
What Did the Rome Laboratory Intruders Really Access?
Official reviews confirmed copied research and seized systems but could not reconstruct every file viewed, altered or removed.
On this page
- The research data known to have been copied
- What investigators could not reconstruct
- Why uncertainty mattered as much as confirmed loss
Page outline Jump by section
Introduction
The official record of the 1994 Rome Laboratory intrusions is both more specific and more uncertain than many later retellings suggest. Investigators confirmed that the intruders copied sensitive Air Force research data, captured hundreds of user credentials, accessed and manipulated email, and used compromised systems as staging points for attacks against other government and research networks. At the same time, multiple government reviews acknowledged a critical limitation: they could never reconstruct every file that had been viewed, copied, altered or removed. That unresolved uncertainty became one of the case’s most significant lessons. Rather than proving the theft of every classified secret imaginable, the investigation demonstrated how difficult it was—even for a well-resourced military investigation—to determine the full extent of a successful network compromise.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
The research data known to have been copied
Official Air Force and congressional documentation identifies several categories of information that investigators knew had been accessed or copied.
The most consistently documented theft involved sensitive but unclassified research held at Rome Laboratory, the Air Force’s premier command-and-control research centre. Investigators determined that the attackers downloaded data files from compromised systems after obtaining administrator-level access.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Among the specifically identified material were:
- Artificial intelligence research, reflecting Rome Laboratory’s work on advanced command-and-control technologies.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
- Radar guidance and target detection research, which formed part of the laboratory’s core mission.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
- Sensitive battlefield simulation program data, which investigators confirmed had been read and copied from compromised systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
- Air Tasking Order (ATO) research, perhaps the best documented example. Air tasking orders are the operational messages used to coordinate military air operations. The material stolen concerned research into these systems rather than wartime operational orders themselves. GAO testimony noted that this research could have required roughly three years and several million dollars to recreate had it been destroyed.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
Government reports deliberately distinguished between research supporting military operations and current operational battle plans. The evidence points to the theft of research and development material, not active combat orders.
Beyond documents: credentials, email and system control
The files themselves were only part of what the attackers acquired.
Investigators found that the intruders installed seven network “sniffer” programs that collected usernames and passwords as authorised users logged into the network. These sniffers compromised around 30 Rome Laboratory systems and captured credentials for more than 100 additional user accounts. Those credentials dramatically expanded what the attackers could legitimately access while appearing to be authorised users.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
The investigation also established that the attackers:
- read user email;
- copied email contents;
- deleted some email;
- installed additional malicious software to preserve future access; and
- gained complete access to the information stored on seven initially compromised systems before expanding further through the network.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
These actions meant that the compromise extended well beyond downloading isolated research files. The attackers effectively harvested the trust relationships embedded within the laboratory’s network.
What investigators could not reconstruct
Perhaps the most important finding of the official reviews is what they could not determine.
Although investigators documented more than 150 known intrusions during the monitored period, they repeatedly acknowledged that they were unable to reconstruct every action performed before discovery. By the time the sniffer software was detected, the attackers had already been active for several days and had administrative privileges on numerous systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Official investigations therefore could not establish with certainty:
- every file that had been viewed;
- every document that had been copied;
- whether earlier undetected intrusions had occurred before March 1994;
- whether additional systems had been compromised without leaving recoverable evidence;
- whether copied material had been redistributed after removal from Rome Laboratory.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Government reports are explicit that investigators never conclusively determined what ultimately happened to the copied research data. The unidentified collaborator known as “Kuji” was never found, leaving unanswered questions about where the material went and whether others received it.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
Why uncertainty mattered as much as confirmed loss
The inability to measure precisely what had been taken became a central governance lesson from the Rome Laboratory case.
GAO and Senate investigations argued that the greatest damage was not simply the confirmed theft of research files. Once attackers acquired privileged credentials and administrator access, defenders lost confidence in the integrity of the affected systems. Restoring trust required taking networks offline, validating system contents, reinstalling software, applying security patches and conducting lengthy forensic investigations. Those recovery activities accounted for much of the financial cost of the incident.[GAO]gao.govUnited States General Accounting OfficeUnited States General Accounting Office…
The Air Force could estimate the direct recovery expense, but it could not place a reliable value on the compromised research itself. Nor could it determine whether the theft represented ordinary hacking, espionage or preparation for future operations. GAO testimony noted that sensitive defence information may have very different value to a foreign intelligence service than to its original owner, making conventional accounting inadequate.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive
The enduring evidence
Within the broader story of Richard Pryce (“Datastream Cowboy”) and the Rome Laboratory intrusions, the evidence about what was actually taken is narrower—and more credible—than many popular accounts suggest.
The official record supports several firm conclusions:
- sensitive Air Force research files were copied;
- battlefield simulation and Air Tasking Order research were among the confirmed targets;
- extensive user credentials and email were compromised;
- attackers gained administrator-level access across numerous systems; and
- investigators were never able to reconstruct the complete scope of the theft or determine the eventual destination of all copied information.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
That final point remains the defining characteristic of the incident. The Rome Laboratory investigation demonstrated that, after a sufficiently successful intrusion, uncertainty itself becomes a lasting consequence. Even exhaustive forensic work could establish important facts about what had been stolen while leaving the complete extent of the compromise permanently unknown.[GAO]gao.govUnited States General Accounting OfficeUnited States General Accounting Office…
Amazon book picks
Further Reading
Books and field guides related to What Did the Rome Laboratory Intruders Really Access?. Use these as the next step if you want deeper reading beyond the article.
Dark Territory: The Secret History of Cyber War
“An important, disturbing, and gripping history” (Kirkus Reviews, starred review), the never-before-told story of the computer scientists...
Cyber War: The Next Threat to National Security and What to D...
Rating: 3.0/5 from 96 Google Books ratings
An essential, eye-opening book about cyberterrorism, cyber war, and the next great threat to our national security. " Cyber War may be th...
Secrets and Lies: Digital Security in a Networked World
Bestselling author Bruce Schneier offers his expert guidance on achieving security on a network Internationally recognized computer secur...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromretro computer poster oneBay.co.uk.
Endnotes
1.
Source: gao.gov
Title: United States General Accounting Office
Link:https://www.gao.gov/assets/hr-97-30.pdf
Source snippet
United States General Accounting Office...
2.
Source: files.gao.gov
Link:https://files.gao.gov/reports/GAO-26-107668/index.html
Source snippet
gao.govGAO-26-107668, TELECOMMUNICATIONS: Selected Agencies Have Taken Steps to Address Risks of Equipment Linked to ChinaMay 19, 2026 —...
Published: May 19, 2026
3.
Source: files.gao.gov
Link:https://files.gao.gov/reports/GAO-26-108774/index.html
Source snippet
gao.govGAO-26-108774, CYBERSECURITY: National Labor Relations Board Detailees Did Not Access IT Systems Between April 16 and July 25, 202...
4.
Source: files.gao.gov
Title: Each federal law e
Link:https://files.gao.gov/reports/GAO-24-106915/index.html
Source snippet
gao.govGAO-24-106915, 2024 ANNUAL REPORT: Additional Opportunities to Reduce Fragmentation, Overlap, and Duplication and Achieve Billions...
5.
Source: gao.gov
Title: gao 21 59
Link:https://www.gao.gov/products/gao
6.
Source: gao.gov
Link:https://www.gao.gov/products/gao-16-871t
7.
Source: gao.gov
Link:https://www.gao.gov/assets/a77215.html
8.
Source: gao.gov
Title: nsiad 94 219
Link:https://www.gao.gov/products/nsiad
9.
Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm
Source snippet
Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...
10.
Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr
11.
Source: irp.fas.org
Link:https://irp.fas.org/gao/aim96084.htm
12.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a
13.
Source: nsarchive.gwu.edu
Title: 21407 document 10b
Link:https://nsarchive.gwu.edu/document/21407-document-10b
14.
Source: irp.fas.org
Title: ssci ames
Link:https://irp.fas.org/congress/1994_rpt/ssci_ames.htm
Additional References
15.
Source: sciencedirect.com
Link:https://www.sciencedirect.com/science/article/pii/S0379073825000313
Source snippet
March 1, 2025 — FORENSIC SCIENCE INTERNATIONAL Case report A case of contamination by indirect DNA transfer in a sexual assa...
Published: March 1, 2025
16.
Source: youtube.com
Title: The Gary [Mc Kinnon Case]({{ ‘mc-kinnon-case/’ | relative_url }}): The Hacker Who Looked For UFO’s
Link:https://www.youtube.com/watch?v=C4JHW9Lnc1w
Source snippet
Richard Pryce Datastream Cowboy hack THE HACKER WHO EXPOSED THE PENTAGON'S GREATEST WEAKNESS KRYPT Files...
17.
Source: pmc.ncbi.nlm.nih.gov
Link:https://pmc.ncbi.nlm.nih.gov/articles/PMC9367628/
Source snippet
Issues When Articles are Retracted Due to Research Misconduct and Then Resubmitted - PMCJuly 7, 2022 — Open in a new tab The Retraction W...
Published: July 7, 2022
18.
Source: youtube.com
Title: THE HACKER WHO EXPOSED THE PENTAGON’S GREATEST WEAKNESS
Link:https://www.youtube.com/watch?v=ltNqoeAEx20
Source snippet
Unveiling the Untold Saga of Kuji and Datastream Cowboy...
19.
Source: youtube.com
Link:https://www.youtube.com/watch?v=B00Fv9VMDq0
Source snippet
The Gary McKinnon Case: The Hacker Who Looked For UFO's...
20.
Source: youtube.com
Title: Unveiling the Untold Saga of Kuji and Datastream Cowboy
Link:https://www.youtube.com/watch?v=n_iLfffJbzo
Source snippet
Gary Mckinnon: The Hacker Who Found UFOs...
21.
Source: sciencedirect.com
Link:https://www.sciencedirect.com/science/article/abs/pii/S1355030618300108
22.
Source: youtube.com
Title: Gary Mckinnon: The Hacker Who Found UFOs
Link:https://www.youtube.com/watch?v=8_1DuqeU8hw
Source snippet
UFO - Hacker Gary Mckinnon Interview 5-5-2006 BBC...
23.
Source: ori.hhs.gov
Title: why duplication and other forms redundancy must be avoided
Link:https://ori.hhs.gov/why-duplication-and-other-forms-redundancy-must-be-avoided
24.
Source: researchgate.net
Title: (PDF) Romanian Review of Laboratory Medicine Statement on plagiarism
Link:https://www.researchgate.net/publication/298411575_Romanian_Review_of_Laboratory_Medicine_Statement_on_plagiarism



