Within Richard Pryce

What Did the Rome Laboratory Intruders Really Access?

Official reviews confirmed copied research and seized systems but could not reconstruct every file viewed, altered or removed.

40 sources 3 graphics
Preview for What Did the Rome Laboratory Intruders Really Access?

On this page

  • The research data known to have been copied
  • What investigators could not reconstruct
  • Why uncertainty mattered as much as confirmed loss

Introduction

The official record of the 1994 Rome Laboratory intrusions is both more specific and more uncertain than many later retellings suggest. Investigators confirmed that the intruders copied sensitive Air Force research data, captured hundreds of user credentials, accessed and manipulated email, and used compromised systems as staging points for attacks against other government and research networks. At the same time, multiple government reviews acknowledged a critical limitation: they could never reconstruct every file that had been viewed, copied, altered or removed. That unresolved uncertainty became one of the case’s most significant lessons. Rather than proving the theft of every classified secret imaginable, the investigation demonstrated how difficult it was—even for a well-resourced military investigation—to determine the full extent of a successful network compromise.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

What Was Taken illustration 1

The research data known to have been copied

Official Air Force and congressional documentation identifies several categories of information that investigators knew had been accessed or copied.

The most consistently documented theft involved sensitive but unclassified research held at Rome Laboratory, the Air Force’s premier command-and-control research centre. Investigators determined that the attackers downloaded data files from compromised systems after obtaining administrator-level access.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Among the specifically identified material were:

  • Artificial intelligence research, reflecting Rome Laboratory’s work on advanced command-and-control technologies.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
  • Radar guidance and target detection research, which formed part of the laboratory’s core mission.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
  • Sensitive battlefield simulation program data, which investigators confirmed had been read and copied from compromised systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…
  • Air Tasking Order (ATO) research, perhaps the best documented example. Air tasking orders are the operational messages used to coordinate military air operations. The material stolen concerned research into these systems rather than wartime operational orders themselves. GAO testimony noted that this research could have required roughly three years and several million dollars to recreate had it been destroyed.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

Government reports deliberately distinguished between research supporting military operations and current operational battle plans. The evidence points to the theft of research and development material, not active combat orders.

Beyond documents: credentials, email and system control

The files themselves were only part of what the attackers acquired.

Investigators found that the intruders installed seven network “sniffer” programs that collected usernames and passwords as authorised users logged into the network. These sniffers compromised around 30 Rome Laboratory systems and captured credentials for more than 100 additional user accounts. Those credentials dramatically expanded what the attackers could legitimately access while appearing to be authorised users.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

The investigation also established that the attackers:

  • read user email;
  • copied email contents;
  • deleted some email;
  • installed additional malicious software to preserve future access; and
  • gained complete access to the information stored on seven initially compromised systems before expanding further through the network.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

These actions meant that the compromise extended well beyond downloading isolated research files. The attackers effectively harvested the trust relationships embedded within the laboratory’s network.

What Was Taken illustration 2

What investigators could not reconstruct

Perhaps the most important finding of the official reviews is what they could not determine.

Although investigators documented more than 150 known intrusions during the monitored period, they repeatedly acknowledged that they were unable to reconstruct every action performed before discovery. By the time the sniffer software was detected, the attackers had already been active for several days and had administrative privileges on numerous systems.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Official investigations therefore could not establish with certainty:

  • every file that had been viewed;
  • every document that had been copied;
  • whether earlier undetected intrusions had occurred before March 1994;
  • whether additional systems had been compromised without leaving recoverable evidence;
  • whether copied material had been redistributed after removal from Rome Laboratory.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Government reports are explicit that investigators never conclusively determined what ultimately happened to the copied research data. The unidentified collaborator known as “Kuji” was never found, leaving unanswered questions about where the material went and whether others received it.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

Why uncertainty mattered as much as confirmed loss

The inability to measure precisely what had been taken became a central governance lesson from the Rome Laboratory case.

GAO and Senate investigations argued that the greatest damage was not simply the confirmed theft of research files. Once attackers acquired privileged credentials and administrator access, defenders lost confidence in the integrity of the affected systems. Restoring trust required taking networks offline, validating system contents, reinstalling software, applying security patches and conducting lengthy forensic investigations. Those recovery activities accounted for much of the financial cost of the incident.[GAO]gao.govUnited States General Accounting OfficeUnited States General Accounting Office…

The Air Force could estimate the direct recovery expense, but it could not place a reliable value on the compromised research itself. Nor could it determine whether the theft represented ordinary hacking, espionage or preparation for future operations. GAO testimony noted that sensitive defence information may have very different value to a foreign intelligence service than to its original owner, making conventional accounting inadequate.[National Security Archive]nsarchive.gwu.eduNational Security Archive OCR of the Document | National Security ArchiveNational Security Archive OCR of the Document | National Security Archive

The enduring evidence

Within the broader story of Richard Pryce (“Datastream Cowboy”) and the Rome Laboratory intrusions, the evidence about what was actually taken is narrower—and more credible—than many popular accounts suggest.

The official record supports several firm conclusions:

  • sensitive Air Force research files were copied;
  • battlefield simulation and Air Tasking Order research were among the confirmed targets;
  • extensive user credentials and email were compromised;
  • attackers gained administrator-level access across numerous systems; and
  • investigators were never able to reconstruct the complete scope of the theft or determine the eventual destination of all copied information.[fas.org]irp.fas.orgIntelligence Resource Program Security in Cyberspace APPENDIX BIntelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5…

That final point remains the defining characteristic of the incident. The Rome Laboratory investigation demonstrated that, after a sufficiently successful intrusion, uncertainty itself becomes a lasting consequence. Even exhaustive forensic work could establish important facts about what had been stolen while leaving the complete extent of the compromise permanently unknown.[GAO]gao.govUnited States General Accounting OfficeUnited States General Accounting Office…

What Was Taken illustration 3

Amazon book picks

Further Reading

Books and field guides related to What Did the Rome Laboratory Intruders Really Access?. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromretro computer poster oneBay.co.uk.

Endnotes

1. Source: gao.gov
Title: United States General Accounting Office
Link:https://www.gao.gov/assets/hr-97-30.pdf

Source snippet

United States General Accounting Office...

2. Source: files.gao.gov
Link:https://files.gao.gov/reports/GAO-26-107668/index.html

Source snippet

gao.govGAO-26-107668, TELECOMMUNICATIONS: Selected Agencies Have Taken Steps to Address Risks of Equipment Linked to ChinaMay 19, 2026 —...

Published: May 19, 2026

3. Source: files.gao.gov
Link:https://files.gao.gov/reports/GAO-26-108774/index.html

Source snippet

gao.govGAO-26-108774, CYBERSECURITY: National Labor Relations Board Detailees Did Not Access IT Systems Between April 16 and July 25, 202...

4. Source: files.gao.gov
Title: Each federal law e
Link:https://files.gao.gov/reports/GAO-24-106915/index.html

Source snippet

gao.govGAO-24-106915, 2024 ANNUAL REPORT: Additional Opportunities to Reduce Fragmentation, Overlap, and Duplication and Achieve Billions...

5. Source: gao.gov
Title: gao 21 59
Link:https://www.gao.gov/products/gao

6. Source: gao.gov
Link:https://www.gao.gov/products/gao-16-871t

7. Source: gao.gov
Link:https://www.gao.gov/assets/a77215.html

8. Source: gao.gov
Title: nsiad 94 219
Link:https://www.gao.gov/products/nsiad

9. Source: irp.fas.org
Title: Intelligence Resource Program Security in Cyberspace APPENDIX B
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm

Source snippet

Intelligence Resource ProgramSecurity in Cyberspace APPENDIX B - Case Study Rome Laboratory, Griffiss Air Force Base, NY IntrusionJune 5...

10. Source: nsarchive.gwu.edu
Title: National Security Archive OCR of the Document | National Security Archive
Link:https://nsarchive.gwu.edu/media/21407/ocr

11. Source: irp.fas.org
Link:https://irp.fas.org/gao/aim96084.htm

12. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a

13. Source: nsarchive.gwu.edu
Title: 21407 document 10b
Link:https://nsarchive.gwu.edu/document/21407-document-10b

14. Source: irp.fas.org
Title: ssci ames
Link:https://irp.fas.org/congress/1994_rpt/ssci_ames.htm

Additional References

15. Source: sciencedirect.com
Link:https://www.sciencedirect.com/science/article/pii/S0379073825000313

Source snippet

March 1, 2025 — FORENSIC SCIENCE INTERNATIONAL Case report A case of contamination by indirect DNA transfer in a sexual assa...

Published: March 1, 2025

16. Source: youtube.com
Title: The Gary [Mc Kinnon Case]({{ ‘mc-kinnon-case/’ | relative_url }}): The Hacker Who Looked For UFO’s
Link:https://www.youtube.com/watch?v=C4JHW9Lnc1w

Source snippet

Richard Pryce Datastream Cowboy hack THE HACKER WHO EXPOSED THE PENTAGON'S GREATEST WEAKNESS KRYPT Files...

17. Source: pmc.ncbi.nlm.nih.gov
Link:https://pmc.ncbi.nlm.nih.gov/articles/PMC9367628/

Source snippet

Issues When Articles are Retracted Due to Research Misconduct and Then Resubmitted - PMCJuly 7, 2022 — Open in a new tab The Retraction W...

Published: July 7, 2022

18. Source: youtube.com
Title: THE HACKER WHO EXPOSED THE PENTAGON’S GREATEST WEAKNESS
Link:https://www.youtube.com/watch?v=ltNqoeAEx20

Source snippet

Unveiling the Untold Saga of Kuji and Datastream Cowboy...

19. Source: youtube.com
Link:https://www.youtube.com/watch?v=B00Fv9VMDq0

Source snippet

The Gary McKinnon Case: The Hacker Who Looked For UFO's...

20. Source: youtube.com
Title: Unveiling the Untold Saga of Kuji and Datastream Cowboy
Link:https://www.youtube.com/watch?v=n_iLfffJbzo

Source snippet

Gary Mckinnon: The Hacker Who Found UFOs...

21. Source: sciencedirect.com
Link:https://www.sciencedirect.com/science/article/abs/pii/S1355030618300108

22. Source: youtube.com
Title: Gary Mckinnon: The Hacker Who Found UFOs
Link:https://www.youtube.com/watch?v=8_1DuqeU8hw

Source snippet

UFO - Hacker Gary Mckinnon Interview 5-5-2006 BBC...

23. Source: ori.hhs.gov
Title: why duplication and other forms redundancy must be avoided
Link:https://ori.hhs.gov/why-duplication-and-other-forms-redundancy-must-be-avoided

24. Source: researchgate.net
Title: (PDF) Romanian Review of Laboratory Medicine Statement on plagiarism
Link:https://www.researchgate.net/publication/298411575_Romanian_Review_of_Laboratory_Medicine_Statement_on_plagiarism