Within Defense Targets

How One Breach Allegedly Reached Dozens More

The case alleged that access to one computer enabled movement across a much larger set of government networks.

On this page

  • Finding Vulnerable Systems
  • Using Compromised Machines as Launch Points
  • The Scale of the Government Network Search
Preview for How One Breach Allegedly Reached Dozens More

Introduction

A key part of the US case against Gary McKinnon was not simply that he allegedly accessed individual military and NASA computers. Prosecutors argued that each successful intrusion became a stepping stone to many others. Their theory was that once access had been obtained to one poorly protected machine, that machine could be used to discover additional targets, gather credentials and move deeper into government networks. In this way, what might have begun as a compromise of a single computer allegedly expanded into access to dozens of systems across Army, Navy, Air Force, Department of Defense and NASA networks. [Department of Justice+2Pinsent Masons]justice.govDepartment of JusticeLondon, England Hacker Indicted Under Computer Fraud…One count charges McKinnon with accessing and damaging witho…

Network Spread illustration 1 This network-spread allegation was important because it helped explain how prosecutors connected one individual in London to a very large number of affected government computers. Rather than presenting 97 separate and unrelated break-ins, the prosecution described a pattern in which previously compromised machines were repeatedly used as launch points for further exploration and intrusion. [Department of Justice]justice.govDepartment of JusticeLondon, England Hacker Indicted Under Computer Fraud…One count charges McKinnon with accessing and damaging witho…

Finding Vulnerable Systems

According to the indictment, investigators alleged that McKinnon first identified vulnerable computers by scanning large numbers of machines within the US military “.mil” domain. Prosecutors claimed he looked for systems with weak security controls and then obtained administrative privileges on those machines. [Pinsent Masons]pinsentmasons.comalleged uk hacker will fight extradition to usPinsent MasonsAlleged UK hacker will fight extradition to US14 Nov 2002 — McKinnon is alleged to have installed a remote administration d…

The significance of this allegation was that administrative access gave far more than simple entry. Once an administrator account was obtained, prosecutors argued, the intruder could view system information, inspect network settings, examine user accounts and collect data that revealed the existence of other computers. In networked government environments, one compromised machine could therefore provide a map pointing towards many more. [Pinsent Masons]pinsentmasons.comalleged uk hacker will fight extradition to usPinsent MasonsAlleged UK hacker will fight extradition to US14 Nov 2002 — McKinnon is alleged to have installed a remote administration d…

Investigators also alleged that password files and account information were copied from compromised systems. Prosecutors treated this as evidence that access to one computer could yield credentials useful elsewhere, allowing movement beyond the original target. [Pinsent Masons]pinsentmasons.comalleged uk hacker will fight extradition to usPinsent MasonsAlleged UK hacker will fight extradition to US14 Nov 2002 — McKinnon is alleged to have installed a remote administration d…

Network Spread illustration 3

Using Compromised Machines as Launch Points

The prosecution’s most important mechanism was the claim that previously accessed computers were used to facilitate additional compromises. The Justice Department stated that McKinnon allegedly used compromised computers to identify further military and NASA victims. This transformed the case from a collection of isolated intrusions into what prosecutors portrayed as a chain of connected access events. [Department of Justice]justice.govDepartment of JusticeLondon, England Hacker Indicted Under Computer Fraud…One count charges McKinnon with accessing and damaging witho…

Court summaries and indictment materials also described the alleged installation of remote-access software, particularly a tool called “RemotelyAnywhere”. Prosecutors said that after gaining entry to a machine, McKinnon installed software that enabled continued access while concealing his activities. Once such access was established, the machine could allegedly be revisited repeatedly and used as a platform for further network reconnaissance. [UK Parliament]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — Having gained access to those accounts he installed u…

The alleged sequence described by investigators was broadly:

Network Spread illustration 2

  1. Find a vulnerable government computer.
  2. Obtain administrative privileges.
  3. Install remote-access software. [publications.parliament.uk]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — Having gained access to those accounts he installed u…
  4. Copy account and password information.
  5. Use information discovered on that system to locate additional machines.
  6. Repeat the process on newly discovered targets. Pinsent Masons+2UK Parliament

This model helped prosecutors explain how access could spread across multiple agencies over many months without requiring a separate, independent breakthrough for every machine involved.

The prosecution’s description of network spread was closely tied to the unusually large number of affected systems. Different court and government documents cited totals ranging from 92 government computers in the original indictment to 97 government computers in later judicial summaries. These systems allegedly included Army, Navy, Air Force, Department of Defense and NASA machines. Department of Justice+2UK Parliament

From the prosecution’s perspective, the breadth of affected systems was itself evidence that the intrusions were interconnected. Investigators argued that the same methods, tools and patterns appeared across numerous compromises. The allegation was not that dozens of unrelated attacks happened independently, but that access expanded through a process of discovery and movement from one machine to another. Department of Justice+2Pinsent Masons

This point mattered because it supported the government’s portrayal of the incident as a wide-ranging intrusion into military and space-agency networks rather than a series of accidental encounters with isolated computers. The alleged ability to leverage one compromise into many others became one of the central mechanisms through which prosecutors connected a single point of entry to a much larger set of government systems. Department of Justice+2UK Parliament

Amazon book picks

Further Reading

Books and field guides related to How One Breach Allegedly Reached Dozens More. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Example marketplace items related to this page. Use the search link to explore similar finds on eBay.

Using USA

Endnotes

  1. Source: justice.gov
    Link: https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict.htm
    Source snippet

    Department of JusticeLondon, England Hacker Indicted Under Computer Fraud...One count charges McKinnon with accessing and damaging witho...

  2. Source: publications.parliament.uk
    Title: mckinn 1
    Link: https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm
    Source snippet

    UK ParliamentMckinnon V Government of The United States of America...30 Jul 2008 — Having gained access to those accounts he installed u...

  3. Source: justice.gov
    Link: https://www.justice.gov/archive/usao/nj/Press/files/pdffiles/Older/edva_mckinnon_indictment.pdf
    Source snippet

    n unemployed computer system.Read more...

  4. Source: pinsentmasons.com
    Title: pentagon hacker mckinnon fights extradition
    Link: https://www.pinsentmasons.com/out-law/news/pentagon-hacker-mckinnon-fights-extradition
    Source snippet

    'Pentagon hacker' McKinnon fights extradition28 Jul 2005 — McKinnon allegedly exploited poorly-secured Windows systems to attack networks...

  5. Source: Wikipedia
    Title: Gary [Mc Kinnon]({{ ‘mc-kinnon/’ | relative_url }})
    Link: https://en.wikipedia.org/wiki/Gary_McKinnon
    Source snippet

    Gary McKinnonThe US government accused McKinnon of hacking into 97 United States military and NASA computers... Representing McKinnon...

Additional References

  1. Source: guinnessworldrecords.de
    Link: https://guinnessworldrecords.de/world-records/90133-biggest-military-computer-hack
    Source snippet

    Biggest military computer hackGary McKinnon, a 42-year old Englishman, is accused of hacking into 97 US military computers (53 US Army, 2...

  2. Source: cybereason.com
    Link: https://www.cybereason.com/blog/malicious-life-podcast-the-u.s-vs.-gary-mckinnon
    Source snippet

    Malicious Life Podcast: The U.S. vs. Gary McKinnonGary McKinnon, a British hacker with Asperger's, broke into NASA and US Army networks t...

  3. Source: vlex.co.uk
    Link: https://vlex.co.uk/vid/mckinnon-v-united-states-793612009
    Source snippet

    McKinnon v United States of AmericaMcKinnon v United States of America; Judge, Lord Justice Maurice Kay; Judgment Date, 03 April 2007...

    Published: April 2007

  4. Source: malicious.life
    Link: https://malicious.life/episode/us_vs_gary_mckinnon/
    Source snippet

    The US vs. Gary McKinnonGary McKinnon, a British hacker with Asperger's, broke into NASA & US Army networks - to find evidence of UFO cov...

  5. Source: reuters.com
    Title: british nasa hacker to face us trial idUSL0623036
    Link: https://www.reuters.com/article/technology/british-nasa-hacker-to-face-us-trial-idUSL0623036/
    Source snippet

    British NASA hacker to face U.S. trialJul 30, 2008 — Gary McKinnon was arrested in 2002 after U.S. prosecutors charged him with illegally...

  6. Source: casemine.com
    Link: https://www.casemine.com/judgement/uk/5a8ff75e60d03e7f57eabd29
    Source snippet

    The conduct was intentional and calculated to intimidate and...Read more...

  7. Source: futureintelligence.co.uk
    Title: Future Intelligence Gary Mc Kinnon was unlucky
    Link: https://www.futureintelligence.co.uk/2012/10/18/gary-mckinnon-was-unlucky-hes-not-even-a-good-hacker/
    Source snippet

    He's not even a very good hacker18 Oct 2012 — How he would search for blank passwords and then once inside the US computers, install a re...

  8. Source: cbsnews.com
    Title: brit hacker loses us extradition appeal
    Link: https://www.cbsnews.com/news/brit-hacker-loses-us-extradition-appeal/
    Source snippet

    Brit Hacker Loses U.S. Extradition AppealJul 30, 2008 — McKinnon, 42, an unemployed computer administrator, allegedly broke into 97 compu...

  9. Source: verticalvertical.com
    Link: https://verticalvertical.com/hacking-the-pentagon-in-search-of-ufos
    Source snippet

    Hacking the Pentagon in search of UFO'sIn November 2002, Gary McKinnon was indicted by a federal grand jury in the Eastern District of Vi...

    Published: November 2002

  10. Source: wired.com
    Title: ufo hacker tells what he found
    Link: https://www.wired.com/2006/06/ufo-hacker-tells-what-he-found/
    Source snippet

    'UFO Hacker' Tells What He Found21 Jun 2006 — After allegedly hacking into NASA websites -- where he says he found images of what looked...

Topic Tree

Follow this branch

Parent topic

Defense Targets Why Pentagon Intrusions Raised the Stakes

Related pages 5