Within Defense Targets

Why Copied Password Files Raised the Stakes

The password-copying claims helped prosecutors argue the conduct created continuing risks beyond simple access.

On this page

  • What Files Were Allegedly Taken
  • The Earle Password Collection
  • Long Term Security Consequences
Preview for Why Copied Password Files Raised the Stakes

Introduction

Among the many allegations made against Gary McKinnon, the claim that he copied password files was especially important to prosecutors because it suggested a risk that extended far beyond simply viewing information. In the government’s account, the issue was not only that military and NASA systems had been accessed without authorisation, but that credentials and account data were allegedly extracted and stored elsewhere, creating the possibility of continued access and future compromise. The password-file allegations therefore became a central part of the narrative about security harm within the broader Pentagon and Defence Department hacking case. [UK Parliament]publications.parliament.ukmckinn 1The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted…

Password Files illustration 1

What Files Were Allegedly Taken

Court summaries and indictments consistently describe McKinnon as having copied operating-system files that contained account names and encrypted passwords from government computers. According to the House of Lords’ summary of the extradition case, prosecutors alleged that files were copied from 22 compromised systems, including Army, Navy and NASA computers. The material allegedly included operating-system files containing user account information and encrypted password data. [UK Parliament]publications.parliament.ukmckinn 1The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted…

The scale of the allegations was significant. The House of Lords judgment states that investigators claimed McKinnon’s computers contained:

  • 189 files copied from US Army systems.
  • 35 files copied from US Navy systems.
  • Six files copied from NASA systems. [vlex.co.uk]vlex.co.ukMcKinnon v United States of America… 950 passwords from server computers at Naval Weapons Station Earle [charges 9 to 10]. (3) 6 fi…
  • Operating-system files containing account names and encrypted passwords from those networks. [UK Parliament]publications.parliament.ukmckinn 1The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted…

Separate US charging documents also alleged that password files were copied from military computers after administrator-level access had been obtained. Prosecutors argued that the extraction of credential data was part of a broader pattern that included installing remote-access software, moving through networks and using compromised machines to reach additional targets. [Department of Justice]justice.govDepartment of Justice British National Charged with Hacking Into N.JNaval…… 950 passwords stored on server computers connected to the NWS Earle network. In addition, the Indictment charges that on Sep…

The Earle Password Collection

The most frequently cited example involved the US Naval Weapons Station Earle in New Jersey. In the government’s case, Earle was not presented as an ordinary office network but as a naval installation responsible for replenishing munitions and supplies for the Atlantic Fleet. That context made the password allegations particularly sensitive. [Department of Justice]justice.govDepartment of Justice British National Charged with Hacking Into N.JNaval…… 950 passwords stored on server computers connected to the NWS Earle network. In addition, the Indictment charges that on Sep…

US prosecutors alleged that McKinnon obtained approximately 950 passwords stored on server computers connected to the Earle network. According to the indictment, those credentials were obtained after remote-access software had been installed on computers within the network. Prosecutors further alleged that the passwords were later used during subsequent intrusions into the system. [Department of Justice]justice.govDepartment of Justice British National Charged with Hacking Into N.JNaval…… 950 passwords stored on server computers connected to the NWS Earle network. In addition, the Indictment charges that on Sep…

The figure of roughly 950 passwords became one of the most repeated details in official statements, court summaries and press coverage. The House of Lords judgment referred to “some 950 passwords” from server computers at Naval Weapons Station Earle, while contemporary reporting similarly highlighted the allegation that hundreds of military credentials had been copied from the facility. [UK Parliament+2vLex]publications.parliament.ukmckinn 1The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted…

From a security perspective, the importance of the allegation was not merely the number itself. Password collections can provide a map of an organisation’s user accounts, system relationships and administrative structure. Even when passwords are encrypted rather than stored in plain text, possession of the files may enable later attempts to recover or reuse credentials. That is why prosecutors treated the alleged copying of password files as a distinct category of harm rather than simply another form of data collection. [UK Parliament]publications.parliament.ukmckinn 1The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted…

Password Files illustration 2

Why Password Files Were Viewed as a Continuing Threat

The government’s theory of the case emphasised persistence. If an intruder merely accesses a computer and leaves, the incident may end when the session ends. Credential theft raises a different concern: access can potentially be regained later, shared with others or used to expand compromise across connected systems.

Prosecutors argued that copied password files increased the vulnerability of affected networks because they provided information that could support future intrusions. In the Earle allegations, the government explicitly linked the acquisition of passwords to later access and argued that the network remained exposed after the incident. [Department of Justice]justice.govDepartment of Justice British National Charged with Hacking Into N.JNaval…… 950 passwords stored on server computers connected to the NWS Earle network. In addition, the Indictment charges that on Sep…

The House of Lords summary also recorded forensic findings that investigators said linked account names and passwords found on McKinnon’s home computer to dozens of compromised military systems. According to that summary, administrative account names and passwords for 39 of the compromised computers were allegedly recovered during analysis of his seized equipment. Prosecutors used such findings to support the claim that credential collection was deliberate rather than incidental. [vLex]vlex.co.ukMcKinnon v United States of America… 950 passwords from server computers at Naval Weapons Station Earle [charges 9 to 10]. (3) 6 fi…

This distinction mattered legally as well as technically. Unauthorised viewing of information can often be described as a transient intrusion. Copying credentials, by contrast, can be characterised as creating an enduring security problem because organisations may need to identify affected accounts, reset passwords, audit access logs and verify that no further compromise occurred. The government therefore treated the password-file allegations as evidence of ongoing risk and part of the justification for substantial claimed remediation costs. [UK Parliament]publications.parliament.ukmckinn 1The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted…

Long-Term Security Consequences

The alleged password copying helped prosecutors argue that the consequences of the intrusions extended beyond immediate disruption. Their position was that military networks could not simply be returned to service once systems were restored; administrators also had to consider whether credentials had been exposed and whether unauthorised access might continue in the future. [UK Parliament]publications.parliament.ukmckinn 1The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted…

In practical terms, the security concerns included:

  • Potential reuse of compromised credentials.
  • The possibility of regaining access through previously obtained passwords.
  • Increased risk to interconnected systems that trusted the affected accounts.
  • The need for extensive password resets, audits and network reviews.
  • Uncertainty over whether copied credentials had been shared or retained. [UK Parliament]publications.parliament.ukmckinn 1The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted…

These concerns explain why password files occupied such a prominent place in official descriptions of the case. While public attention often focused on McKinnon’s claim that he was searching for UFO-related information, prosecutors repeatedly highlighted the alleged copying of account files and passwords because it supported their broader argument that the intrusions created lasting security exposure for military and government networks. [UK Parliament+2gov.uk]publications.parliament.ukmckinn 1The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted…

Password Files illustration 3

Amazon book picks

Further Reading

Books and field guides related to Why Copied Password Files Raised the Stakes. Use these as the next step if you want deeper reading beyond the article.

BookCover for The Art of Intrusion

The Art of Intrusion

By Kevin D. Mitnick, William L. Simon

Rating: 4.0/5 from 10 Google Books ratings

Real-world case studies involving unauthorized access and compromised systems.

eBay marketplace picks

Marketplace Samples

Example marketplace items related to this page. Use the search link to explore similar finds on eBay.

Using USA

Endnotes

  1. Source: publications.parliament.uk
    Title: mckinn 1
    Link: https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm
    Source snippet

    The appellant also copied data and files onto his own computers, including operating system files containing account names and encrypted...

  2. Source: justice.gov
    Title: Department of Justice British National Charged with Hacking Into N.J
    Link: https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict2.htm
    Source snippet

    Naval...... 950 passwords stored on server computers connected to the NWS Earle network. In addition, the Indictment charges that on Sep...

  3. Source: GOV.UK
    Title: latest on gary mckinnon case
    Link: https://www.gov.uk/government/news/latest-on-gary-mckinnon-case
    Source snippet

    on Gary McKinnon case4 Nov 2010 — Mr McKinnon is accused by US authorities of the unauthorised access of 97 government computers concerne...

  4. Source: vlex.co.uk
    Link: https://vlex.co.uk/vid/mckinnon-v-united-states-793612009
    Source snippet

    McKinnon v United States of America... 950 passwords from server computers at Naval Weapons Station Earle [charges 9 to 10]. (3) 6 fi...

  5. Source: Wikipedia
    Title: Gary [Mc Kinnon]({{ ‘mc-kinnon/’ | relative_url }})
    Link: https://en.wikipedia.org/wiki/Gary_McKinnon
    Source snippet

    Gary McKinnonMcKinnon was also accused of copying data, account files and passwords onto his own computer. US authorities stated that...

Additional References

  1. Source: malicious.life
    Link: https://malicious.life/episode/us_vs_gary_mckinnon/
    Source snippet

    The US vs. Gary McKinnonHe stole around 950 passwords, trashed around 1,300 user accounts. He deleted files at a naval weapons station, a...

  2. Source: mg.co.za
    Title: 2008 07 30 uk computer hacker loses appeal over us extradition
    Link: https://mg.co.za/news/south-africa/2008-07-30-uk-computer-hacker-loses-appeal-over-us-extradition/
    Source snippet

    UK computer hacker loses appeal over US extradition30 Jul 2008 — The US authorities allege he stole 950 passwords and deleted files at th...

  3. Source: redhotcyber.com
    Title: famous hackers the story of gary mckinnon
    Link: https://www.redhotcyber.com/en/post/famous-hackers-the-story-of-gary-mckinnon/
    Source snippet

    Famous Hackers: The Story of Gary McKinnon.1 Jul 2025 — Gary McKinnon, single-handedly scanned thousands of US government machines and di...

  4. Source: independent.co.uk
    Title: hacker loses us extradition appeal 880707
    Link: https://www.independent.co.uk/news/uk/crime/hacker-loses-us-extradition-appeal-880707.html
    Source snippet

    Hacker loses US extradition appeal30 Jul 2008 — The House of Lords rejected a plea by McKinnon... American authorities claim he stole 95...

  5. Source: theguardian.com
    Link: https://www.theguardian.com/technology/2008/aug/28/hacking.security
    Source snippet

    Hacker Gary McKinnon loses appeal against extradition to...28 Aug 2008 — Gary McKinnon, a computer expert who hacked into dozens of US m...

  6. Source: youtube.com
    Title: Theresa May blocks Gary Mc Kinnon’s extradition to US
    Link: https://www.youtube.com/watch?v=Y5jtyps4oaY
    Source snippet

    Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub...

  7. Source: theguardian.com
    Link: https://www.theguardian.com/world/2005/jun/08/usa.uk
    Source snippet

    'Military computer hacker' faces extradition to US8 Jun 2005 — It was alleged he also "deleted critical system files" on the computer, co...

  8. Source: youtube.com
    Title: The Man Who Hacked the U.S. Government
    Link: https://www.youtube.com/watch?v=ND0zQX1rGdg
    Source snippet

    Hacking for UFOs and fighting for his life. Who is Gary McKinnon? | NordVPN...

  9. Source: youtube.com
    Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon? | Nord VPN
    Link: https://www.youtube.com/watch?v=OImdnvQx7sQ
    Source snippet

    UK hacker to learn extradition fate...

  10. Source: youtube.com
    Title: UK hacker to learn extradition fate
    Link: https://www.youtube.com/watch?v=LEvGU1b4ysw
    Source snippet

    Theresa May blocks Gary McKinnon's extradition to US...

Topic Tree

Follow this branch

Parent topic

Defense Targets Why Pentagon Intrusions Raised the Stakes

Related pages 5