Skip to content
safemode.space
All incidents
2013-01-01 (approximate)
network intrusion

AnonSec claimed NASA breach and data leak (OpNasaDrones), January-February 2016

Confidence in this reading:
low

What happened

At the end of January 2016 a group calling itself AnonSec published a self-produced document describing an operation it called OpNasaDrones, together with a large archive of files it said came from NASA. Press accounts give the archive as 276 GB; The Register, the source SPARTA's bibliography cites, reported it at 250 GB. The claimed contents were approximately 2,143 flight logs, 631 video recordings from aircraft and weather radars, and contact details for about 2,414 NASA employees. In its own account the group said it bought access from another actor who had deployed the Gozi malware on a NASA system, that the intrusion dated back to 2013, and that it went on to compromise three network-attached storage devices across the Glenn Research Center, the Goddard Space Flight Center and the Dryden Flight Research Center. It further claimed to have found that drones received pre-planned routes as .gpx files over a wireless link, to have created a substitute file, and to have used a man-in-the-middle attack to replace it in an attempt to fly a Global Hawk into the Pacific. NASA denied the drone claim in terms - control of the aircraft was not compromised - and stated it had no evidence the material was anything other than publicly available scientific data.

HOLD RECOMMENDED, and low confidence is the point of the record rather than a defect in it. Almost every factual claim originates with the people who say they carried out the intrusion, in a document they published themselves, and the operator denied the most serious of those claims outright. What is established is that the zine and archive were published and what they assert, and that NASA denied the drone claim and characterised the data as public. The two technique edges are both low and both derived, and neither rests on the drone claim. Independently of who is right about that claim, a Global Hawk is an aircraft: altering its flight plan is not a spacecraft event, and SPARTA's command and PNT techniques are written with a spacecraft as the affected party, which is the same scope question the corpus already carries on its two GNSS records. The editor should decide whether the corpus carries adversary-claimed, operator-denied incidents at all; if it does, this record is the shape such a record should take, and if it does not, this one goes.

Attack vector

Claimed by the group and not independently established: access bought from another actor who had deployed the Gozi malware on a NASA system, followed by lateral movement and the compromise of three network-attached storage devices.

Operational impact

None established. The group claimed a Global Hawk deviated from its route until NASA controllers manually corrected it; NASA states control of the aircraft was not compromised. The group also reported that NASA systems went down for a period after the attempt and that on restoration it had lost all access, with backdoors removed and credentials changed.

Data compromised

Claimed: approximately 2,143 flight logs, 631 video recordings from aircraft and weather radars, and contact details for about 2,414 NASA employees, in an archive reported at 250 GB or 276 GB depending on source. NASA's position is that the information appears to have been retrieved from publicly available data sets.

Disclosed

2016-02-01

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • AnonSec's account describes bought access to a NASA system, presence from 2013, and the compromise of three network-attached storage devices at the Glenn Research Center, the Goddard Space Flight Center and the Dryden Flight Research Center, from which the published archive was taken. That is EXF-0007's shape, exfiltration from a resident position in ground infrastructure. Confidence is low and the evidence type derived because the account has one interested source and is contradicted by the operator on whether it produced any non-public data.

    https://www.helpnetsecurity.com/2016/02/02/hackers-claim-to-have-hacked-nasa-hijacked-one-of-its-drones/

  • IMP-0006Theft
    low
    derived
    #

    A large archive presented as NASA flight logs, aircraft and radar video, and employee contact details was published, so material held out as NASA's did leave NASA's control and reach the public, which is the outcome IMP-0006 describes. Confidence is low because the only account of an intrusion is the perpetrators' own, and because NASA's stated position is that the information appears to have come from publicly available data sets, which if correct means nothing was stolen at all.

    https://www.foxnews.com/tech/nasa-probes-anonsec-hack-claims-denies-that-one-of-its-drones-was-hacked

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Not SPARTA-cited, and would be the natural home for the .gpx substitution if it stood up. It does not: NASA states control of the aircraft was not compromised, and the only contrary account is the claimant's.

  • Cited by SPARTA. Nothing in any account describes the acquisition or assembly of an RF ground stack: mounts, feeds, amplifiers, SDRs or modems. A context citation.

  • Cited by SPARTA, and the tempting one. AnonSec claims access to systems that distributed aircraft flight plans, which is a mission's own operational infrastructure in the ordinary sense. Two things stop it. RD-0002.01 is a resource-development technique about obtaining preconfigured TT&C reach toward a spacecraft, and the mission here is an aircraft; and the operator denies the control claim outright, so accepting the edge would mean asserting the disputed fact rather than recording the dispute.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

A source marked contradicting disputes the account above rather than supporting it. It is listed because a reader assessing this record should see it.

  • Help Net Security · Zeljka Zorz · 2016-02-02

    Tier 2: Named reporting by a security trade title that read the group's own document and reports its claims as claims. Tier_2 reflects the reporting; the claims it carries are the perpetrators' and carry no independent weight, which is why both edges built on it are low confidence.

  • The Register (Situation Publishing) · Iain Thomson · 2016-02-01

    Tier 2: Named reporting by an established trade title. Recorded chiefly for provenance: this is the URL three SPARTA techniques cite for this incident.

  • Fox News · James Rogers · 2016-02-02

    Tier 2: Named reporting carrying NASA's own statement in quoted form. The statement inside it is an operator statement; the article is trade press.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.