Skip to content
safemode.space
All incidents
2018-04-01 (approximate)
network intrusion
ground

JPL mission-network intrusion via an unauthorised Raspberry Pi (NASA OIG IG-19-022), April 2018

Confidence in this reading:
high

What happened

In April 2018 the Jet Propulsion Laboratory discovered that an account belonging to an external user of its partner network had been compromised and used to log into JPL's mission network. The attacker reached the network by targeting a Raspberry Pi that was not authorised to be attached to it and that had never been reviewed or approved by the JPL Office of the Chief Information Officer. JPL's gateway for external partners, which serves foreign space agencies, contractors and educational institutions, had not been segmented to limit users to the systems for which they had approved access, so the attacker moved laterally between systems connected to the gateway, including multiple JPL mission operations systems and the Deep Space Network. Classified as an advanced persistent threat, the intrusion went undetected for approximately ten months. Before detection and containment the attacker exfiltrated approximately 500 megabytes of data from 23 files, two of which contained International Traffic in Arms Regulations information relating to the Mars Science Laboratory mission, and successfully accessed two of JPL's three primary networks. NASA questioned the integrity of Deep Space Network data related to space flight systems and temporarily disconnected several space-flight-related systems from the JPL network; Johnson Space Center disconnected from the gateway in May 2018 and did not restore limited spacecraft data until March 2019.

Sourced entirely to a Tier 1 NASA OIG audit report, which is why confidence is high despite the absence of attribution. The report does not name the attacker, the external partner whose account was compromised, or the owner of the Raspberry Pi, and the investigation was ongoing at publication. The most visible operational consequence, the loss of DSN data use at Johnson Space Center for six months, was NASA's own containment decision rather than an adversary-produced effect, and is deliberately not mapped as an impact technique. The intrusion's defining behaviour, pivoting across an unsegmented partner gateway into mission systems, has no SPARTA edge because SPARTA's lateral-movement tactic is written for movement aboard the vehicle; that gap is recorded rather than papered over with an approximate mapping.

Attack vector

A compromised external-user account on JPL's shared partner gateway, reached by targeting an unauthorised Raspberry Pi attached to the JPL network without OCIO review or approval, followed by lateral movement across a gateway that had not been segmented to separate partner environments.

Operational impact

NASA questioned the integrity of Deep Space Network data related to space flight systems and temporarily disconnected several space-flight-related systems from the JPL network. Johnson Space Center, which handles the Orion Multi-Purpose Crew Vehicle and the International Space Station, disconnected from the gateway in May 2018 and discontinued use of DSN data over concerns it could be corrupted and unreliable; it reconnected in November 2018, restored use of limited spacecraft data in March 2019, and as of that month had not restored all communications data. No source reports that any spacecraft was commanded or that any data was in fact corrupted.

Data compromised

Approximately 500 megabytes from 23 files, two of which contained International Traffic in Arms Regulations information related to the Mars Science Laboratory mission.

Affected segments

ground, user

Disclosed

2019-06-18

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • From a resident position inside JPL's mission network the attacker exfiltrated approximately 500 megabytes of data from 23 files, two carrying ITAR information on the Mars Science Laboratory mission. EXF-0007 is exfiltration at scale from a trusted position in mission ground infrastructure; the report gives the volume, the file count and the classification of the content.

    https://oig.nasa.gov/docs/IG-19-022.pdf

  • The attacker moved between systems connected to the gateway, including multiple JPL mission operations systems and the Deep Space Network, and successfully accessed two of the three primary JPL networks. Mission operations systems and the DSN are ground segment in IA-0007's own enumeration, which covers mission control software, data gateways and antenna control. The access is stated, not inferred.

    https://oig.nasa.gov/docs/IG-19-022.pdf

  • Initial access was a compromised account belonging to an external user of JPL's shared partner environment, used to log into the mission network. IA-0009.03's subject is precisely that: where end-user and partner environments interconnect with mission cores, a compromised user domain becomes a springboard. The report names the account, the environment and the pivot.

    https://oig.nasa.gov/docs/IG-19-022.pdf

  • IMP-0006Theft
    moderate
    direct
    #

    Two of the 23 exfiltrated files held ITAR-controlled information on the Mars Science Laboratory mission, so mission data was taken and the theft is described rather than inferred. Confidence is moderate rather than high because IMP-0006's literal subject is the data a spacecraft gathers, processes and sends, and IG-19-022 characterises the stolen files by their export-control status without saying whether they were MSL science products or MSL technical data.

    https://oig.nasa.gov/docs/IG-19-022.pdf

  • The report classifies the attack as an advanced persistent threat and states that the attacker exploited weaknesses in JPL's security controls to move undetected within the JPL network for approximately ten months. Ten months of retained, undetected access inside mission ground infrastructure is what PER-0003 describes.

    https://oig.nasa.gov/docs/IG-19-022.pdf

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • The attacker reached mission operations systems and the DSN, which is the position from which IA-0007.02 is executed. The report does not say a command was sent, and Johnson's worry about attackers "potentially gaining access and initiating malicious signals" is expressly a worry. Capability is not conduct.

  • The tempting edge, and wrong. Johnson discontinued its use of DSN data and disconnected from the gateway as a precaution; NASA disconnected several space-flight-related systems because it questioned data integrity. Those are defender containment decisions. IMP-0002 describes measures an adversary designs to impair use of a system, and no source reports the adversary impairing anything. This batch applies that test consistently: see the same rejection on noaa-nesdis-intrusion-2014.

  • Carried in SPARTA against a secondary citation. IG-19-022 describes no adversary reconnaissance of manufacturers, logistics, custody handoffs or procurement artefacts.

  • Not SPARTA-cited here, and correctly so: the report says one of the four compromised systems had not been patched, which is a defender finding about patch state, not a description of the adversary correlating versions against vulnerability sources.

  • Same. The attacker took mission files; taking files is IMP-0006 and EXF-0007. REC-0009 is the compilation of a CONOPS-level portrait to predict operational rhythms, and nothing in the report describes that.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • NASA Office of Inspector General, Office of Audits · 2019-06-18

    Tier 1: A federal Inspector General audit report with direct access to JPL systems, officials and incident records. Primary and official. Where a record cites both this report and the February 2012 congressional testimony, this one is preferred as primary, being the more specific of the two.

  • Confirmed: NASA Has Been Hacked
    Trade press
    corroborating

    Forbes · Davey Winder · 2019-06-20

    Tier 3: Contributor-platform reporting on a published government report. It adds no independent access and no facts the report does not state. Two SPARTA techniques cite it.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.