NASA agency-wide network intrusions reported to Congress (Martin testimony, 2012)
What happened
Testifying before the Subcommittee on Investigations and Oversight of the House Committee on Science, Space, and Technology on 29 February 2012, NASA Inspector General Paul K. Martin reported that in 2010 and 2011 NASA recorded 5,408 computer security incidents that resulted in the installation of malicious software on, or unauthorised access to, its systems, at an estimated cost of more than $7 million. He described the range as spanning individuals testing their skill, organised criminal enterprises hacking for profit, and intrusions that may have been sponsored by foreign intelligence services. For fiscal year 2011 NASA reported 47 advanced-persistent-threat attacks, 13 of which successfully compromised agency computers; in one, intruders stole user credentials for more than 150 NASA employees. Martin reported that only 1 percent of NASA portable devices and laptops had been encrypted as of 1 February 2012, against a government-wide rate of 54 percent, and that the March 2011 theft of one unencrypted notebook resulted in the loss of the algorithms used to command and control the International Space Station. Other lost or stolen notebooks held Social Security numbers and data on the Constellation and Orion programmes. Individual OIG case summaries in the testimony record more than 3,000 registered users denied access to NASA-supplied oceanographic data for several days, and NASA scientific research products made inaccessible to the public after a further intrusion.
A portfolio record, not a single event: the Inspector General's agency-wide account of two years of intrusions, put before Congress. It is kept separate from jpl-privileged-account-compromise-2011, which is one of the intrusions this testimony describes and which has its own later documentary record in NASA OIG IG-19-022; the relationship is containment, not duplication. Martin's own caveat is preserved because it bears on how the counts should be read: NASA OIG is the only Office of Inspector General that regularly conducts international network intrusion cases, which he says could skew perceptions of NASA's relative rate of significant intrusion events. The technique edges are deliberately few. Aggregate incident counts describe volume, not behaviour, and SPARTA techniques describe behaviour; where the testimony names a behaviour it is mapped, and where it reports only a count or a possibility it is not. SCOPE UNDETERMINED, recorded 2026-08-22. Whether this record belongs in this corpus has not been established, and here what is missing is a settled boundary rather than a source. A record is admitted here when a space system, meaning a spacecraft, a mission ground segment, a tracking or command path or a launch system, is in the attack path. The network-intrusion side of this record does not reach one on its own account: the technique rationales here record in seven places that the testimony names no mission system as reached, and the one intrusion of this period that did compromise a mission ground system is carried separately as jpl-privileged-account-compromise-2011. The one fact that touches a space system is the March 2011 theft of an unencrypted notebook computer holding the algorithms used to command and control the International Space Station, and nothing entered the station or its operations. Whether losing a spacecraft's command material from a stolen laptop puts that spacecraft in the attack path is not settled. A source tying one of the 5,408 reported incidents to a named mission ground system on this record, or a hearing record specifying which mission operations the aggregate disruption sentence refers to, would settle it one way; a determination that the attack path must be reached by intrusion rather than by removal of control material would settle it the other. The record stays published while the question is open, under decisions entry 189.
Attack vector
Not a single vector. The testimony counts the 5,408 incidents by their result, the installation of malicious software on or unauthorized access to NASA systems, and states no entry path for the aggregate. The loss or theft of 48 agency mobile computing devices between April 2009 and April 2011 is reported separately, under the section on NASA's slow pace of laptop encryption, rather than as part of that total.
Operational impact
Stated in aggregate: intrusions that affected thousands of NASA computers, caused significant disruption to mission operations, and resulted in the theft of export-controlled and otherwise sensitive data, at an estimated cost of more than $7 million. Named consequences include the loss of the algorithms used to command and control the International Space Station, denial of access to NASA-supplied oceanographic data for more than 3,000 registered users for several days, and a brief public outage of NASA scientific research products.
Data compromised
Export-controlled and otherwise sensitive data; ISS command-and-control algorithms; Social Security numbers; data on the Constellation and Orion programmes; user credentials for more than 150 NASA employees.
Affected segments
ground
Disclosed
2012-02-29
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
Export-controlled and otherwise sensitive data left NASA systems as a result of intrusions into those systems, which is EXF-0007's shape: an adversary resident in ground infrastructure siphoning data along paths that already exist. The edge is derived because the testimony aggregates across 5,408 incidents and does not tie any exfiltration to a named mission ground system; where it does name one, JPL in November 2011, the edge is made on that record instead.
The testimony states that some of the 5,408 intrusions caused significant disruption to mission operations. That is the effect IMP-0002 names, in the source's own words. The edge is derived rather than direct because no mission, interface, or duration is identified: the claim is a summary characterisation of a two-year aggregate, not a described event.
Two OIG case summaries inside the testimony describe access being eliminated rather than degraded: after a February 2011 wire-fraud guilty plea, more than 3,000 registered users were denied access to oceanographic data supplied by NASA for several days; and after the intrusion behind the January 2012 arrest of a Romanian national, products from a variety of NASA scientific research efforts were inaccessible to the general public for a brief period. IMP-0003's scope extends to denying interested parties access, not only ground controllers, and a data-distribution outage is that.
The testimony reports the theft of export-controlled and otherwise sensitive data and, specifically, that the March 2011 theft of an unencrypted NASA notebook resulted in the loss of the algorithms used to command and control the International Space Station. Those algorithms are mission-critical spacecraft data whose loss is the harm IMP-0006 describes. The edge is derived because IMP-0006's literal subject is data gathered, processed and sent from the victim spacecraft, and command-and-control algorithms travel toward the spacecraft rather than from it, so the fit is by consequence rather than by definition.
Martin states that even after NASA fixes the vulnerability that permitted an attack to succeed, the attacker may covertly maintain a foothold inside NASA's system for future exploits. That is PER-0003's definition, long-lived access retained inside mission ground infrastructure, asserted by the agency's own Inspector General about the agency's own experience rather than inferred by a reader. Confidence is moderate because the statement generalises across NASA's APT experience rather than describing one observed foothold.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
Nothing in the testimony describes suppression or alteration of fault detection, isolation or recovery on any spacecraft. The citation is context.
Nothing describes telemetry processing, rendering or interpretation being inhibited. The mission-operations disruption the testimony mentions is unspecified and is already carried, at derived strength, by IMP-0002.
The nearest fact is that intruders stole credentials for more than 150 NASA employees, credentials that Martin says "could have been used to gain unauthorized access to NASA systems." Could have been. The testimony does not report that the stolen credentials were used to present as an authorised origin, and DE-0004 is about the use, not the holding.
Nothing concerns backup or standby ground segment, alternate commercial stations, or failover paths.
Carried in SPARTA against the Reuters citation, which resolves to a story about the Romanian defendant rather than to the agency-wide picture. No source describes infrastructure being compromised in order to stage reach into a mission; the intrusions are the operation, not preparation for one.
The testimony does not describe an adversary taking a mission's own ground system in order to obtain preconfigured TT&C access. Where a mission ground system was actually compromised, JPL, November 2011, that is the separate record, and the edge is made there.
"Installation of malicious software" on enterprise NASA computers is not the pre-positioning of exploit packages, patch images, modem profiles or operator macros on infrastructure with reach to a spacecraft that RD-0004.02 describes.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
Tier 1: The published record of a congressional oversight hearing, containing the written statement of the NASA Inspector General in full. Primary, official, and permanently addressable at congress.gov.
- Written statement of Paul K. Martin, Inspector General, NASA (the URL cited by SPARTA's bibliography)Government reportsupporting
Tier 1: Would be Tier 1 as the Inspector General's own publication of his statement. Recorded here for provenance only.
Tier 2: Named contemporaneous reporting by a specialist security journalist on the Inspector General's report to Congress. Reports on the primary document rather than on independent access, so no claim in this record rests on it alone.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.