Skip to content
safemode.space
All incidents
2005-04-01 (approximate)
data exfiltration
ground

NASA network intrusions and data exfiltration to Taiwan and Moscow (BusinessWeek, 2008)

Confidence in this reading:
moderate

What happened

On 20 November 2008 Keith Epstein and Ben Elgin reported in BusinessWeek, from internal NASA documents they say they reviewed and that had not previously been disclosed, on a pattern of intrusions against NASA networks reaching back to the late 1990s. In April 2005 malware called stame.exe entered the network of the Kennedy Space Center and gathered data from computers in the Vehicle Assembly Building where the Space Shuttle is maintained, on a network managed by a joint venture owned by Boeing and Lockheed Martin, and sent Shuttle information to a computer system in Taiwan. By December 2005 the compromise, in BusinessWeek's words, "had spread to a NASA satellite control complex in suburban Maryland and to the Johnson Space Center in Houston": at least 20 gigabytes of compressed data, described as the equivalent of 30 million pages, were routed from Johnson to the system in Taiwan, much of it from a server connected to a network that tracks malfunctions that could threaten the International Space Station. The flow was discovered seven months after the April intrusion, after which work in the Vehicle Assembly Building was halted for several days while hundreds of systems were combed. The article separately reports that the US-German ROSAT satellite was rendered useless in 1998 after turning suddenly toward the sun, and that NASA investigators later determined the accident was linked to a cyber-intrusion at the Goddard Space Flight Center from which information was sent to computers in Moscow.

Sourced to a single trade-press investigation resting on internal NASA documents that are not public: their contents reach this record only through the reporters' description of them, which is why overall_confidence is moderate rather than high and why the article is Tier 2 despite its documentary basis. Attribution is hedged in the source and is left hedged here: intruders are said to be suspected of ties to the governments of China and Russia, and Taiwan is described as a digital way station often used by the Chinese government, on the authority of unnamed US security specialists. One edge, IMP-0005, is flagged for an explicit editorial ruling before import. It rests on the article's statement that NASA investigators determined the loss of the ROSAT satellite was linked to a cyber-intrusion at Goddard. Linked to is not caused by, no mechanism is given, and the underlying documents cannot be checked; it is carried at low confidence as derived evidence so the record does not silently drop its only spacecraft-segment claim, but dropping it is a defensible call and would also remove space from affected_segments.

Attack vector

Not stated. The article names the resident malware (stame.exe) and the networks it reached but does not describe how it entered the Kennedy Space Center network, and offers no entry path for the 1998 Goddard intrusion.

Operational impact

Work in the Vehicle Assembly Building was halted for several days during the investigation and hundreds of computer systems were combed. The article states that the NASA documents it reviewed do not refer to any specific interference with operations of the Shuttle, which was aloft from 26 July to 9 August 2005, or of the International Space Station. Separately, the ROSAT satellite is reported to have been rendered useless in 1998.

Data compromised

At least 20 gigabytes of compressed data routed from the Johnson Space Center to a system in Taiwan, described as the equivalent of 30 million pages, much of it from a server on a network tracking malfunctions that could threaten the International Space Station; an undetermined amount of Space Shuttle information from the Vehicle Assembly Building.

Affected segments

ground, space

Disclosed

2008-11-20

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • The exfiltration ran from inside NASA ground infrastructure, spreading from the Kennedy Space Center to a satellite control complex in suburban Maryland and to the Johnson Space Center, and continued for seven months before it was discovered. EXF-0007 describes exactly that: an adversary resident in mission ground infrastructure siphoning data along paths that already carry it. The article names the resident program, the systems and the flow.

    https://www.bloomberg.com/news/articles/2008-11-19/network-security-breaches-plague-nasa

  • FLAGGED FOR EDITORIAL RULING BEFORE IMPORT. The article states that the US-German ROSAT satellite was rendered useless after it turned suddenly toward the sun and that NASA investigators later determined the accident was linked to a cyber-intrusion at the Goddard Space Flight Center. A satellite permanently deprived of its use is what IMP-0005 describes. Confidence is low and the evidence type is derived because the source asserts a link rather than a causal mechanism, says nothing about what the link was, and rests on NASA documents that are not public and cannot be checked. If the editor rules the causal claim insufficient, this edge is dropped and space leaves the record's affected_segments.

    https://www.bloomberg.com/news/articles/2008-11-19/network-security-breaches-plague-nasa

  • IMP-0006Theft
    high
    direct
    #

    At least 20 gigabytes of compressed data was routed from the Johnson Space Center to a system in Taiwan, and much of it came from a computer server connected to a network that tracks malfunctions that could threaten the International Space Station. That is mission data taken from the systems that process it, quantified, with a stated destination and a stated content class.

    https://www.bloomberg.com/news/articles/2008-11-19/network-security-breaches-plague-nasa

  • stame.exe resided undetected on NASA ground systems from April 2005 to at least December 2005, spreading from Kennedy to a satellite control complex and to Johnson, which is retained presence inside mission ground infrastructure. The edge is derived because the article describes the program's collection and spread without ever characterising it as a maintained foothold, and because the Vehicle Assembly Building is launch-processing rather than a TT and C path; what carries the edge is the Johnson server on the ISS malfunction-tracking network.

    https://www.bloomberg.com/news/articles/2008-11-19/network-security-breaches-plague-nasa

  • The article's stated subject is the theft of secret information on satellites, rocket engines, launch systems and the Space Shuttle, and it locates stame.exe in the Vehicle Assembly Building where the Shuttle is maintained. That content class is REC-0001's own list. Confidence is moderate because the article characterises the material by category rather than naming artefacts, and because this edge and IMP-0006 read a single event at two layers, acquisition and loss, rather than describing two behaviours.

    https://www.bloomberg.com/news/articles/2008-11-19/network-security-breaches-plague-nasa

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Cited by SPARTA. The article's entry points are a contractor-managed centre network and NASA centre computers, not a SATCOM terminal, tasking portal or customer gateway interconnecting with a mission core. The nearest fact, that the violated Kennedy network is managed by a Boeing-Lockheed joint venture, is a contractor-operated mission network, which is what IA-0007 and EXF-0007 already carry.

  • Cited by SPARTA, and a term-similarity match rather than a scope match. The article says "launch systems" were among the information stolen, meaning launch engineering data, which is REC-0001's subject. REC-0004 is the collection of launch schedules, windows, sites, range operators and vehicle configurations to time an operation, and nothing in the article describes that. Accepting it would repeat the wrong-scope-acronym error the curation rules already name.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • BusinessWeek (later Bloomberg Businessweek) · Keith Epstein, Ben Elgin · 2008-11-20

    Tier 2: Named investigative reporting by two journalists, resting on internal NASA documents the reporters state they reviewed. Not Tier 1, because those documents are not published: their contents reach the record only through the reporters' description of them, and no claim in this record can be checked against a primary source.

  • seclists.org (Nmap Project) · Keith Epstein, Ben Elgin (redistributed by InfoSec News) · 2008-11-24

    Tier 3: A public mailing-list archive carrying the article verbatim. It has no editorial standing of its own and adds no facts; it is the retrievable copy the quotations in this record were read from.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.