Skip to content
safemode.space
All incidents
2014-09-01 (approximate)
network intrusion
ground

NOAA NESDIS satellite ground-system intrusion, September-October 2014

Confidence in this reading:
high

What happened

In early September 2014 the National Oceanic and Atmospheric Administration experienced what the Commerce Department's Inspector General called a significant cyber attack. An attacker exploited vulnerabilities in internet-accessible web applications and compromised internal systems operated by the National Environmental Satellite, Data, and Information Service. Three NESDIS systems were compromised, with complete control of system components gained within one: the Environmental Satellite Processing Center, a high-impact system responsible for disseminating critical weather satellite data to customers including the National Weather Service and the US Navy's and Air Force's primary forecast centres; the NOAA Satellite Operations Facility Administrative Local Area Network; and the National Geophysical Data Center Data Archive Management and User System. Using usernames and passwords harvested from the NSOF system the attacker also obtained unauthorised access to NESDIS's Headquarters IT Support LAN, NOAA's Web Operation Center and NOAA's Cyber Security Center. NOAA determined the attacker obtained at minimum usernames and passwords including those of system administrators, system configuration information, and records from NOAA's own cyber incident tracking system documenting its analysis of the attack; it could not determine the full extent of what was taken, because logs were unavailable and the attacker used encryption when exfiltrating data. Initial access was through a publicly accessible web application that supported only internal NOAA users, believed compromised by exploiting a high-risk input-validation vulnerability that penetration testing had identified in February 2013 and that was never remediated because web-developer support had been discontinued.

Sourced to a Tier 1 Commerce Department Inspector General audit that examined this specific attack, which is why confidence is high although no actor is named. Attribution is deliberately kept out of the record fields: the OIG report is silent on it, and the public attribution to China comes from Rep. Frank Wolf as reported in November 2014, which is a congressional statement carried in the press rather than a government finding. The rejection of IMP-0003 is the substantive curation call. Weather satellite data dissemination did stop for two days and data from that window was lost, but the OIG is explicit that NESDIS disconnected ESPC itself as containment, after an unrelated website defacement convinced officials they could not wait longer; an outage the defender chooses is not a measure the adversary designed, which is what IMP-0003 requires. The same test rejects IMP-0002 on jpl-raspberry-pi-intrusion-2018. Contemporaneous 2014 reporting counts four compromised NOAA websites where the 2016 audit counts three compromised NESDIS systems plus unauthorised access to three more; these are different units of account rather than a contradiction, and the record uses the audit's.

Attack vector

Exploitation of a high-risk input-validation vulnerability in a publicly accessible web application that supported only internal NOAA users, identified by penetration testing in February 2013 and left unremediated, followed by pivoting to three further systems by reusing usernames and passwords obtained from that initial compromise of the NOAA Satellite Operations Facility Administrative Local Area Network. Web applications in the two other compromised NESDIS systems were exploited as well, one of them through a vulnerability that NESDIS had not previously identified.

Operational impact

Dissemination of weather satellite data through the Environmental Satellite Processing Center was disrupted from 20 to 22 October 2014, when NESDIS disconnected the system from the internet as part of containment; satellite data gathered during that window was not recovered. The National Weather Service's National Centers for Environmental Prediction assert that this satellite data is critical to the weather prediction models forecasters use, but could not fully determine the impact on those models during the disruption. The outage was prolonged by an ESPC firewall ruleset that had accumulated more than 16,000 rules over ten years without periodic review, of which a subset of more than 3,100 controlling internet access had to be rebuilt rule by rule before reconnection.

Data compromised

At minimum, usernames and passwords including those of system administrators, system configuration information, and records from NOAA's cyber incident tracking system documenting its analysis of the attack. The full extent is unknown: NOAA states that the unavailability of logs and the attacker's use of encryption when exfiltrating data limited its ability to determine what was taken.

Affected segments

ground

Disclosed

2014-11-12

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • The audit records that the attacker used encryption when exfiltrating data, which states that exfiltration occurred from inside the compromised ground systems rather than leaving it to be inferred. What left is partly known, usernames and passwords including administrators', system configuration information, and NOAA's own incident-tracking records documenting its analysis of the attack, and partly unknowable, because the logs that would show it were unavailable.

    https://www.oig.doc.gov/OIGPublications/OIG-16-043-A.pdf

  • The attacker compromised three NESDIS systems and gained complete control of system components within one of them. The compromised set includes the Environmental Satellite Processing Center, which the audit describes as the most critical system compromised because it is responsible for disseminating critical weather satellite data to NESDIS customers, and the NOAA Satellite Operations Facility Administrative LAN. These are satellite ground-segment processing and data-handling systems, which is IA-0007's own subject, and a Tier 1 audit names them.

    https://www.oig.doc.gov/OIGPublications/OIG-16-043-A.pdf

  • The attacker held access across six NOAA systems from the compromise in early September until containment on 20 October, having pivoted from the initially compromised system using credentials harvested there. That is maintained presence inside satellite ground infrastructure over roughly six weeks. Confidence is moderate because the audit describes the extent and the pivots without naming any persistence mechanism the attacker installed.

    https://www.oig.doc.gov/OIGPublications/OIG-16-043-A.pdf

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • The entry point was a publicly accessible web application that was only supposed to serve internal NOAA users: an exposed internal application, not a user-segment or partner environment interconnecting with a mission core.

  • Cited by SPARTA, and the rejection that most needs stating. Weather satellite data dissemination did stop from 20 to 22 October, and data from that window was never recovered. But the OIG is explicit about the cause: NOAA disconnected ESPC from the internet as part of its containment strategy, after an unrelated defacement convinced officials they could no longer wait. IMP-0003 describes measures an adversary designs to eliminate the use of a system. This outage was the defender's decision. This batch applies that test consistently: the same rejection is made on jpl-raspberry-pi-intrusion-2018, where Johnson Space Center's loss of DSN data was also its own containment call.

  • Credentials, system configuration information and incident-tracking records are not the mission data IMP-0006 is about. The same distinction is applied on mckinnon-nasa-dod-intrusions-2001-2002, doppelpaymer-dmi-nasa-contractor-2020 and nasa-employee-pii-server-breach-2018.

  • Cited by SPARTA, and a subtler miss. The vulnerability was indeed known: to NOAA, from its own February 2013 penetration testing, and left unremediated. REC-0008.03 describes an adversary correlating discovered component and software versions against public and private vulnerability sources to build an exploit catalogue. The OIG documents the defender's knowledge and the defender's failure to act on it, and says nothing about how the attacker found the flaw. Known to whom is the whole question.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.