---
title: "Hackers Stole A Reaper Drone Manual From An Air Force Captain And Tried To Sell It For $150"
date: "2018-07-11"
modified: "2018-07-11"
authors:
  - name: "Paul Szoldra"
    job_title: "Editor"
    link: "https://taskandpurpose.com/authors/paul-szoldra/"
url: "https://taskandpurpose.com/news/hackers-stole-a-reaper-drone-manual-from-an-air-force-captain-and-tried-to-sell-it-for-150-2624458131/"
categories:
  - "Air Force"
  - "Aircraft"
  - "Drones"
  - "Intelligence"
  - "Military Branches"
  - "News"
  - "Tactics"
  - "Tech & Tactics"
tags:
  - "cyber command"
  - "southern command"
---

# Hackers Stole A Reaper Drone Manual From An Air Force Captain And Tried To Sell It For $150

![](<https://taskandpurpose.com/wp-content/uploads/2020/12/18989344-1.jpg>)

A South America-based hacking crew stole an export-controlled U.S. Air Force manual for the MQ-9 Reaper unmanned aerial vehicle and tried to sell it for $150 — thanks to an unidentified Air Force captain who had the document sitting on his home network, stuck behind a default password.

The document was found for sale on the dark web last month, but no one ended up buying it, despite its rock-bottom price, [according](<https://www.thedailybeast.com/hacker-selling-pentagons-killer-drone-manual-on-dark-web-for-dollar150-cheap>) to Kevin Poulsen at The Daily Beast. Titled "MQ-9A Reaper Block 5 (UHK97000-15) RPA Maintenance Event 1 Delta Training," the document, though unclassified, offered technical data on the drone that could potentially be used by adversaries to defeat it. (Built by General Atomics, the MQ-9 Reaper is slated to be in the Air Force inventory into the [2030s](<https://www.flightglobal.com/news/articles/usafs-small-uas-roadmap-calls-for-swarming-kamikaz-424973/>). It's also used by the Navy, Customs and Border Protection, several foreign militaries, and others.)

"This document contains technical data whose export is restricted," the pilfered manual says, adding: "Comply with distribution statement and destroy by any method that will prevent disclosure of the contents or reconstruction of the document."

Andrei Barysevich at cybersecurity firm Recorded Future, who first spotted the document on June 1, [wrote an analysis](<https://www.recordedfuture.com/reaper-drone-documents-leaked/>) of the hacker group's methods, which were fairly unsophisticated. The group used the Internet of Things search engine *Shodan* to find open, unsecured networks, before connecting and pilfering them of documents.

The drone manual came from a captain at the 432nd Aircraft Maintenance Squadron out of Creech Air Force Base in Nevada, the analysis said.

Besides getting hold of the Reaper docs, the hacker also apparently grabbed content from some other military source (or sources) that includes M1 Abrams tank training manuals, and a manual meant to educate soldiers on how to mitigate the risk of improvised explosive devices.

*Correction: This article was updated to note the Reaper was made by General Atomics, not General Dynamics.*

![](<https://taskandpurpose.com/wp-content/uploads/2020/12/image-placeholder-title-16.jpg>)

## Author
Paul Szoldra was the Editor in Chief of Task & Purpose from October 2018 until August 2022. Since joining T&P, he has led a talented team of writers, editors, and creators who produce military journalism reaching millions of readers each month. He also founded and edits [Duffel Blog](<https://www.duffelblog.com/>), a popular satirical newsletter for the military. Before becoming a journalist in 2013, he served as a Marine infantryman in Afghanistan, Korea, and other areas of the Pacific. His eyes still go up every time a helicopter from Camp Pendleton flies over his office in Southern California.

### Author social links  
[Twitter](<https://twitter.com/paulszoldra>)  
[LinkedIn](<https://www.linkedin.com/in/paulszoldra/>)  
[Facebook](<https://www.facebook.com/pszoldra>)  
[Instagram](<https://www.instagram.com/paulszoldra/>)