NASA’s Office of Inspector General (OIG) reported in 2021 that the agency recorded 6,094 cybersecurity events over fiscal years 2017 through 2020. That supports the headline’s “over 6,000” figure, but it does not mean NASA suffered 6,094 successful hacks or data breaches: the tally included policy violations and lost or stolen equipment as well as attack activity.
What the 6,094 figure counts
In its 2021 Cybersecurity Readiness audit, NASA OIG described more than 6,000 cyber-attacks in the preceding four years. Its underlying table lists 6,094 events across fiscal years (FY) 2017–2020. The report’s opening summary uses “cyber-attacks,” while the table categorizes “types of cyber-attacks”; neither wording makes the total a count of confirmed, successful intrusions. The table also notes that legacy figures were adjusted to align with current Federal Information Security Modernization Act (FISMA) reporting parameters. NASA OIG report IG-21-019.
| Fiscal year | Recorded events |
|---|---|
| FY2017 | 1,284 |
| FY2018 | 1,137 |
| FY2019 | 1,888 |
| FY2020 | 1,785 |
| FY2017–FY2020 total | 6,094 |
These are annual totals from the OIG’s published table, not a current NASA incident rate. The report does not establish that the same number or rate continued after FY2020.
Which events were included?
The OIG’s categories included several kinds of activity and security-related records. They should not be read as a ranking of successful compromises:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
- Attack methods: brute-force network attacks (listed as attrition), email, external or removable media, impersonation, and web activity.
- Policy and equipment records: improper usage and loss or theft of equipment.
- Other: events that did not fall into the other listed types.
In the report, “improper usage” meant acceptable-use policy violations, such as installing unapproved software or viewing inappropriate material. It was the largest listed category in FY2020, with 1,103 events; the category had 249 in FY2017. OIG reported that NASA officials found the increase concerning but believed improved cybersecurity software had increased network visibility and contributed to more events being recorded. The increase therefore cannot, by itself, show that successful attacks rose by the same amount.
Was there a real intrusion among the events?
Yes. The OIG described a 2018 incident in which an external user account connected an unauthorized device to Jet Propulsion Laboratory (JPL) servers, inadvertently exposing the network. Hackers then infiltrated the system and accessed servers and NASA’s Deep Space Network. This documented case shows that NASA faced serious intrusions, but it is one example; the report does not identify it as the cause of the 6,094-event total.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What later oversight says about NASA cybersecurity
GAO found unfinished risk-management work in selected systems
In a report published June 25, 2025, the U.S. Government Accountability Office (GAO) assessed risk-management implementation for four selected NASA systems. It found that implementation remained incomplete among those systems and issued 16 recommendations. The recommendations addressed issues including an agency-wide cybersecurity risk assessment, documenting and applying controls, corrective-action plans (POA&Ms), authorization-package quality control, and continuous-monitoring strategies. NASA’s response varied by recommendation, so the findings should not be reduced to a claim that the agency accepted or rejected them all. GAO report GAO-25-108138.
GAO explained that NASA mission projects handle sensitive command-and-control operational data and spacecraft intellectual property; theft or manipulation could have serious consequences. Its findings concern selected systems and risk-management processes, not a new agency-wide count of incidents.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsNASA also reported security improvements
NASA’s 2024 Information Technology Annual Report, published March 11, 2025, says the agency exceeded 90 percent implementation targets for data-at-rest encryption, data-in-transit encryption, and multifactor authentication. NASA also reported that its vulnerability disclosure program had received more than 800 reports and enabled remediation of over 700 vulnerabilities during the report’s 2024 activity period. These are agency-reported measures of progress; they do not establish that all cybersecurity risks have been resolved. NASA 2024 IT Annual Report.
NASA OIG’s 2025 Report on NASA’s Top Management and Performance Challenges, posted January 15, 2026, continued to identify managing cybersecurity risks and emerging technology as one of five key challenges. NASA OIG 2025 challenges report.
Quick Recap
Best Value
Rank #4
How to interpret the headline
- Accurate: NASA OIG’s 2021 report recorded 6,094 events across FY2017–FY2020 and summarized the period as more than 6,000 cyber-attacks.
- Not established by that figure: that all events were successful intrusions, that 6,094 data breaches occurred, or that this rate continued beyond FY2020.
- Important context: the counted categories included policy violations and equipment loss or theft, and NASA officials said improved software visibility likely contributed to the rise in recorded events.
- Later picture: NASA reported improvements in some security controls, while GAO and NASA OIG continued to identify risk-management work as an oversight concern.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

