The D.B. Cooper skyjacking produced ransom notes, newspaper letters, and claims of hidden ciphers. Cryptologists disagree. Here is what the FBI files and the evidence actually show.
A man calling himself Dan Cooper boarded Northwest Orient Flight 305 in Portland on November 24, 1971. He passed a note to flight attendant Florence Schaffner, claimed he had a bomb, demanded $200,000 and four parachutes, and jumped out the back stairs somewhere over southwest Washington. He was never found. The media misnamed him "D.B. Cooper," and the name stuck.
The FBI called its investigation NORJAK (for "Northwest Hijacking"). It ran for 45 years before the FBI closed the active case in July 2016 without identifying the skyjacker. Since then, the Bureau has continued releasing case files through FOIA, including a 398-page trove around July 4, 2025, reported by the New York Post, and Part 113 (391 pages) released January 6, 2026. None of these files confirmed a suspect.
Over the years, a persistent claim has circulated that Cooper left behind ciphers in letters mailed to newspapers. Investigator Thomas Colbert and codebreaker Rick Sherwood announced in 2018 that they had decoded these letters using "simple English gematria" and identified suspect Robert Rackstraw. Cryptologists rejected the claim. The bottom line is that there is no verified cipher in the D.B. Cooper case. You can test the claimed strings yourself with our Cipher Identifier and Text to Number converter.
Thanksgiving Eve, 1971. A man in a dark suit and tie bought a one-way ticket from Portland to Seattle under the name "Dan Cooper." He passed a note to flight attendant Florence Schaffner. She tucked it in her pocket, assuming it was a phone number. He leaned in and told her to look at the note. It said he had a bomb in his briefcase and wanted her to sit next to him.
Cooper demanded $200,000 in negotiable currency and four parachutes, two main and two reserve. The plane landed in Seattle. Passengers were released. The ransom and parachutes were delivered. Cooper kept the crew aboard and directed the pilot to fly toward Mexico at low altitude with the aft stairs down. Somewhere over southwest Washington, he jumped. He was never seen again.
The FBI launched NORJAK. Agents recovered some of the ransom money years later, in 1980, when a boy digging on a beach along the Columbia River found decaying $20 bills matching the serial numbers of the Cooper ransom. No body was ever recovered. No parachute was confirmed as Cooper's. The FBI's NORJAK case page documents the official record.
The media coined the name "D.B. Cooper" early in the reporting. A reporter confused a preliminary suspect name with the alias on the ticket. The real alias was "Dan Cooper." The error became permanent.
Between late 1971 and early 1972, several newspapers received letters from someone claiming to be D.B. Cooper. The Oregonian was among them. The letters contained typed or handprinted text, and some included strings of numbers and letters at the bottom. Two strings that attracted attention were "717171634*" and "7698QA2753."
The FBI laboratory examined these letters. A December 15, 1971 FBI lab memo stated that the significance of "717171634*" "remains unknown." The FBI viewed most of the Cooper letters as probable hoaxes. Skyjacking was a epidemic in the early 1970s, and copycat attention-seekers routinely mailed fake confessions and tips to newspapers and law enforcement.
This is the core problem. The strings exist, but they appear in letters the FBI never authenticated. They could be genuine messages from Cooper. They could be the work of a hoaxer. They could be a partial phone number, a shipping code, or gibberish typed by someone who wanted attention. Without a verified link to the skyjacker, there is no cipher to analyze, only unexplained strings on unverified documents.
If you want to see how a cryptanalyst approaches such material, paste the strings into our Letter Frequency Analyzer and compare the distribution against standard English. Short strings like these produce no meaningful statistical signal, which is part of why the FBI could not classify them.
In 2018, investigator Thomas Colbert held a press conference announcing that his team had cracked the Cooper letters. Colbert, a former Army investigator and journalist, had spent years pursuing a theory that the skyjacker was Robert Rackstraw, a Vietnam veteran with a criminal record and explosives training.
Colbert's team included Rick Sherwood, a former Army Security Agency veteran who served as their codebreaker. Sherwood claimed to have decoded the letter strings using "simple English gematria," a method that assigns numeric values to letters and looks for patterns. According to Colbert, the decoded messages pointed to Rackstraw, including references to military units and personal details.
The announcement generated significant media coverage. Colbert published documents and claimed the FBI had ignored his findings. He produced a list of decoded phrases he said connected Rackstraw to the hijacking.
The problem, as cryptologists quickly pointed out, is that "simple English gematria" is not a recognized cipher system. It is a numerological method. You assign numbers to letters, add them up, and interpret the results. There is no key, no algorithm, and no way to verify a decoding. Different assignment schemes produce different numbers, and the solver can try endless combinations until a desired result appears.
The strongest rebuttal came from Lawren Smithline, a mathematician and cryptologist at the Institute for Advanced Study. Smithline is known for cracking a 200-year-old cipher attributed to Thomas Jefferson in 2009, work published through the Princeton-based institute. He reviewed Sherwood's process and stated plainly that "simple English gematria" has "no value in determining reality."
Smithline's objection is mathematical. In a real cipher, the encryption process is deterministic. Given the key and the algorithm, there is exactly one plaintext. Given the ciphertext and enough plaintext, you can recover the key. Gematria does not work this way. The solver assigns numbers to letters, sums them, and then interprets the sums. Because the assignment scheme is arbitrary and the interpretation is subjective, the solver can produce any output they want by choosing the right scheme. This is confirmation bias dressed up as cryptanalysis.
The Oregonian, which had received some of the original Cooper letters, consulted two independent experts who cast doubt on the Sherwood decoding. The Oregonian's reporting on the Colbert claim documented the skepticism from the cryptologic community.
This is the same problem that plagues amateur "solutions" to the Zodiac Z13 cipher, the Voynich Manuscript, and other famous unsolved codes. When the method allows the solver to tune parameters until a desired name or phrase appears, the result is not a decryption. It is a construction. Real cryptanalysis requires a method that produces a unique, verifiable answer. The Wikipedia article on the Cooper case summarizes the academic and law enforcement consensus: no cipher has been verified.
The FBI closed the active NORJAK investigation in July 2016, citing the passage of time and the unlikelihood of resolving the case. But the Bureau did not lock away the files. It has continued processing FOIA requests and releasing case documents in batches.
Around July 4, 2025, the FBI released a 398-page trove of NORJAK files, reported by the New York Post. These files contained Form 302 interview summaries, the standard FBI document for recording witness and suspect interviews. The 302s covered many suspects investigated over the decades, including individuals whose names had never been public.
On January 6, 2026, the FBI released Part 113 of the NORJAK file, totaling 391 pages. This release included additional 302 reports, lab analyses, and correspondence. As with prior releases, none of the files confirmed a suspect. The 302s document interviews, tips, and dead ends. Some suspects were eliminated by alibi. Others were investigated and cleared. A few remain persons of interest in the eyes of amateur researchers, but the FBI made no posthumous identification.
Notably, none of the 2025-2026 releases contained a verified cipher. The files include references to the Cooper letters and the "717171634*" string, but the FBI's position remained unchanged: the letters are likely hoaxes, and the strings are unexplained but not cryptographic in any verifiable sense. The Seattle Times has covered the NORJAK file releases and the ongoing public interest in the case.
For cipher enthusiasts, the lesson is caution. The Cooper case attracts speculation because it is unsolved and dramatic. But speculation is not cryptanalysis. A real cipher solution requires a deterministic method, a verifiable key, and a plaintext that independent experts can reproduce. The Cooper letters have none of these.
The D.B. Cooper "cipher" claim is a useful case study in how to distinguish genuine cryptanalysis from numerology. The distinction matters beyond true crime. It applies to every unsolved cipher that attracts amateur attention.
A real cipher has three properties. First, the encryption process is deterministic: given the key and algorithm, there is exactly one ciphertext, and given the ciphertext and key, there is exactly one plaintext. Second, the method is reproducible: another person applying the same key and algorithm gets the same result. Third, the solution is verifiable: the plaintext is readable, coherent, and consistent with known facts about the sender.
The Sherwood gematria method fails all three tests. The assignment of numbers to letters is not fixed by any algorithm. The interpretation of sums is subjective. And the "decoded" text pointing to Rackstraw cannot be independently reproduced by someone who does not already know the desired answer.
Compare this to the Zodiac Z340 solution. David Oranchak, Jarl Van Eycke, and Sam Blake identified a specific transposition route and a specific substitution key. Anyone applying that route and key to Z340 gets the same plaintext. The FBI verified it independently. That is cryptanalysis. The Cooper gematria is not.
This is also why the FBI's Cryptanalysis and Racketeering Records Unit, which solves a reported 99 percent of the ciphers it receives, never endorsed the Colbert claim. Their standards require deterministic, reproducible methods. The Cooper strings do not meet them.
No verified cipher exists in the D.B. Cooper case. Letters mailed to newspapers in 1971-1972 contained strings of numbers and letters, but the FBI viewed most of these letters as likely hoaxes. A December 1971 FBI lab memo stated the significance of one string, "717171634*," "remains unknown." No cryptologic authority has verified a cipher.
Investigator Thomas Colbert and codebreaker Rick Sherwood announced in 2018 that they had decoded the letters using "simple English gematria" and identified suspect Robert Rackstraw. Cryptologist Lawren Smithline, who cracked a 200-year-old Jefferson cipher in 2009, said the method has "no value in determining reality" because the solver can tune parameters to get any desired result.
The FBI closed the active NORJAK investigation in July 2016 after 45 years without identifying the skyjacker. However, the FBI continues releasing case files through FOIA. A 398-page trove was released around July 4, 2025, and Part 113 (391 pages) was released January 6, 2026. None of these files confirmed a suspect.
Gematria assigns numeric values to letters and interprets the sums. Because the assignment scheme is arbitrary and the interpretation is subjective, the solver can try endless combinations until a desired name or phrase appears. This is confirmation bias, not deterministic cryptanalysis. A real cipher solution must be reproducible by independent experts applying the same key and algorithm.
Yes. In 1980, a boy digging on a beach along the Columbia River found decaying $20 bills. The serial numbers matched the Cooper ransom. No additional ransom money has ever been found in circulation, and no body or parachute was confirmed as Cooper's.
Code Identifier
Identify the cipher or encoding used in a piece of text. Paste encoded or encrypted data and the code identifier returns ranked candidates with confidence scores.
Letter Frequency Analyzer
Count and analyze letter frequencies in text for cryptogram solving.
Text to Number (A=1, B=2)
Convert text to numbers using A=1, B=2, phone keypad, and ASCII encoding systems.
The Zodiac Killer Ciphers: How Z340 Was Solved After 51 Years
For 51 years, a 340-character cipher sat in FBI files. It was solved in December 2020 by three amateur codebreakers working from home. Z13 and Z32 remain unsolved. Here is how it was done.
The Somerton Man: Australia's Tamam Shud Cipher That's Never Been Solved
On December 1, 1948, a man was found dead on Somerton Beach in Adelaide with a torn scrap reading 'Tamam Shud.' A code in a copy of the Rubaiyat has never been decoded. A 2022 DNA identification is contested. Here is what is known.