{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-russian-offered-a-tesla-employee-1m-to-plant-ransomware-at-the-nevada-gi"},"incident":{"title":"Russian offered a Tesla employee $1M to plant ransomware at the Nevada Gigafactory","date":"2020-08","date_precision":"month","victim_org":"Tesla, Inc.","sector":"Manufacturing","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"No loss occurred. The targeted employee reported the approach to Tesla and the FBI, and the plot was never executed.","records_affected":null,"threat_actor":"Egor Igorevich Kriuchkov (later pleaded guilty)","summary":"Egor Kriuchkov, a 27-year-old Russian national who entered the US in July 2020, approached a Russian-speaking Tesla employee at the Nevada Gigafactory and offered payment to introduce malware into Tesla's network. The offer began at $500,000 and rose to $1 million in cash or bitcoin. The employee reported the approach, cooperated with the FBI, and Kriuchkov was arrested in Los Angeles after attempting to flee the country. Elon Musk publicly confirmed the incident.","how_it_worked":"Kriuchkov built rapport with the employee in person over social meetings before naming the ask. The proposal was for the employee to run attacker-supplied ransomware inside the plant network, either by opening a malicious email attachment or plugging in an infected USB stick, while the conspirators ran a simultaneous distributed denial-of-service attack to occupy Tesla's security team. The group intended to exfiltrate Tesla files and extort the company for their non-release; Kriuchkov said the malware itself had cost $250,000 to develop. The scheme died at the first step because the employee, rather than accepting, told Tesla and then wore a wire for the FBI.","lessons":"A no-blame, clearly advertised channel for reporting bribery approaches is the control that actually catches insider recruitment, since no technical control sees the offer being made.","confidence":"Confirmed","sources":[{"title":"How a $1 million plot to hack Tesla failed","url":"https://www.technologyreview.com/2020/08/28/1007752/how-a-1-million-plot-to-hack-tesla-failed/","publisher":"MIT Technology Review"}],"entry_type":"incident","slug":"2020-russian-offered-a-tesla-employee-1m-to-plant-ransomware-at-the-nevada-gi","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-russian-offered-a-tesla-employee-1m-to-plant-ransomware-at-the-nevada-gi"}}