CASE DOSSIER sentenced

U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)

Docket: 3:20-cr-00032 Court: U.S. District Court for the District of Nevada Opened: 2020-08-25 Sector: Automotive, Advanced Manufacturing, Clean Energy

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$4.0 million
Intended extortion demand was $4 million; operation was intercepted before malware execution.
Techniques
3
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the District of Nevada.
  • Primary Target Sector: Automotive, Advanced Manufacturing, Clean Energy.
  • Documented Financial Loss: $4.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Automotive, Advanced Manufacturing, Clean Energy networks. Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.

Operational & Financial Fallout

Intended extortion demand was $4 million; operation was intercepted before malware execution. Impacted Automotive, Advanced Manufacturing, Clean Energy infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Automotive, Advanced Manufacturing, Clean Energy networks. Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet.

Artifacts & Tooling: T1078 Valid Accounts
2
Phase 2: Impact Operational Disruption or Extortion Detonation
MITRE ATT&CK T1486 →

The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers.

Artifacts & Tooling: T1486 Data Encrypted for Impact
Real-World Blast Radius & Operational Fallout

Intended extortion demand was $4 million; operation was intercepted before malware execution. Impacted Automotive, Advanced Manufacturing, Clean Energy infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2020-08-22 arrest

Kriuchkov arrested in Los Angeles while attempting to flee the United States.

2021-03-18 plea

Pleads guilty to conspiracy to intentionally cause damage to a protected computer.

2021-05-25 sentencing

Sentenced to time served (10 months) and ordered to pay $14,825 in restitution before deportation.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Egor Igorevich Kriuchkov Russian Federation sentenced 10 mo None Conspired to bribe a Tesla employee to deploy ransomware; sentenced to 10 months and deported.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet." Criminal Complaint ¶ 12, Page 6 reviewed
T1486 Data Encrypted for Impact
Impact
"The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers." Plea Agreement ¶ 6, Page 5 reviewed
T1498 Network Denial of Service
Impact
"The plan included launching a distributed network denial of service flood against Tesla's external gateways to distract security staff during malware deployment." Complaint ¶ 15, Page 7 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt), No. 3:20-cr-00032 (U.S. District Court for the District of Nevada 2020), https://cybercaselibrary.com/cases/us-v-kriuchkov-tesla-ransomware/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-kriuchkov-tesla-ransomware" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>