U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the District of Nevada.
- Primary Target Sector: Automotive, Advanced Manufacturing, Clean Energy.
- Documented Financial Loss: $4.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Automotive, Advanced Manufacturing, Clean Energy networks. Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.
Operational & Financial Fallout
Intended extortion demand was $4 million; operation was intercepted before malware execution. Impacted Automotive, Advanced Manufacturing, Clean Energy infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Automotive, Advanced Manufacturing, Clean Energy networks. Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.
Adversary Kill Chain Flow
2 Documented PhasesDefendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet.
The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers.
Intended extortion demand was $4 million; operation was intercepted before malware execution. Impacted Automotive, Advanced Manufacturing, Clean Energy infrastructure and associated victim operations.
Procedural & Incident Timeline
Kriuchkov arrested in Los Angeles while attempting to flee the United States.
Pleads guilty to conspiracy to intentionally cause damage to a protected computer.
Sentenced to time served (10 months) and ordered to pay $14,825 in restitution before deportation.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Egor Igorevich Kriuchkov | Russian Federation | sentenced | 10 mo | None | Conspired to bribe a Tesla employee to deploy ransomware; sentenced to 10 months and deported. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet." | Criminal Complaint ¶ 12, Page 6 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers." | Plea Agreement ¶ 6, Page 5 | reviewed |
| T1498 | Network Denial of Service Impact | "The plan included launching a distributed network denial of service flood against Tesla's external gateways to distract security staff during malware deployment." | Complaint ¶ 15, Page 7 | reviewed |