{
  "id": "case-kriuchkov-tesla",
  "slug": "us-v-kriuchkov-tesla-ransomware",
  "title": "U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)",
  "summary": "Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.",
  "case_number": "3:20-cr-00032",
  "court": "U.S. District Court for the District of Nevada",
  "district": "D. Nev.",
  "country": "United States",
  "opened_at": "2020-08-25",
  "status": "sentenced",
  "victim_sector": "Automotive, Advanced Manufacturing, Clean Energy",
  "victim_country": "United States",
  "loss_amount_usd": 4000000,
  "loss_amount_note": "Intended extortion demand was $4 million; operation was intercepted before malware execution.",
  "first_seen_at": "2020-07-16T00:00:00Z",
  "last_updated_at": "2026-08-28T14:00:00Z",
  "actor_slug": "kriuchkov-group",
  "defendant_slugs": [
    "egor-kriuchkov"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet.",
      "evidence_locator": "Criminal Complaint \u00b6 12, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Complaint: U.S. v. Kriuchkov",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-conspiracy-cause-damage-protected-computer",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers.",
      "evidence_locator": "Plea Agreement \u00b6 6, Page 5",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-conspiracy-cause-damage-protected-computer",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1498",
      "evidence_excerpt": "The plan included launching a distributed network denial of service flood against Tesla's external gateways to distract security staff during malware deployment.",
      "evidence_locator": "Complaint \u00b6 15, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Complaint: U.S. v. Kriuchkov",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-conspiracy-cause-damage-protected-computer",
      "technique_name": "Network Denial of Service",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2020-08-22",
      "description": "Kriuchkov arrested in Los Angeles while attempting to flee the United States."
    },
    {
      "event_type": "plea",
      "event_date": "2021-03-18",
      "description": "Pleads guilty to conspiracy to intentionally cause damage to a protected computer."
    },
    {
      "event_type": "sentencing",
      "event_date": "2021-05-25",
      "description": "Sentenced to time served (10 months) and ordered to pay $14,825 in restitution before deportation."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Automotive, Advanced Manufacturing, Clean Energy networks. Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.",
    "blast_radius": "Intended extortion demand was $4 million; operation was intercepted before malware execution. Impacted Automotive, Advanced Manufacturing, Clean Energy infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Phase 2: Impact",
        "title": "Operational Disruption or Extortion Detonation",
        "description": "The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers.",
        "technical_artifacts": [
          "T1486",
          "Data Encrypted for Impact"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}