21 August 2023

Tesla confirms “insider wrongdoing” was the cause of May data breach


Tesla confirms “insider wrongdoing” was the cause of May data breach

Tesla’s massive data breach impacted the personal information of over 75,000 and was a result of an “insider wrongdoing,” according to a data breach notice posted by the office of the Maine Attorney General.

The incident came to light in May 2023 when a German media resource Handelsblatt reported that a Tesla employee stole about 100GB of data from the automaker, including the sensitive information related to 100,000 names of past and present employees including the social security number of Tesla CEO Elon Musk and thousands of customer complaints about their cars like braking and acceleration issues.

In a notice to staff, Tesla said that it was informed of the breach on May 10. A further investigation revealed, “that two former Tesla employees misappropriated the information in violation of Tesla’s IT security and data protection policies and shared it with the media outlet.”

The impacted data included names and certain contact information such as address, phone number, and/or email address of current and former employees.

The company said it filed lawsuits against the culprits behind the breach, which resulted in the seizure of electronic devices that were believed to have contained the Tesla information. The automaker also obtained court orders that prohibit the former employees from further use, access, or dissemination of the data, subject to criminal penalties.

Earlier this month, a team of students at the Technical University of Berlin found a way to unlock premium Tesla features behind a paywall, including Full Self-Driving (FSD) and heated rear seats.

Back to the list

Latest Posts

Cyber Security Week in Review: December 20, 2024

Cyber Security Week in Review: December 20, 2024

In brief: A suspected Russian cyberattack hits Ukraine's state registries, new ICS malware targets Mitsubishi and Siemens systems, and more.
20 December 2024
Major phishing campaign abuses HubSpot to steal credentials from European firms

Major phishing campaign abuses HubSpot to steal credentials from European firms

The attackers exploited the service’s legitimate functionality to create convincing phishing pages.
19 December 2024
UAC-0125 malware campaign targeting Ukrainian military personnel

UAC-0125 malware campaign targeting Ukrainian military personnel

Victims are lured to fraudulent websites offering to download a malicious version of the Army+ app.
19 December 2024