Case file · TESLA 2020

The Tesla insider bribe plot: the $1 million offer an employee reported

Published 2026-09-29 · 4 min read · Missing control: Insider bribe reporting channel

In 2020 a criminal crew tried to buy its way into Tesla's Nevada battery factory by offering one employee up to $1 million to plug malware into the company network.[1][3] This case file covers how the approach worked, why it failed, and the one control that turned a would-be insider attack into an FBI sting.

What happened

Egor Igorevich Kriuchkov, then 27, a Russian national, had met a Tesla employee back in 2016. In July 2020 he got back in touch over a messaging app, saying he was planning a vacation in the US, and traveled to Nevada to see him.[3][4] The employee worked at the Gigafactory in Sparks, near Reno, a 1.9 million-square-foot plant that makes batteries.[4]

On August 3, 2020, after a road trip to Lake Tahoe, Kriuchkov made his pitch at a bar in the Reno area. Prosecutors said he asked the employee to install malware on Tesla's systems in exchange for a payment that started at $500,000 and was later raised to $1 million, payable in cash or bitcoin.[3][4]

The employee did not take the money. He told Tesla, and Tesla called the FBI.[1][2][5] Later meetings between the two were recorded while agents watched. When Kriuchkov sensed trouble, he drove from Reno to Los Angeles, where he was arrested on August 22, 2020, as he tried to leave the country.[1][4]

How it worked

The plan skipped the hard part of hacking. Instead of breaking through Tesla's defenses from outside, the crew wanted someone already inside to run their software on a company computer, so data could be copied out and used for extortion.[1][5]

According to prosecutors and court filings as reported, the malware was to be custom-built for Tesla at a cost of about $250,000. A flood of junk traffic from outside, known as a denial-of-service attack, would keep the security team busy while data was quietly copied out. The crew would then demand a ransom and threaten to publish the stolen files if Tesla did not pay.[3][4] Kriuchkov also claimed the group had squeezed a $4 million ransom out of another company.[3]

The weak point the crew was betting on was not a server. It was the chance that one person, offered life-changing money, would keep the offer to himself.

How it was caught and what it cost

The employee's report was the whole detection system. Federal authorities credited him for coming forward, and the network was never compromised.[2] Tesla chief executive Elon Musk publicly confirmed the company was the target and called it a serious attack.[3][4]

Kriuchkov was indicted in September 2020 and pleaded guilty on March 18, 2021, to conspiracy to intentionally cause damage to a protected computer.[1] On May 24, 2021, a federal judge in Reno sentenced him to 10 months in custody, which he had already served, and he was to be deported. He was also ordered to pay about $14,825 in restitution to Tesla for investigation costs.[1][2] Co-conspirators were identified in court papers only by nicknames and were not charged by name.[2][3]

The missing control

The missing control: a fast, trusted channel for insiders to report bribes and recruitment attempts. Here it was not missing, and that is the point. Tesla's employee knew who to tell, told them quickly, and the company escalated straight to the FBI.[1][2]

Most companies never test this. If an employee is approached with an offer, do they know where to go, do they trust they will not be blamed, and does the company know to call law enforcement rather than quietly fire someone? Without that channel, a crew only needs one person in the building to stay silent. With it, the approach becomes evidence.

What to do in your business

Watch the case
The $1M bribe to hack Tesla that an employee reportedDrops 2026-11-05
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More insider risk cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. The Record: Russian who tried to hack Tesla last summer pleads guilty
  2. Al Jazeera (AP): US to deport Russian man who tried to hack Tesla
  3. AP via Audacy: Tesla targeted in failed ransomware extortion scheme
  4. TechSpot: Tesla's Nevada Gigafactory targeted in Russian hacking plot
  5. Dark Reading: Russian man pleads guilty in thwarted Tesla hack