VladTV’s new interview with former CIA officer Charles Finfrock revisits Tesla’s 2020 insider-ransomware plot, a case that shows why an employee’s decision to report a suspicious approach can matter more than another endpoint security control. Finfrock, who says he joined Tesla’s internal security intelligence organization in 2019 after work in private intelligence, describes the company’s efforts to protect proprietary technology and business data from insider theft. The interview’s central case is the attempted recruitment of a Tesla Nevada employee by Russian national Egor Igorevich Kriuchkov, who sought to have malware planted inside the company network.
This was not a newly disclosed attack. The U.S. Department of Justice charged Kriuchkov in August 2020, and Elon Musk publicly confirmed at the time that Tesla had been the intended target.

Two analysts discuss a cybersecurity threat beside servers, robotics, and ominous red warning graphics.The Insider Was the Intended Initial-Access Vector​

According to the Justice Department’s criminal complaint, Kriuchkov traveled to the United States and cultivated contact with a Tesla employee he had met previously. The alleged plan was for the employee to install malware supplied by the conspirators, enabling theft of company data and a subsequent extortion demand.
VladTV characterizes the offer as $500,000. The federal complaint described a more fluid negotiation: Kriuchkov said his group was paying him $500,000 for recruiting the employee, while discussing a substantial share for the insider; later, the employee—working with the FBI—pushed the demand to $1 million and requested an advance payment.
The target employee instead reported the approach to Tesla, which contacted the FBI. Recorded meetings and communications then helped investigators document the alleged conspiracy before malware reached Tesla’s environment.

The Case Was About Data Theft, Not Just Encryption​

The incident is often remembered as a ransomware plot, but the proposed operation fit the now-familiar double-extortion model. The Justice Department said the malware would be used to exfiltrate data, after which the company would be threatened with its disclosure.
That distinction matters for Windows administrators and security teams. Backups, recovery testing and ransomware containment remain essential, but they do not resolve the exposure created when proprietary source code, manufacturing data, credentials, engineering files or employee information can be stolen before encryption ever begins.
Finfrock’s account emphasizes the practical insider-threat routes security teams still contend with: corporate email, cloud-storage services and removable USB devices. Controls around those channels need to be paired with monitoring for unusual data access, role-based permissions, egress restrictions and a reporting culture that gives employees a safe path to escalate coercion or bribery attempts.

A Foiled Breach Still Produced a Modest Sentence​

Kriuchkov pleaded guilty in March 2021 to conspiracy to intentionally cause damage to a protected computer. He was sentenced in May 2021 to 10 months in prison—largely time served—plus about $14,825 in restitution, and was to be deported.
The result illustrates an uncomfortable reality in attempted cybercrime cases: stopping an attack before intrusion is the ideal operational outcome, but it can limit the measurable damage available at sentencing. Tesla avoided a potentially severe compromise precisely because its employee and security team acted before the malware was deployed.
For enterprise defenders, the lasting lesson is straightforward: an insider threat program cannot be only a technical program. It must account for recruitment, financial pressure, social engineering and employees who may become the first—and sometimes only—warning that an attacker is already at the door.

References​

  1. Primary source: VladTV
    Published: 2026-07-31T17:00:00+00:00
  2. Related coverage: securityweek.com
  3. Related coverage: bleepingcomputer.com
  4. Related coverage: techspot.com
  5. Related coverage: cbsnews.com
  6. Related coverage: vancouver.citynews.ca