Tesla Investigates Claims Of Crypto-currency Hack

Tesla car in spaceImage copyright AFP

Tesla has confirmed that its cloud computing platform has been compromised by hackers.

RedLock, the company that alerted it to the breach, believes the attackers may have done this to mine crypto-currency - an attack known as crypto-jacking.

Tesla said it had addressed the vulnerability "within hours" and that no customer data had been stolen.

A spokeswoman added that the effects of the hack seemed to be limited to internally used engineering test cars.

"Our initial investigation found no indication that customer privacy or vehicle safety or security was compromised in any way," she said.

RedLock said that Tesla's log-in credentials were stored on a system that was not password-protected.

Crypto-currency mining is the process for creating new digital coins by solving complex mathematical problems. It uses large amounts of computer processing power and therefore racks up large electricity bills.

Hackers can save money by installing software on other people's computers to mine coins without their knowledge or consent. This is known as crypto-jacking.

Crypto-jacking is becoming more widespread, especially as the value of digital currencies such as Bitcoin continues to rise. Hackers have compromised services offered by Starbucks, YouTube and the UK's Information Commissioner's Office.

According to RedLock, the hackers discovered log-in details to Tesla's Amazon Web Services environment on a Kubernetes console - a system originally designed by Google to manage applications. The console was reportedly not password-protected.

The value of the crypto-currency that the hackers mined using stolen power is unknown.

According to a report in Fortune, Tesla paid RedLock $3,133.70 (£2,243.73) for uncovering the security flaw.

The researchers said that the hackers used "sophisticated evasion measures" to avoid detection, such as keeping their use of computing power low and masking their Internet Protocol (IP) address with CloudFlare's content delivery network service.

In a report published last year, RedLock said that 53% of organisations using cloud storage services such as Amazon had accidentally exposed these to the public, with "hundreds" leaking credentials through services such as Kubernetes.

The firm uncovered a similar attack on British insurance company Aviva in October 2017.

RECENT NEWS

From Chip War To Cloud War: The Next Frontier In Global Tech Competition

The global chip war, characterized by intense competition among nations and corporations for supremacy in semiconductor ... Read more

The High Stakes Of Tech Regulation: Security Risks And Market Dynamics

The influence of tech giants in the global economy continues to grow, raising crucial questions about how to balance sec... Read more

The Tyranny Of Instagram Interiors: Why It's Time To Break Free From Algorithm-Driven Aesthetics

Instagram has become a dominant force in shaping interior design trends, offering a seemingly endless stream of inspirat... Read more

The Data Crunch In AI: Strategies For Sustainability

Exploring solutions to the imminent exhaustion of internet data for AI training.As the artificial intelligence (AI) indu... Read more

Google Abandons Four-Year Effort To Remove Cookies From Chrome Browser

After four years of dedicated effort, Google has decided to abandon its plan to remove third-party cookies from its Chro... Read more

LinkedIn Embraces AI And Gamification To Drive User Engagement And Revenue

In an effort to tackle slowing revenue growth and enhance user engagement, LinkedIn is turning to artificial intelligenc... Read more