CIO Brief: Cryptojacking — The Breach That Shows Up on Your Cloud Bill
Retrospective: this article looks back at events from February 2018, written in 2026 with the benefit of hindsight.
The short version: In 2018, attackers broke into Tesla's cloud through an unprotected management console and used its computers to mine cryptocurrency. Tesla caught it quickly — but cryptojacking is often the first sign of a much larger exposure.
Why a "harmless" crypto miner matters
Crypto mining seems like the least damaging outcome of a breach: no stolen data, just a higher cloud bill. But the attacker had the access needed to do far worse. In Tesla's case, the same environment could reach sensitive storage.
The business impact
- Unexpected cloud bills, sometimes tens of thousands of dollars in days.
- A signal of deeper compromise — the same access could steal data or deploy ransomware.
- Reputational risk if the story becomes public.
Questions to ask your team
- Would we notice a sudden spike in cloud spending within a day?
- Are any administrative consoles or dashboards reachable from the internet without login?
- Do we restrict which cloud regions can be used at all?
- If we found crypto mining tomorrow, would we investigate how they got in, or just shut it down?
What good looks like
Budget and anomaly alerts on cloud spending, no management interfaces exposed to the internet, restrictions on unused regions, and a rule that any cryptojacking is investigated as a full security incident.
The decision
Turn on cost anomaly alerts this week. It takes minutes and often catches compromises earlier than security tools do.
- Tesla's Kubernetes Console Cryptojacked (Feb 2018): Exposed Dashboards, Exposed AWS Keys Incident Teardowns
- How to Secure Kubernetes Dashboards and Cluster Credentials on AWS How-To & Hardening
- Detecting Cryptojacking in Cloud: CloudTrail, GuardDuty and Athena Queries Detection & Response