AWSCIO BriefingsRetrospectives

CIO Brief: Cryptojacking — The Breach That Shows Up on Your Cloud Bill

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2018, written in 2026 with the benefit of hindsight.

The short version: In 2018, attackers broke into Tesla's cloud through an unprotected management console and used its computers to mine cryptocurrency. Tesla caught it quickly — but cryptojacking is often the first sign of a much larger exposure.

Why a "harmless" crypto miner matters

Crypto mining seems like the least damaging outcome of a breach: no stolen data, just a higher cloud bill. But the attacker had the access needed to do far worse. In Tesla's case, the same environment could reach sensitive storage.

The business impact

  • Unexpected cloud bills, sometimes tens of thousands of dollars in days.
  • A signal of deeper compromise — the same access could steal data or deploy ransomware.
  • Reputational risk if the story becomes public.

Questions to ask your team

  • Would we notice a sudden spike in cloud spending within a day?
  • Are any administrative consoles or dashboards reachable from the internet without login?
  • Do we restrict which cloud regions can be used at all?
  • If we found crypto mining tomorrow, would we investigate how they got in, or just shut it down?

What good looks like

Budget and anomaly alerts on cloud spending, no management interfaces exposed to the internet, restrictions on unused regions, and a rule that any cryptojacking is investigated as a full security incident.

The decision

Turn on cost anomaly alerts this week. It takes minutes and often catches compromises earlier than security tools do.

tesla cryptojacking impactTesla cryptojacking2018

More on this story