The approach began, like a great deal of 2020, on WhatsApp. On 16 July a Russian-speaking employee of Tesla's Gigafactory in Sparks, Nevada heard from Egor Kriuchkov, a 27-year-old Russian he had met years earlier through mutual acquaintances. Kriuchkov was visiting the United States on a tourist visa and wanted to catch up. By early August the two were on an outing to Lake Tahoe with friends, where Kriuchkov covered everyone's bills and stayed carefully out of the group photographs. Afterwards, back in the Reno area, he set out the reunion's actual agenda: he worked with a group that extorted companies for money, and that group wanted to pay the employee to put malware inside Tesla's network.

The "special project", as Kriuchkov called it, was ransomware with the intrusion step made human. The employee would carry the malicious code in — a USB stick or an emailed attachment would do — and while a distributed denial-of-service attack kept Tesla's security team occupied, the group would quietly copy corporate data, then demand payment against the threat of publishing it. The offer started at $500,000 and rose to $1 million, payable in cash or bitcoin, and it came with tradecraft attached: a burner phone Kriuchkov supplied, the Tor browser, patience about the money. The group, Kriuchkov said, had run such operations before. What he did not know was that the employee had already reported the approach to Tesla, and Tesla had already called the FBI.

What followed reads like a procedural because it became one. The later meetings, in bars and parked cars around Reno, were monitored and recorded by the FBI while the employee — kept in place, and playing along — let Kriuchkov talk through timings, payment and reassurances. In mid-August Kriuchkov said the project would be delayed, then that he was leaving. On 22 August agents arrested him in Los Angeles as he prepared to fly out of the country, having driven through the night from Reno. The criminal complaint, unsealed days later, charged a single count of conspiracy to intentionally cause damage to a protected computer, and named the target only as "Victim Company A", a company in Nevada.

Elon Musk confirmed within the week what the filing would not — the company was Tesla, and, in his words, this had been "a serious attack". The endings are all known now. Kriuchkov pleaded guilty in March 2021 to the conspiracy charge and was sentenced that May to ten months — in effect the time he had already served — plus restitution of about $14,825 for the company time his plot consumed, with deportation to Russia to follow. The government's filings never named the employee. August 2020 put a face on a step ransomware normally keeps abstract — the recruitment of an insider — and left the industry a lesson from a bar outside Reno: the whole criminal model can fail because one person says no.

Also that month · Four sessions dark

A stock exchange, priced in bitcoin

New Zealand's stock exchange halted trading on the afternoon of 25 August 2020 and could not stay reliably open for the rest of the week. The cause was a volumetric distributed denial-of-service attack from offshore, aimed through NZX's network provider at its public websites — including the platform that publishes market announcements. With announcements unreachable, the exchange could not meet its continuous-disclosure obligations, so the cash markets stopped: four consecutive sessions halted or delayed. The extortion notes behind the flood demanded bitcoin and were signed with borrowed names — "Fancy Bear", "Armada Collective" — part of a global campaign researchers at Akamai had tracked since mid-August, whose targets also included MoneyGram, Worldpay, PayPal and India's YES Bank. The senders were never publicly identified. On 28 August the government activated its national security system and directed the GCSB, its signals-intelligence agency, to assist; by Monday 31 August, with its public sites behind overseas DDoS protection, NZX absorbed further attacks and kept trading. A Financial Markets Authority review published in early 2021 was blunt about the deeper cause: thin technology resourcing and crisis planning at the exchange itself.

Also that month · Who answers for a breach

The security chief becomes the defendant

On 20 August 2020 federal prosecutors in San Francisco charged Joseph Sullivan, Uber's chief security officer from 2015 to 2017, with obstruction of justice and misprision of a felony — the first criminal case of its kind against a corporate security executive over the handling of a breach. The complaint alleged that when attackers took data on roughly 57 million Uber riders and drivers in November 2016, including about 600,000 driver's licence numbers, Sullivan arranged a $100,000 bitcoin payment to the hackers through the company's bug-bounty programme and had them sign non-disclosure agreements that falsely stated no data had been taken. The Federal Trade Commission was investigating Uber's data security at the time; the hackers had made contact ten days after Sullivan gave sworn testimony in that very inquiry. Uber disclosed the breach a year later, under new management. By 2026 the ending is settled: convicted by a jury on 5 October 2022, Sullivan was sentenced in May 2023 to three years' probation, 200 hours of community service and a $50,000 fine. The charge sheet, though, belongs to August 2020 — the month concealment acquired a defendant.

India desk · August 2020

A claimed breach, a flat denial, and a health ID for everyone

On 30 August 2020 the US threat-intelligence firm Cyble published a claim that a cybercrime group calling itself "John Wick" had planted a backdoor on Paytm Mall's website and application, gained what it described as unrestricted access to the company's databases, and demanded ten ether — then about US$4,000. The claims reached Cyble as forwarded messages, including the group's own boast that an insider had helped; Cyble itself labelled the material unverified. Paytm Mall's denial was immediate and total: the reports were "absolutely false", all user and company data remained secure, and, the company added pointedly, Cyble had never contacted it before publishing. Nothing has settled the question since — a dataset attributed to the incident surfaced through a breach-notification service in July 2022, and within days was reclassified as fabricated. This archive records it as exactly that: a claim, a denial, no proof.

The month's more consequential Indian story involved no attacker at all. In his Independence Day address from the Red Fort on 15 August, Prime Minister Narendra Modi announced the National Digital Health Mission: a health ID for every Indian, holding tests, diagnoses and prescriptions in a single digital account, piloted from that day in six union territories. The privacy questions were immediate, because the ground was bare — India had no data protection statute, and the bill meant to provide one sat with a parliamentary committee, later to be withdrawn entirely. A draft health-data management policy followed within weeks for public comment. In hindsight the trajectory is clear: the mission became the Ayushman Bharat Digital Mission and went national in September 2021, while the law — the DPDP Act — arrived only in August 2023, three years after the IDs.

AI Tech desk · August 2020

The Summer the Algorithm Lost

Britain supplied the decade's clearest lesson in algorithmic accountability. With exams cancelled by the pandemic, the regulator Ofqual computed A-level results from schools' past performance, and on 13 August 2020 its standardisation model downgraded nearly two in five teacher-assessed grades. Students protested outside the Department for Education — the chant aimed at the algorithm became the fortnight's refrain — and on 17 August the government conceded and restored teachers' judgements; Ofqual's chief regulator stepped down before the month ended. Arguments about automated decision-making in public life have cited that week ever since. The machines advanced more quietly elsewhere: on 20 August an AI agent built by Heron Systems beat an experienced US Air Force F-16 pilot five rounds to nil in the simulated finale of DARPA's AlphaDogfight Trials, an experiment that matured into AI flying real fighter tests within four years. And on 28 August Elon Musk introduced Gertrude, a pig carrying Neuralink's coin-sized brain implant for two months — the device line that reached its first human volunteer in January 2024.

Digital Guard desk · August 2020

The Quiet Vaccine Against Emotet

The defence side's story of the month was disclosed on 14 August 2020, only once it was over. James Quinn, a researcher at the Ohio firm Binary Defense, had found a buffer overflow in the installation code of Emotet, the botnet that served as organised crime's favourite delivery service, and turned the bug into EmoCrash — a small registry entry that crashed the malware before it could take hold. From 12 February the script travelled quietly to national response teams and corporate defenders under strict instructions never to publish it, and for six months, from 6 February to 6 August, machines carrying it were in effect vaccinated. Emotet's operators closed the hole with a loader update weeks after returning from a months-long hiatus, and their August spam soon outweighed every other threat's — the same month DEF CON convened online as Safe Mode. The coda came later: police coordinated through Europol seized Emotet's infrastructure in January 2021 and uninstalled it from infected machines that April, but the six-month vaccine remains the classic proof that malware has bugs too.

⏳ Time capsule — August 2020

  • SpaceX's Crew Dragon splashed down in the Gulf of Mexico on 2 August with astronauts Doug Hurley and Bob Behnken aboard — the first American crewed water landing in 45 years.
  • On 4 August, roughly 2,750 tonnes of ammonium nitrate stored at the Port of Beirut exploded, killing more than 200 people and devastating large parts of the city.
  • Russia registered Sputnik V on 11 August — the world's first registered COVID-19 vaccine, approved before large-scale trials had finished.
  • Shinzo Abe, Japan's longest-serving prime minister, announced his resignation on 28 August, citing ill health.
Where it stands today — 2026

The refusals that held

August 2020's stories aged along clean lines. The Tesla sting dragged insider recruitment into the open, and within a year ransomware crews were advertising openly for employees willing to sell access — the quiet WhatsApp approach industrialised, a pipeline later editions of this archive track through the LockBit era. The extortionists who darkened NZX kept their business model too: ransom DDoS under borrowed names recurs through these pages, and Wellington's four halted sessions remain the standard citation for what unpreparedness costs. Sullivan's charge sheet ran the longest thread — through Uber's own admission of the cover-up in our July 2022 edition, his conviction that October, probation in 2023, and an era in which security executives read indictments as governance documents.

The India desk's pairing set a template this archive returns to often: an unverifiable breach claim met with a flat denial, and a state digitising faster than its safeguards. The health IDs announced from the Red Fort preceded their governing statute by three years — a gap these pages watch narrow through the DPDP Act and its slow enforcement debates. And the Gigafactory employee, unnamed in the case file, stands where this edition leaves him: proof that between a criminal group and everything it wants, there can be one person who is not for sale. The Vault continues backwards from here.