Desk live·
ForensicPost
Breaches/Insider/File 23-0818

Tesla Says Two Former Employees Leaked Personal Data on 75,735 People to a Newspaper

No intrusion, no ransom and no criminal market. Tesla learned of the exposure when journalists contacted it, and the file it filed with a state regulator describes the one threat model that most security programmes are least equipped to see.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTesla
ActorInsider — former employees
S. Rosler10 min readConfidence: high2 sources reviewed

Tesla disclosed to Maine regulators on 18 August 2023 that personal data belonging to 75,735 current and former employees had been exposed, and attributed the exposure to two former employees who sent confidential information to a German newspaper.

The company reported learning of the exposure on 10 May 2023, when journalists contacted it to say they had obtained confidential Tesla information. The data reportedly included names, addresses, phone numbers, employment records and social security numbers.

The Detection Came From Outside, Again

Tesla did not identify this through monitoring. It learned about it because a newspaper asked for comment, and the investigation followed the enquiry.

The corpus records the same pattern at 23-1020, where affected customers found the Okta breach, and at 23-0918, where an external firm found an exposed storage token. Where the finder is outside the organisation, the number of similar events nobody happened to ask about is unknowable.

Authorised Access, Unauthorised Purpose

Every technical control in this database is built to answer "should this account be able to reach this data". Here the answer was yes. What changed was what the people behind the accounts decided to do with it.

The corpus files the adjacent shape at 26-0208, where a support contractor improperly accessed customer records, and argues at 26-0719 that most insider incidents are not sabotage. This one is the harder version: it was deliberate, and the recipients were journalists.

The Desk Does Not Take A Position On The Disclosure

Reporting described the leaked material as including customer complaints about driver assistance features, which is plainly matter of public interest. This file records neither approval nor condemnation of the leak.

What it records is narrower and is the reason the file exists: 75,735 employees had their identity data exposed, and none of them chose to be part of anyone’s disclosure decision.

How we reported this

Built on contemporaneous reporting of Tesla’s breach notification to the Maine Attorney General. The 75,735 figure, the 10 May 2023 discovery, the attribution to two former employees and the data categories are as stated in that notification and reported. Characterisations of the wider leaked material come from reporting of the newspaper’s own account and are not findings of this desk. No individual is named: the corpus names individuals only after conviction, and this desk records that Tesla stated it had taken legal action without treating any allegation as established. Graded high on the notification. Corrections: corrections@forensicpost.com.

Sources
  1. Tesla says data breach impacting 75,000 employees was an insider jobTechCrunch
  2. Tesla Discloses Data Breach Related to Whistleblower LeakSecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary