Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Expert comment: Former Tesla Employee Accused Of IP Theft, Uploaded Autopilot Code To iCloud
News & Analysis

Expert comment: Former Tesla Employee Accused Of IP Theft, Uploaded Autopilot Code To iCloud

ISBuzz TeamBy ISBuzz TeamJuly 12, 2019Updated:July 4, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Earlier this year, Tesla filed suit against former engineering employee, Guangzhi Cao, accusing him of stealing trade secrets (Tesla’s Autopilot source code).  In a court filing from Monday (July 8), Cao admitted to uploading .zip files containing the Autopilot source code to his personal iCloud account.  

Additionally, Cao is accused of bringing the code to Chinese competitor, Xiaopeng Motors (AKA Xmotors or XPeng), which is backed by industry-giant Alibaba. This is a prime example of the havoc insider threats can wreak on companies. 

Tesla former engineer Guangzhi Cao, accused of stealing AP source code, now works at Xpeng as head of perception. Coincidence? https://t.co/IasSlPRSEH

— Ray (@ray4tesla) July 11, 2019

Experts Comments: 

Jeff Nathan, Principal Researcher at Exabeam:

“Insiders with access to privileged information represent a greater risk to a company’s security. In this particular case, a former Tesla employee admitted to uploading confidential Autopilot source code to a personal iCloud account before leaving to work for a competitor.   

Tesla is not alone. Managing cloud applications and services is an ongoing and common challenge for enterprises. With more enterprises deploying critical resources within their cloud services, the threat landscape can extend to a larger attack surface that could be outside of security’s traditional span of control.   

In many organisations, cloud credentials might be outside the scope of internal network security policies and controls. For example, it’s not unusual for software developers to provision their own cloud services and define their own credentials. They then proceed to create applications within their self-provisioned cloud services. Should a developer leave the company, the standard off-boarding policies might not include removing their cloud-based resource access. The former employee can continue to access the cloud resources, and the company would be completely unaware of the security risk.   

However, advancements in cloud-based security management solutions have helped close this gap. Some modern SIEM solutions now use machine learning capabilities to track individual users’ behaviour across the entire company network and identify anomalous events. Now, security teams can easily and immediately discover who is using cloud resources to upload sensitive corporate information or illicitly access cloud applications and revoke their credentials–improving cloud security for the modern enterprise.”  

Naaman Hart, Cloud Services Security Architect at Digital Guardian: 

“This is indeed an ideal case to be solved by Data Loss Prevention (DLP) products.  There was no need for this employee to be using their own iCloud for data storage even if the original intent was non-malicious.  This should’ve been detected and blocked, either by identifying the important files and selectively blocking them or by a blanket ban on iCloud.  Simply allowing this to happen has exposed Tesla to potential data loss.  Closing the doors to private cloud hosted services is a proactive approach to preventing data loss.   

“Yes, it’s great that Tesla can get information from Apple to help their case, but the data is gone and now it’s in the wild for Tesla’s competitors to use.  Implementing DLP visibility solutions are also a great reactive measure to retrospectively identify and confirm a specific employee’s malicious intent.  This information can enhance any court proceedings and get a positive outcome for the victim.   

“Prevention is better than reaction however, so focusing on forcing employees to use approved and secure channels is the preferred approach.  You don’t have to make yourself ineffective, just provide a sufficient set of tools that you can control, rather than allowing people to use services completely outside of your control.” 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}