Abusing the Internet of Things

(Rick Simeone) #1

FIGURE 7-30. Twitter account of Elon Musk hacked by vandals


In response, Tesla issued the following press release:

This case is under investigation, here’s what we know: Posing as a Tesla employee, somebody called
AT&T customer support and had them forward calls to an illegitimate phone number. The impos-
tor then contacted the domain registrar company that hosts teslamotors.com, Network Solutions.
Using the forwarded number, the imposter added a bogus email address to the Tesla domain
admin account. The impostor then reset the password of the domain admin account, routed most
of the website traffic to a spoof website and temporarily gained access to Tesla’s and Elon’s Twitter
accounts.
Some customers may have noticed temporary changes to http://www.teslamotors.com on their browsers or
experienced difficulty when using our mobile app to access Model S. Both were due to teslamo-
tors.com being re-routed.
Our corporate network, cars and customer database remained secure throughout the incident. We
have restored everything back to normal. We are working with AT&T, Network Solutions, and fed-
eral authorities to further investigate and take all necessary actions to make sure this never hap-
pens again.

224 CHAPTER 7: SECURE PROTOTYPING—LITTLEBITS AND CLOUDBIT
Free download pdf