If you can grab credentials from there you can do quite some things already.
See https://www.teslaapi.io/authentication/oauth (and this is in the case you don't trick an employee).
But I agree, that normally at some point they would catch it.