To OP robinpie:
I understand that Tesla is treating your NTP server, a volunteer server and part of the greater volunteer pool of NTP servers, as their own infrastructure.
However, I can't tell from the article if the scans originate with:
A.) IT staff at Tesla that are scanning exposed services on what they perceive, or claim wrongly, as their own network for vulnerabilities.
B.) Somehow a rogue operator (read botnet)
C.) A rogue operator who is using the cars themselves to run exploit scans?
C would be the most alarming and concerning.