If you needed a wake-up call about the importance of trade secret protection, 2026 has delivered two cases highlighting the importance of trade secret protection. Both cases involve Google.
In January, a federal jury in California convicted former Google engineer Linwei Ding on seven counts of economic espionage and seven counts of trade secret theft for stealing over 2,000 pages of confidential AI technology and funneling it to companies in China. He faces up to 15 years in prison on each espionage count. (DOJ Press Release; CNBC)
Then in February, federal prosecutors in San Jose indicted three more Silicon Valley engineers on 14 felony counts for allegedly stealing hundreds of confidential files related to Google’s Pixel Tensor processor and routing that data to Iran. (CNBC; Courthouse News)
These cases involve two different countries, but they illustrate a broader reality: trade secret theft is a serious and fast-growing threat facing American businesses of all sizes, not just technology giants.
According to the 2017 Report from the Commission on the Theft of American Intellectual Property, trade secret theft costs the U.S. economy between $225 billion and $600 billion annually (IP Commission Report, 2017 Update). While the headlines understandably focus on nation-state espionage targeting companies like Google, trade secret misappropriation is pervasive across businesses of every size and in virtually every industry.
The international espionage cases naturally attract attention, but the more common scenario we encounter in our practice involves a departing employee or contractor who copies customer lists, pricing data, proprietary processes, or technical specifications before leaving to join a competitor or launch their own venture. The tools may have evolved (cloud storage, personal devices, encrypted messaging apps), but the underlying risk is as old as business itself.
The Ding case is notable not just for the severity of the charges, but for how the theft occurred. Over almost a year timespan, Ding uploaded thousands of pages of confidential information from Google’s internal systems to his personal Google Cloud account, while still employed at the company. However, unbeknownst to Google, he was simultaneously in discussions to become the CTO of a Chinese technology startup and was in the process of founding his own AI company in China.
Google ultimately detected the theft through routine internal security monitoring and referred the matter to law enforcement.
In the Ghandali case, prosecutors allege that the defendants leveraged their positions at Google and at another major semiconductor company to access confidential files related to processor security and cryptography. According to the indictment, the defendants routed those files through a third-party communications platform to channels bearing each of their first names, then copied the material to personal devices, to each other’s work devices, and ultimately transmitted it to Iran.
Both cases share a common and critically important thread: the alleged theft was carried out by trusted insiders who had legitimate access to the information as part of their regular job responsibilities. This is not a case of an outsider breaching a firewall, but it is a reminder that trade secret risk often originates from within an organization.
Trade secrets are protected under both federal and state law. At the federal level, the Defend Trade Secrets Act (DTSA), enacted in 2016, provides trade secret owners with a civil cause of action in federal court for misappropriation. Oklahoma, like a majority of states, has also adopted a version of the Uniform Trade Secrets Act, which provides complementary state-law protections.
On the criminal side, cases involving economic espionage (theft for the benefit of a foreign government) carry penalties of up to 15 years in prison and fines up to $5 million for individuals.
But many business owners miss one critical issue: you can only protect what qualifies as a trade secret. Under the DTSA, a trade secret must derive independent economic value from not being generally known, and the owner must take “reasonable measures” to keep it secret. The “reasonable measures” requirement is where many businesses fall short, and it is precisely where courts focus much of their analysis when trade secret claims are litigated.
Whether you operate a technology company, a healthcare practice, an energy firm, or a local restaurant with a proprietary recipe, the following steps represent a reasonable baseline for protecting your confidential information.
- Identify what you are protecting. Many businesses have never formally catalogued their trade secrets, which creates a significant vulnerability. Take the time to identify and document your most valuable confidential information, such as customer lists, pricing strategies, algorithms, manufacturing processes, vendor relationships, and business plans are common examples. Establishing a clear inventory is the foundation of any defensible trade secret program.
- Restrict access on a need-to-know basis. Not every employee needs access to every piece of confidential information. Use role-based access controls, limit file permissions, and segment sensitive data so that any single employee’s access is limited to what they need for their job.
- Use written agreements. Every employee, contractor, and business partner with access to confidential information should sign a nondisclosure agreement (NDA) and, where appropriate, a non-compete or non-solicitation agreement. These agreements should clearly define what constitutes confidential information and outline the consequences of unauthorized disclosure.
- Monitor and audit. As the Ding case demonstrates, Google detected the theft through routine internal security monitoring, not a sophisticated forensic investigation after the fact. Every business should have systems in place to detect unusual data access patterns, including large file downloads, access to files outside an employee’s normal scope, and transfers to personal devices or cloud accounts. Effective monitoring is scalable and does not require enterprise-level resources to implement.
- Conduct exit interviews and offboarding procedures. When an employee leaves, especially one with access to sensitive information, have a formal process in place. Remind them of their confidentiality obligations, collect all company devices and credentials, and revoke system access immediately. Consider requiring departing employees to certify in writing that they have returned all confidential materials.
- Act quickly when you suspect theft. Courts evaluate whether a trade secret owner acted promptly to address suspected misappropriation, and delay can significantly undermine your legal position. If you suspect that a current or former employee has taken confidential information, consult with an intellectual property attorney promptly to evaluate your options, which may include seeking emergency injunctive relief such as a temporary restraining order.
These back-to-back Google cases demonstrate that even the most sophisticated companies in the world remain vulnerable to insider theft. For smaller businesses that lack comparable security infrastructure, the exposure may be even greater.
The encouraging takeaway, however, is that effective trade secret protection does not require an enterprise-level budget. What it does require is intentional, consistent effort: identifying your trade secrets, restricting access appropriately, putting agreements in place, monitoring for unusual activity, and maintaining a clear protocol for employee departures.
If you have questions about how to protect your business’s trade secrets or how to respond to suspected misappropriation, please contact us at Silverline Legal at [email protected].

