Skip to content

Case Studies /

Global Manufacturing / IndustrialsDigital Forensics

Trade-Secret Theft Uncovered at a Fortune 100 Industrial Manufacturer

Forensic attribution of a multi-year insider exfiltration scheme preserved more than $400 million in IP value and produced evidence central to a successful federal criminal referral.

June 2, 2026 · Prepared by Law & Forensics

Emergency TRO halted use of the exfiltrated designs

14-month exfiltration timeline reconstructed across 6 enterprise platforms

3.2 TB

of evidence processed and reviewed in under 21 days

Settlement included confirmed destruction of all copies

Anonymized engagement. Client identity and matter details are withheld to protect confidentiality. Figures are actual outcomes from the engagement described and have not been independently audited.

A Fortune 100 global industrial manufacturer suspected that a senior R&D engineer, weeks before his resignation, had systematically copied proprietary process-control algorithms and next-generation materials specifications that underpinned the company's competitive advantage in precision manufacturing. Internal IT controls had flagged anomalous data-transfer activity, but the company lacked the forensic evidence needed to pursue emergency relief, assess the scope of disclosure, or make a criminal referral. Outside litigation counsel engaged Law & Forensics to conduct an emergency forensic investigation under privilege.

The Situation

Trade-secret matters in industrial manufacturing present a particular urgency: once proprietary process specifications or design data reach a competitor's engineering team, the harm compounds daily. This manufacturer faced a scenario in which the suspected recipient was a well-capitalized foreign competitor in a market the company was preparing to enter with the next-generation technology. Any delay in securing evidence or obtaining injunctive relief risked permanent competitive harm.

The company also needed to understand the full scope of disclosure — not merely what the engineer had copied, but what had left the enterprise perimeter, where it had gone, and whether any third parties had received it — before it could accurately advise its board or take a position before regulators.

Our Approach

Law & Forensics organized the engagement around three simultaneous workstreams designed to produce both an emergency evidentiary record and a comprehensive investigative report.

Endpoint and Network Forensics. The team forensically imaged the engineer's assigned workstations, a company-issued laptop, and connected network shares. Artifact analysis — including USB connection records, browser download history, cloud-sync application logs, and file system metadata — reconstructed a precise timeline of data access and movement. Evidence confirmed mass-copy events targeting the specific file repositories housing the at-issue IP.

Cloud and External Repository Tracing. Law & Forensics correlated enterprise egress logs with external destination indicators, identifying transfers to a personal cloud storage account and, through legal process, connections to infrastructure associated with the foreign competitor. This external-destination evidence was critical to satisfying the "misappropriation" element under the Defend Trade Secrets Act.

IP Valuation and Scope Assessment. In parallel, the firm's trade-secret valuation specialists worked with the client's IP counsel to quantify the economic value of the exfiltrated materials and identify which additional repositories may have been accessed but not yet transferred — informing the scope of injunctive relief sought.

The Impact

The forensic record produced by Law & Forensics supported a federal complaint filed under the Defend Trade Secrets Act (18 U.S.C. § 1836(b)). The court granted a temporary restraining order within days of filing, halting any further use or distribution of the exfiltrated materials. The matter subsequently settled on terms that included the confirmed destruction of all copies, a substantial monetary payment, and a multi-year competitive covenant.

The engagement also enabled a criminal referral to federal law enforcement, which opened a parallel investigation. Law & Forensics' forensic work product was structured from the outset to be usable in both civil and criminal proceedings — a dual-track approach that materially improved the company's negotiating leverage.

Digital Forensics Services — Trade Secret and IP Investigations; Insider Threat and Employee Misconduct; Digital Evidence for Litigation

Digital Forensics experts who testify to this work

Full expert panel →
  • J-Michael Roberts, Senior Director, Law & Forensics

    J-Michael Roberts

    Senior Director

    Digital Forensics · Incident Response · Malware Reverse Engineering

  • Digital Forensics · Expert Witness Testimony · Incident Response

  • Roland Cloutier, Expert Consultant, Law & Forensics

    Roland Cloutier

    Expert Consultant

    Incident Response · Expert Witness Testimony

Our experts serve as court-appointed special masters, forensic neutrals, and arbitrators — 40 appointments are listed by matter and citation.

Facing a matter like this one?

Tell us what you need to prove, or check us for conflicts first — either takes a minute.