Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityPhysicalPhysical Security

The Inside Job: Corporate Espionage Never Went Away

By Greg Newman
Open filing cabinet
Maksym Kaharlytskyi via Unsplash
August 14, 2026

When most people hear “corporate espionage,” they can’t help but picture something out of a Cold War thriller. Trench coats. Dead drops. A microfilm camera hidden in a briefcase.

The fact is: Corporate espionage never stopped, but it did stop looking like the movies. 

The playbook for this kind of threat has changed in the modern era, but it’s important to note the two different approaches. The first is private competitors, which are companies that want to steal your intellectual property (IP), sabotage your product roadmap, recruit your key talent, or find out where the bodies are buried so they can slow you down. The second is nation-states: friends, frenemies, and adversaries doing the same work on behalf of their state-owned industries or the commercial interests of their country.

But who they’re targeting is different. They want to get to whoever they can have the most impact on. The more your business matters to your industry, your country, or the world, the more target-rich you become. This might be AI companies rewriting how the world works, defense contractors and manufacturers, or IP-rich industries like movie studios. 

The size of the company matters less than you’d think, too. A multibillion-dollar pharma company churning out generics is far less interesting to an adversary than the smaller company that just developed a new GLP-1. And they might be a tougher target, too. The uncomfortable truth is that if you’ve built something the world wants, someone wants to take it. 

And all of this has happened before: 

  • The theft of Kodak film secrets by Harold Worden in the 1990s
  • The IBM/Hitachi case in the 1980s
  • A developer convicted in Germany for stealing trade secrets from Valeo, allegedly to benefit NVIDIA’s parking-assistance work
  • A Chinese national charged with taking more than 500 confidential AI files from Google 
  • A former Coca-Cola employee convicted over stolen chemical formulas sold to rivals
  • Tesla suing Rivian over poached employees and proprietary battery technology

These cases fall under the same corporate espionage umbrella, putting the emphasis on security teams to play a pivotal role in thwarting these threats. 

The Old Tricks Are the New Tricks

Here’s what security leaders should know: the fundamentals of espionage haven’t evolved much. They include things like human intelligence and recruitment campaigns, tech-based interception (some of us might know this as signals intelligence) like malicious code that’s slipped into systems, or a hack that allows sensitive work walking out the door. There are other categories of tricks, but when we think about corporate espionage, these are the two that come up most frequently. 

What has evolved is the delivery of the threats.

AI now lets a bad actor believably transform their appearance, language, and mannerisms, allowing them to tailor exactly how they approach a target. The LinkedIn message from a “recruiter” asking oddly specific questions about your work is the new stranger at the conference. Sophisticated phishing campaigns have replaced scattering USB sticks in the parking lot and hoping someone helpfully plugs one in. And where spies once smuggled in a camera to photograph documents, cloud infrastructure has made exfiltrating data extremely easy (although it’s also made monitoring and catching it easier, if anyone’s actually watching).

Then there’s the threat that would’ve sounded absurd five years ago: companies unknowingly hiring North Korean IT workers, such as remote employees who interview well, work competently, and happen to be sitting in Pyongyang. This example isn’t hypothetical. It’s federal case law. 

The insider threat isn't just the disgruntled employee anymore. Sometimes the insider was never really your employee at all.

How Businesses Actually Protect Themselves

Here’s where a lot of organizations get this wrong: they treat espionage risk as everyone’s job, which in practice means it’s no one’s job. This might look like phishing reports that go to an IT helpdesk, data loss prevention (DLP) alerts that pile up unread, or travel security protocols in a PDF nobody opens.

Without question, the best investment a business can make is a function-specific threat team. This looks different at every company, but the spirit is the same: threat awareness, training, detection, and mitigation need to be somebody’s primary function, not their second or third hat.

In actuality, this means a few things happen:

  • Travelers get real briefings. Employees heading abroad learn what they might actually encounter, including things like elicitation attempts, device tampering, or the too-friendly contact at a conference, not a generic checklist to skim on the plane.
  • Alerts route to an owner. Phishing attempts and DLP alerts go to someone whose actual job is to connect the dots, and not a ticket queue where they go unread or unaddressed.
  • Hiring gets a second look. Remote candidates are verified as real people in real places, with a team that conducts identity checks, live interviews, and monitors hardware shipping addresses that make sense so the new hire isn’t logging in from somewhere they shouldn’t be.
  • Access follows the employee lifecycle. When people change roles or leave, their access to sensitive systems and spaces changes with them. Departing employees are the single most common exfiltration point, and offboarding is where it gets caught (or doesn’t). Regular reviews and the Principle of Least Privilege can go a long way.
  • The program gets rehearsed. Mature organizations run tabletop exercises against realistic scenarios, so the first time the team works an insider case isn’t during a real one.
  • A full insider threat program ties it together. The most advanced companies proactively watch for indicators of intrusion, elevated risk, and behavior that doesn’t add up, across both digital and physical environments.

That last part matters. Espionage doesn’t respect the org chart split between cyber and physical security. The person uploading files to the cloud also badges into the building. The signals are present in the form of badge data, access anomalies, unusual hours, and alerts that individually look like noise. The organizations that catch insiders are the ones that bring those signals together and put a dedicated team in front of them.

The fix here to catch these threats isn’t another dashboard. It’s a program: ownership, training, and detection working as a single function.

Corporate espionage is older than the corporation. It’s not going away, and the tools aimed at your IP are only getting better and more sophisticated. The question isn’t whether your business is a target. If your work matters, it is. The question is whether protecting it is somebody’s actual job, or just something everyone assumes someone else is handling.

KEYWORDS: corporate espionage IP IP infringement IP protection

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Greg newman headshot

Greg Newman is the Chief of Staff for HiveWatch. Image courtesy of Newman

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Photograph of apartment complex patios

Enhancing Residential Building Security

2026 Women in Security

Security’s 2026 Women in Security

Northland Controls sponsored content

The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Trust

Building Public Trust in AI‑Enabled Security

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • corporate-freepik1170x658v503646.jpg

    The new face of corporate espionage and what can be done about it

    See More
  • Addressing Corporate Espionage in the 21st Century

    See More
  • Office with workers

    Deepfake Scam or Inside Job? Rethinking the BEC Threat

    See More

Related Products

See More Products
  • Physical Security and Safety: A Field Guide for the Practitioner

  • The Complete Guide to Physical Security

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

See More Products

Events

View AllSubmit An Event
  • November 13, 2025

    Inside the 2025 Security Benchmark Report

    ON DEMAND: The 2025 Security Benchmark Report unveils the top trends CSOs and enterprise security executives are facing in today’s current climate and how each of these trends could potentially impact the enterprise’s global reputation with the public, governments, and business partners. 
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing