Back to Blog

Trade Secret Misappropriation: Prevention and Remedies

it trade secret misappropriation — intellectual property law and protection

Trade secret misappropriation is a serious legal violation that can cause devastating harm to businesses and individuals. The theft or unauthorized disclosure of trade secrets can undermine years of investment in research and development, destroy competitive advantages, and cause incalculable business harm. Understanding what constitutes misappropriation, how to prevent it, and what remedies are available when it occurs is essential for any business that relies on confidential information. PerspireIP provides proactive protection advice and rapid-response enforcement services when trade secret misappropriation strikes. In technology businesses the problem has a particular shape, and IT trade secret misappropriation is now the fact pattern behind most of these cases.

IT Trade Secret Misappropriation: How Code and Data Actually Leave

The archetype of trade secret theft — a formula copied from a locked cabinet — describes almost none of the cases now filed. IT trade secret misappropriation is overwhelmingly a story about credentials, repositories and cloud storage, and about an employee who had entirely legitimate access right up until the week they resigned.

The recurring vectors are narrow enough to list:

  • Repository cloning in the notice period — a full clone of source history looks identical to normal engineering activity in most logs.
  • Personal cloud sync — a work folder mapped to a personal account, often set up years earlier for convenience.
  • Bulk export from a SaaS system — CRM, ticketing or analytics data exported through a feature the vendor provides and the employer never restricted.
  • Forwarding to personal email — still the most common and the most easily proved.
  • Credentials that outlive the role — API keys, service accounts and shared logins that no offboarding process ever revoked.
  • Third-party and vendor access — contractors whose entitlements were never scoped down after the engagement narrowed.

What unites them is that none involve breaking in. That has a direct legal consequence, discussed below, and a direct practical one: the controls that prevent IT trade secret misappropriation are access-lifecycle controls, not perimeter security.

What Is Trade Secret Misappropriation?

Under the Defend Trade Secrets Act (DTSA) and the Uniform Trade Secrets Act (UTSA), trade secret misappropriation occurs through two primary means. The first is acquisition of a trade secret by improper means, including theft, bribery, misrepresentation, breach of a duty to maintain secrecy, or espionage. The second is disclosure or use of a trade secret without consent by a person who used improper means to acquire it, who knew or had reason to know the secret was obtained improperly, or who had a duty to maintain secrecy. Misappropriation does not require actual damages to be actionable; the threat of disclosure or use can be sufficient for injunctive relief.

Common Scenarios of Trade Secret Misappropriation

  • Departing employee theft: An employee leaving for a competitor downloads confidential files, customer lists, or technical data before departure
  • Corporate espionage: A competitor plants an employee or hires an agent to obtain confidential information
  • Vendor or partner breach: A supplier, contractor, or business partner uses confidential information shared for business purposes for their own benefit
  • Hacking and cyberattack: Bad actors breach computer systems to steal confidential technical or business information
  • Reverse engineering beyond permitted bounds: Improper reverse engineering of a product where the method of reverse engineering itself was improper
  • Breach of NDA: A party to a nondisclosure agreement discloses or uses confidential information in violation of their agreement

Prevention: Building a Robust Defense

The most effective approach to trade secret misappropriation is prevention. A comprehensive prevention program includes multiple layers of legal, technical, and organizational controls. Legal controls include robust NDAs and confidentiality agreements with all employees, contractors, and business partners; invention assignment agreements; and well-drafted employment agreements that clearly define employees’ ongoing obligations regarding confidential information after they leave. Technical controls include access restrictions, encryption, monitoring systems, and data loss prevention tools. Organizational controls include training, policies, access audits, and exit interview protocols for departing employees.

Detecting Misappropriation

Early detection of trade secret misappropriation is critical because time is often of the essence in preventing harm. Signs that misappropriation may be occurring include unusual data access patterns detected through monitoring systems, large volumes of downloads or file transfers near an employee’s departure date, a competitor suddenly offering products or services that closely mirror your own proprietary offerings, discovery that a departing employee has joined a competitor in a role that would inevitably require use of your trade secrets, and insider tips from employees who observe suspicious behavior by colleagues. PerspireIP works with clients to establish monitoring programs and response protocols that enable rapid detection and action.

Responding to Suspected Misappropriation

When trade secret misappropriation is suspected, the first priority is to preserve evidence and take immediate steps to prevent further harm. A proper response includes conducting a thorough forensic investigation of relevant computer systems and accounts, securing and preserving all evidence relevant to the suspected misappropriation, consulting legal counsel immediately before taking actions that could prejudice later legal proceedings, considering whether to seek emergency judicial relief through a temporary restraining order or preliminary injunction, and sending a preservation demand to the suspected misappropriating party requiring them to preserve all relevant evidence. Missteps in the early stages of a misappropriation response can undermine your legal position, so legal counsel involvement from the beginning is essential.

Civil Remedies Under the DTSA and UTSA

The Defend Trade Secrets Act and state trade secret laws provide a comprehensive menu of civil remedies for misappropriation. Injunctive relief can prevent the misappropriating party from using or disclosing the trade secret, can require the return of stolen information, and can even prohibit a former employee from working in a role where use of the trade secret would be inevitable.

Monetary damages include actual damages for losses caused by the misappropriation and unjust enrichment to the misappropriating party not already accounted for in actual damages. In cases of willful and malicious misappropriation, exemplary damages of up to twice the actual damages may be awarded. Attorney fees can also be recovered in cases of willful and malicious misappropriation or bad-faith claims.

Emergency Seizure Orders Under the DTSA

One of the most powerful tools available under the DTSA is the ex parte seizure order, which allows a court to authorize law enforcement to seize property used to commit misappropriation without prior notice to the defendant. Seizure orders are available in extraordinary circumstances where a temporary restraining order would be inadequate and immediate seizure is necessary to prevent propagation or dissemination of the trade secret information. This remedy is particularly relevant where there is credible evidence that the defendant is about to flee the jurisdiction, destroy evidence, or immediately disclose the trade secret to third parties. Seizure orders are powerful but require careful legal strategy to deploy effectively.

Criminal Liability for Trade Secret Misappropriation

Beyond civil liability, trade secret misappropriation can result in federal criminal prosecution under the Economic Espionage Act (EEA). The EEA makes it a federal crime to steal trade secrets for the benefit of a foreign government or to steal trade secrets for commercial or economic purposes. Penalties include fines and imprisonment of up to 10 years for individuals and up to 15 years for foreign economic espionage. Several high-profile cases have resulted in criminal prosecution of former employees who took trade secrets to competitors, including cases involving technology companies in the semiconductor, automotive, and pharmaceutical industries.

The Forensic Record Decides These Cases

Misappropriation claims involving technology assets are won on logs and disk images, and lost when neither exists. The evidence that matters is generated in the ordinary course — but only if the systems were configured to generate it before anything happened.

  • Repository access and clone logs, retained long enough to cover a notice period.
  • USB and removable-media connection history from endpoint management.
  • Cloud storage sync and sharing events, including externally-shared links.
  • Email and file-transfer records showing volume and destination.
  • Badge and VPN records establishing presence and session timing.
  • Forensic images of returned devices, taken before reissue — a device wiped and handed to the next employee destroys the case.

Two operational rules follow. First, the moment departure raises a concern, issue a litigation hold and stop the routine wipe-and-reissue process for that person’s devices and accounts. Second, image before you investigate. In-house examination of a live device changes timestamps and gives the other side an argument about spoliation that can outlast the merits.

The other half of the record is what the code itself shows. Where a competitor’s product is suspected of containing your code, the comparison is done by expert analysis of structure, comments, variable naming, dead code and idiosyncratic artefacts — the fingerprints that survive refactoring. Preserved build artefacts and a complete version history are what make that analysis possible.

Why the Computer Fraud and Abuse Act Often Does Not Help

For years the Computer Fraud and Abuse Act, 18 U.S.C. §1030, was pleaded alongside every departing-employee case on the theory that taking data for a competitor exceeded the employee’s authorised access. That theory is now largely closed.

In Van Buren v. United States (2021), the Supreme Court held that a person “exceeds authorized access” only by obtaining information from areas of a computer system that are off limits to them — a gates-up-or-down inquiry. Using information one is entitled to access for an improper purpose does not violate the CFAA.

The practical effect on IT trade secret misappropriation claims is significant, because the typical defendant is an engineer who was authorised to clone the repository as part of their job. The CFAA count that used to supply federal jurisdiction and a threat of criminal referral usually will not survive.

It also cuts the other way as a design lesson. Access boundaries that are technically enforced — rather than merely stated in a policy — are what put the gate down. The narrower the entitlement, the more conduct falls outside it.

Remedies Under the DTSA, Including the Seizure Order

The Defend Trade Secrets Act of 2016 created a federal civil cause of action, at 18 U.S.C. §1836, for misappropriation of a trade secret related to a product or service used in interstate or foreign commerce. Its remedies are the practical toolkit:

  1. Injunctive relief to prevent actual or threatened misappropriation.
  2. Damages for actual loss caused by the misappropriation.
  3. Damages for unjust enrichment not addressed by the actual-loss award.
  4. A reasonable royalty in lieu of the other damages measures.
  5. Exemplary damages of up to twice the award, where the misappropriation is wilful and malicious.
  6. Attorney’s fees, for wilful and malicious misappropriation — or against a claim made in bad faith.

Two limits shape strategy. An injunction may not prevent a person from entering an employment relationship, and any condition placed on employment must rest on evidence of threatened misappropriation rather than merely on what the person knows — the DTSA’s deliberate constraint on inevitable-disclosure reasoning. And exemplary damages and fees are unavailable against an employee whose agreement lacked the §1833(b) whistleblower immunity notice.

§1836(b)(2) also provides for ex parte civil seizure of property necessary to prevent propagation or dissemination of the trade secret. It is available only in extraordinary circumstances, requires findings that an ordinary injunction would be inadequate, and is granted sparingly — but in an IT case, where the asset is a copy that can be replicated in seconds, it is occasionally the only effective order. Claims are subject to a three-year limitations period running from discovery or reasonable discoverability.

Criminal Exposure Under the Economic Espionage Act

Trade secret theft is also a federal crime, and in technology matters a referral is a realistic option where the conduct is clear.

18 U.S.C. §1832 covers theft of trade secrets for the economic benefit of someone other than the owner, where the offender intends or knows the offence will injure the owner, and carries imprisonment of up to ten years for an individual. 18 U.S.C. §1831 covers economic espionage — misappropriation intended to benefit a foreign government, instrumentality or agent — and carries substantially higher penalties, up to fifteen years for an individual and far larger corporate fines.

Referral is a decision to make carefully rather than reflexively. A parallel criminal investigation can slow or complicate the civil case, and the government controls its own timetable and charging decisions once involved. It also removes your control over disclosure of the secret itself, though protective provisions exist.

Preventive Controls That Hold Up in Court

The controls that reduce loss and the controls that prove reasonable measures are largely the same set, which is convenient. For technology assets specifically:

  • Scope repository access by team and project, not organisation-wide by default. Broad read access is the single most common finding in these matters.
  • Enforce an access lifecycle tied to HR events — provisioned on role, re-scoped on change, revoked on the last day, including API keys and service accounts.
  • Block or broker personal cloud sync on managed endpoints, rather than prohibiting it in a policy document.
  • Restrict bulk export in SaaS systems to named roles, and alert on it.
  • Retain the logs long enough to matter — a 30-day retention window will not cover a three-month notice period.
  • Run a departure checklist that includes an access review of the preceding 90 days for anyone with access to top-tier assets.
  • Include the §1833(b) notice in every confidentiality and IP agreement, so exemplary damages and fees remain available.

Finally, decide in advance who owns the response. These matters move fastest in the first 72 hours, and the decisions taken then — preserve or reissue the laptop, notify or wait, seek a temporary restraining order or gather evidence first — are made badly when nobody has authority. A named owner in legal, a named owner in IT security, and a standing relationship with a forensics provider turn a scramble into a procedure, and the difference shows up directly in what a court can later be shown.

None of this is exotic, and that is the point. In a dispute the court is asked whether the measures were reasonable in the circumstances, and a documented, consistently-applied access lifecycle answers that question far better than a sophisticated control nobody could show was actually running.

Conclusion

Trade secret misappropriation is a serious threat that requires both proactive prevention and swift enforcement when it occurs. The combination of the DTSA’s powerful federal remedies, state trade secret laws, and the Economic Espionage Act provides trade secret owners with robust legal tools to protect their most valuable confidential information. PerspireIP provides comprehensive trade secret protection planning, investigation support, and aggressive enforcement services to help businesses prevent misappropriation and respond decisively when it occurs.