By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 26, 2026
Quick Answer
Intellectual property theft from manufacturers is one of the least visible and most damaging categories of cyber threat. Nation-state actors and competitors who gain access to product designs, manufacturing processes, formulas, and customer data can replicate years of R&D investment without triggering a ransomware alarm or disrupting production. Manufacturing IP theft is successful precisely because it leaves no visible trace until the stolen IP appears in a competitor’s product.
Key Takeaways
- Nation-state actors from China, Russia, Iran, and North Korea have specifically and repeatedly targeted manufacturers for IP, process designs, and strategic business intelligence.
- Industrial espionage operates through persistent network access, often maintained for months or years before the intrusion is discovered, if it is ever discovered.
- The most common entry points are phishing of engineers and technical staff, supply chain compromise through software vendors, and exploitation of remote access tools used for OT maintenance.
- Trade secret theft from manufacturers has resulted in criminal prosecutions in both Canada and the US, with foreign intelligence services identified as actors in several major cases.
- Threat intelligence, access controls on engineering systems, and monitoring for anomalous data movement are the controls that detect and interrupt IP theft before exfiltration is complete.
Why Is Manufacturer IP So Valuable to Attackers?
A manufacturer’s intellectual property represents the accumulated investment of years or decades of research, engineering, and process development. Product designs, manufacturing processes, proprietary formulas, tooling specifications, and customer-specific configurations are assets that cost enormous resources to develop and that competitors or foreign state actors can exploit the moment they obtain them.
The economics of IP theft are straightforward from an attacker’s perspective. Developing a competing product from scratch requires years of R&D investment, prototype testing, and manufacturing process development. Obtaining the target manufacturer’s files through a network intrusion bypasses all of that. A stolen formula or design specification can be the basis for a competing product in a fraction of the time and at a fraction of the cost of legitimate development.
For nation-state actors, the motivation extends beyond commercial competition. Manufacturing capability in aerospace, defence, semiconductors, pharmaceuticals, and advanced materials is a strategic asset. Intelligence services that can acquire manufacturing IP for their domestic industries advance national technological capability at the expense of the target country’s manufacturers. The FBI and RCMP have both publicly identified this as an active and ongoing threat to North American manufacturers.
Who Is Behind Industrial Espionage Operations?
Nation-State Actors
China’s Ministry of State Security and affiliated groups have been identified in publicly attributed campaigns against North American manufacturers across aerospace, pharmaceuticals, semiconductors, and advanced materials. These operations involve sophisticated persistent intrusions, patient reconnaissance, and targeted exfiltration of specific IP that aligns with national strategic priorities. The FBI’s Economic Espionage Act prosecutions have named MSS officers and affiliated contractors in multiple cases involving US manufacturer IP theft.
Russia’s SVR and GRU have targeted defence industrial base manufacturers and technology companies in operations that combine IP theft with pre-positioning for potential disruptive attacks. Iran and North Korea have also conducted economic espionage operations against manufacturers, with North Korea specifically targeting aerospace and defence IP as part of weapons development programmes.
Insider Threats and Departing Employees
Not all IP theft involves external actors. Departing engineers, operations staff, and sales personnel who take product designs, customer lists, or process documentation to a competitor represent the insider threat category. These incidents are more common than external espionage in terms of volume, and they are frequently prosecuted under trade secret law in both Canada and the US. Economic espionage statistics include a significant proportion of insider cases, many involving employees who were recruited by foreign companies or state actors.
Competitor Intelligence Operations
Commercial competitors, including those operating in jurisdictions where intellectual property law is weakly enforced, conduct intelligence operations against manufacturers that fall short of nation-state sophistication but are effective at extracting commercial value. These operations may involve hiring former employees, cultivating insider contacts, or conducting targeted cyber intrusions. The boundary between competitive intelligence and trade secret theft is frequently crossed in industries where product cycles are short and IP advantages are decisive.
How Do IP Theft Operations Work?
IP theft operations are designed to be invisible. Unlike ransomware, which announces itself by encrypting files, a successful IP theft operation leaves the manufacturer’s systems functioning normally while exfiltrating copies of the target files. The attacker’s goal is to extract the IP and exit without triggering detection. A well-executed operation may not be discovered until the stolen designs appear in a competitor’s product years later.
The typical operation begins with targeted phishing of technical staff. Engineers, R&D personnel, and operations managers with access to valuable IP are profiled through LinkedIn, conference proceedings, and patent filings to identify individuals with access to target information. Spearphishing emails that reference real projects, colleagues, or industry topics are sent to harvest credentials or deliver malware.
Once initial access is achieved, the attacker maps the network to identify where the target IP resides. Engineering file servers, PLM systems, ERP databases, and shared drives that contain design files, process specifications, and customer configurations are the priority targets. The attacker typically establishes persistence through multiple mechanisms so that remediation of one access point does not terminate the intrusion.
Exfiltration is conducted carefully to avoid triggering data loss detection alerts. Large transfers are broken into smaller chunks, sent over extended periods, or routed through cloud storage services that appear in normal traffic patterns. Attackers who have maintained access for extended periods often have a detailed understanding of the manufacturer’s monitoring capabilities and calibrate their exfiltration behaviour to stay below detection thresholds.
What Controls Detect and Prevent IP Theft?
Access controls on engineering systems limit who can access what IP and reduce the number of accounts that, if compromised, provide access to the full IP portfolio. Role-based access that restricts engineers to the design files relevant to their current projects, rather than providing broad access to all engineering data, limits the blast radius of any single credential compromise. This is a more complex control to implement in engineering environments than in corporate IT, but it is achievable with proper classification and access management planning.
Data loss prevention monitoring that detects unusual access patterns and large data movements provides the detection layer that interrupts exfiltration before it is complete. A user account that accesses files from ten different product lines in a single session, or that transfers large volumes of engineering files to a cloud storage service, is exhibiting behaviour that differs from normal engineering work. Behavioural monitoring calibrated to engineering access patterns identifies these anomalies.
Threat intelligence specific to manufacturing IP theft provides early warning of campaigns targeting the manufacturer’s industry or technology area. FBI and CISA advisories about active campaigns, dark web monitoring for references to the manufacturer’s products or personnel, and credential monitoring for technical staff email addresses used in spearphishing campaigns all provide intelligence that allows proactive defensive action before an intrusion is confirmed.
Network segmentation of engineering systems from general corporate IT limits the lateral movement available to an attacker who compromises a corporate endpoint. A network architecture where engineering workstations, PLM servers, and design file repositories are on segmented networks that require additional authentication to access from general corporate systems reduces the access that any single compromised credential provides. Armour delivers these controls as part of its manufacturing cybersecurity services, built for the engineering environment rather than generic corporate IT.
What Should Manufacturers Do When They Suspect IP Theft?
Suspected IP theft requires a response that differs from standard ransomware incident response. The priority is forensic preservation and investigation rather than rapid restoration. The goal is to understand what was accessed, what was exfiltrated, how the intrusion was established, and how long it has been active. Hasty remediation that removes attacker tools without preserving forensic evidence can destroy the evidence needed for criminal prosecution or civil litigation.
Both the FBI in the US and the RCMP in Canada have units that investigate economic espionage and trade secret theft. Reporting to law enforcement should be considered promptly, particularly when the scale of the intrusion or the nature of the target IP suggests nation-state involvement. Law enforcement engagement can provide intelligence about known campaigns that helps scope the investigation and may enable attribution.
Frequently Asked Questions
How do we know if we have been a victim of IP theft?
Many IP theft victims discover the intrusion through external evidence rather than internal detection: a competitor product that bears suspicious similarity to proprietary designs, a law enforcement notification about a threat actor who targeted the manufacturer’s industry, or a credential exposure in a threat intelligence feed that suggests compromised access to engineering systems. Internal detection through network monitoring, user behaviour analytics, and threat hunting is more reliable but requires a monitoring capability that many manufacturers have not yet built. Armour’s threat intelligence service provides the external monitoring component that supplements internal detection.
What is the legal recourse if our IP is stolen?
Trade secret theft is a criminal offence in both Canada and the US. In the US, the Defend Trade Secrets Act provides a federal civil cause of action alongside state trade secret law and the Economic Espionage Act for criminal cases. In Canada, trade secret protection exists under common law and a Criminal Code trade-secret offence, with civil remedies available through the courts. Pursuing legal action requires forensic evidence of the intrusion and the exfiltration, which is why preserving forensic evidence during incident response is essential. Legal counsel with intellectual property and cybercrime expertise should be engaged early.
Do we need to notify customers if our IP theft involved their product data?
If the exfiltrated data included personal information of employees, contractors, or customers, PIPEDA in Canada and state data breach notification laws in the US may require notification. If the stolen data included customer-specific designs or configurations protected by confidentiality agreements, the manufacturer may have contractual notification obligations to those customers. The scope of notification obligations depends on what was actually accessed and exfiltrated, which is why a thorough forensic investigation is necessary before notification decisions are made.
How does cyber insurance cover IP theft losses?
IP theft losses are not uniformly covered by cyber insurance policies. Some policies cover incident response costs, forensic investigation, and notification expenses regardless of the type of cyber incident. The downstream losses from stolen IP, such as lost competitive advantage or lost revenue from a competitor using stolen designs, are typically not covered by cyber insurance and require separate intellectual property coverage or litigation recovery. Reviewing your policy specifically for IP theft scenarios, with a cyber insurance advisor, identifies the gap before an incident makes the gap consequential.
The Bottom Line
The most expensive attack on a manufacturer is often the one that never sets off an alarm. IP theft leaves the plant running, the files intact, and the network quiet while copies of the designs, formulas, and process knowledge that took decades to build walk out the door, sometimes to a competitor, sometimes to a nation-state that has decided your technology should be its own. It is invisible by design, so it cannot be defended by waiting for something to break. It has to be engineered against in advance: role-based access so no one account holds the whole portfolio, DLP and behavioural monitoring tuned to how engineers actually work, threat intelligence that sees the campaign forming, network segmentation around the crown jewels, and a forensic-first response for the day something looks wrong. Armour Cybersecurity helps manufacturers protect intellectual property with manufacturing cybersecurity services built for the engineering environment, so the R&D that is the whole value of the business stays inside the business.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



