Powered By InformationWeek Business Technology Network
 
Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Ex-Ford Engineer Indicted For Allegedly Stealing Company Secrets

Xiang Dong Yu allegedly copied 4,000 sensitive Ford documents onto a USB drive before leaving the company

Oct 16, 2009 | 03:36 PM

By Kelly Jackson Higgins
DarkReading

Yet another major corporation may have been the victim of one of its own stealing trade secrets: A former Ford Motor engineer has been indicted for allegedly stealing thousands of sensitive documents from the company and copying them onto a USB drive before taking a job with another auto company.

Xiang Dong Yu, who also goes by Mike Yu, was arrested Wednesday at Chicago's O'Hare Airport after returning from a trip to China, according to published reports. Yu, 47, is charged in an indictment with theft, attempted theft of trade secrets, and unauthorized access to a computer and faces up to 10 years in prison. He currently works for an unnamed competitor to Ford in China.

Yu allegedly copied 4,000 documents that contained Ford design information, including engine and transmission mounting subsystems, electrical distribution systems, doors, mirrors, steering-wheel assemblies, power systems, and wipers. The indictment says he allegedly stole most of the information in December 2006, just before he resigned from his engineering job at Ford to take a position at a company in China. In spring 2008, he allegedly used some of the stolen Ford information while job-hunting in China.

"Employees and employers should be aware that stealing proprietary trade secrets to gain an economic advantage is a serious federal offense that will be prosecuted aggressively," U.S. Attorney Terrence Berg said in a statement.

Employees siphoning their employers' corporate trade secrets onto a USB drive for profit or leverage in another job is nothing new -- similar insider theft incidents occurred at duPont and Intel.

"This problem isn't isolated to Ford," says Brian Cleary, vice president of products and marketing at Aveksa. "There have been other very similar situations where people with a bona fide reason to access this information chose to misuse that access for fraud purposes...The challenge to organizations is understanding where they are introducing access-related business risks."

Cleary says the keys to protecting yourself from a rogue privileged user is ensuring that no one has access to anything they don't need for their job, monitoring their access patterns and activities, revoking privileges users aren't using, and deploying real-time access monitoring for users with access to highly sensitive data.

And while the options for securing USB access were a bit slimmer during Yu's alleged activities three years ago, locking down USB drives is crucial, notes Ben Goodman, principal technical specialist for compliance at Novell. "Having an engineering workstation with access to intellectual property that [would have] let him use CD-Rs or USBs is almost neglect [today], " Goodman says. "There are so many tools out there to help you lock down USB drives."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.


Subscribe to RSS



Insider Threat Reports

report Inside Out: Protecting Your Partnerships -- and Your Data
Today's businesses depend on e-commerce among partners, but allowing third parties to access internal networks may endanger your data. How can IT security pros ensure that contractors, supplies and others get the access they need -- without becoming threats? This report offers some answers.

report Rotten Apples: How To Detect And Stop Malicious Insiders In Your Organization
Most data leaks are unintentional - but in every enterprise, there are a few hard cases that defy this truism and threaten the very heart of your data.What can you do to stop these rotten apples from using their intimate knowledge of your organization - and its data access methods - to wreak havoc? This report offers a detailed look at how malicious insiders might attack your data, how they’re motivated, and what you can do to stop them.

report Understanding The Insider Threat
Think you know your trusted users? Think again. The availability of new Internet technologies and the pressures of a spiraling economy are changing the nature of the data breach, and your employees may have their fingers on the trigger. This report offers a look at the full spectrum of insider threats, and the risks associated with each.

report Well-Meaning Employees -- And How To Stop Them
The most dangerous threat to your data isn't hackers or criminal insiders: it's the well-meaning employee, whose missteps may lead to the unintentional leak of your most sensitive corporate data. Learn how employees accidentally expose sensitive information, and how you can keep those good intentions from paving the road to your company's ruin.