Skip to Content

Intellectual Property Theft: What One Extradition Teaches

An extradition tied to university breaches shows why research and projects deserve the same protection as financial data
October 2, 2026 by
Intellectual Property Theft: What One Extradition Teaches

An old case that still has consequences

According to a report by The Record, an Iranian national accused by the United States of taking part in dozens of intrusions into American universities has been extradited from Montenegro to face charges. According to the indictment, the attacks aimed to obtain academic data and intellectual property from the targeted institutions, and the case is still ongoing.

What stands out most in this case is the timeline: intrusions discovered years ago are still causing legal, operational, and reputational fallout for the organizations involved. The episode is also a reminder that research, projects, and strategic information attract as much interest as financial data, because they represent years of investment and competitive advantage.

That raises a question every manager should ask: if someone were gradually copying your company's most valuable knowledge, how long would it take you to notice?

Why intellectual property has become a top target

Intellectual property is any proprietary knowledge that sets a business apart, such as formulas, engineering designs, source code, contracts, teaching methodologies, customer databases, and research results. Unlike a ransomware attack (data held hostage for ransom), which halts operations and announces itself, theft of this kind of information is usually silent, and the company keeps running while it loses the very thing that makes it unique.

How to protect your company's knowledge

The first step is to make it harder for uninvited visitors to get in. MFA (Multi-Factor Authentication) requires a second confirmation beyond the password, which makes a leaked credential far less useful to whoever stole it, and it should be enabled on email, academic and corporate systems, remote access, and cloud platforms. Patch management (the organized, regular application of security updates) completes this layer by closing known vulnerabilities that attackers usually look for first.

The second step is to make it harder for intruders to stay inside the network. EDR (Endpoint Detection and Response, covering workstations and servers) watches for suspicious behavior on devices and can quickly isolate a compromised machine. Combined with continuous proactive monitoring, which tracks access from unusual locations or devices and abnormal volumes of data leaving the network, it turns a silent intrusion into an alert your team can investigate in time, forming the core of a well-structured managed cybersecurity strategy.

Finally, your company needs the ability to recover. Tested backups and a business continuity plan make it possible to restore research, projects, and databases even after a serious incident, and a good starting point is to review your backup and disaster recovery strategy, confirming when the last real restore test was performed.

If someone were gradually taking your data, would your company notice?

Answering that question with confidence depends on visibility. Companies that combine continuous proactive monitoring, EDR on every workstation, up-to-date patch management, and MFA on critical access can spot unusual patterns while they are still small, when fixing them costs little and the impact remains manageable. Tested backups complete the picture, because they make it possible to recover the company's knowledge even in the face of an incident.

The other half of the answer lies with people, since regular awareness training teaches employees, faculty, and researchers to recognize phishing (fake messages designed to steal passwords) and to report suspicious behavior. With managed IT backing up your internal team, these layers work together seamlessly, and you gain time to focus on what makes the business grow.

The case reported by The Record shows that time does not erase the consequences of an intrusion, and also that protecting knowledge is an entirely achievable goal. With well-planned layers and constant oversight, your company can keep innovating, researching, and growing with the confidence of knowing its most valuable asset is in good hands.

Frequently asked questions

What is intellectual property theft in cyberattacks?

It is the unauthorized copying of an organization's proprietary knowledge, such as research, projects, formulas, contracts, and customer databases, through a digital intrusion. This type of attack is usually discreet, because the attacker's goal is to collect information without disrupting operations. As a result, it can go unnoticed by the company for months.

Why can an attacker stay inside the network for months without being noticed?

In many cases, the attacker uses stolen legitimate credentials, which makes their access look normal. Without continuous monitoring and EDR tools, discreet movements and gradual data exfiltration blend in with everyday traffic. Tracking abnormal behavior is what makes it possible to detect this kind of presence in time.

What measures reduce the risk of strategic data theft?

Balanced protection combines MFA on critical access, patch management, EDR on workstations, and continuous proactive monitoring. Access policies based on least privilege limit the reach of a compromised account. Tested backups and a business continuity plan make it possible to recover information if an incident occurs.

References

Want to know how well your company's knowledge is protected? Schedule a no-obligation Strategic IT Assessment with Zamak.

Intellectual Property Theft: What One Extradition Teaches
October 2, 2026
Share this post
Tags
Archive