On August 21, 2026, a federal jury in Chicago convicted a 71-year-old engineer named Chih-Yee Jen on two counts: conspiracy to steal, misappropriate, or possess trade secrets, and possession or attempted possession of stolen trade secrets. Sentencing is set for January 5, 2027.
The headline writes itself — another Chinese-competitor trade secret case, another DOJ press release, another FBI counterintelligence quote about accountability. But the operational lesson underneath is more uncomfortable than the headline, and it has nothing to do with China specifically.
The theft happened in a window that almost every security program leaves wide open: the months between a shutdown announcement and the last badge turn-in.
What actually happened
Philips ran a facility in Aurora, Illinois that designed and built X-ray tubes for CT imaging machines, sold under its Dunlee brand. Jen had worked there since roughly 2006. Two colleagues named in the case, Fince Tendian and Vladimir Nevtonenko, had worked on Philips X-ray tubes since 1998 — three years before the Aurora plant even opened. That is a combined half-century of institutional knowledge sitting in one building.
In June 2017, Philips announced it would close Aurora by year-end, moving the work to Hamburg. Roughly 200 jobs went away.
By August 2017 — two months after the announcement, four months before the doors closed — a vice president at Kunshan GuoLi Electronic Technology, a Chinese vacuum electronics firm, was in conversation with Jen about standing up a U.S. subsidiary to compete with Philips in the exact same product line. That subsidiary was set up in Aurora, in the same suburb.
While still on the Philips payroll, Jen shared confidential documents with the Chinese firm, pulled proprietary X-ray tube information out of internal Philips databases, and recruited colleagues to follow him across.
He left Philips on December 29, 2017. He joined the new company in January 2018 and got to work building X-ray tubes with what he took.
The 2024 indictment enumerates ten categories of Philips trade secrets: assembly procedures, component specifications and tolerances, annealing and wiring specifications, manufacturing processes, tube seasoning protocols, and source code among them. Jen was charged with taking four of them.
The three failures worth studying
1. The offboarding window was treated as an HR event, not a security event
There is a predictable behavioral shift when a site closure is announced. Loyalty evaporates on the day of the announcement, but access does not get revoked until the day of departure. In Aurora, that gap ran roughly six months, and during it, several hundred people with legitimate credentials had every reason to think about what came next — and no reason to think anyone was watching.
Nothing exotic happened here. No malware, no zero-day, no privilege escalation. An engineer with authorized access to engineering databases queried engineering databases. That is the hardest possible pattern to catch after the fact and the easiest to catch in real time, if anyone is looking.
The control: when a RIF, site closure, acquisition, or major reorg is announced, the affected population goes onto a heightened monitoring posture that day. Baseline their normal data access in the 90 days prior, then alert on deviation — volume spikes, access to repositories outside their project scope, bulk exports, personal cloud sync, USB writes, print jobs. This does not require accusing anyone of anything. It requires treating the announcement itself as the trigger event it is.
2. Paper controls were mistaken for controls
Philips did the legal work correctly. Every employee signed an Ethics and Intellectual Property Agreement prohibiting use or disclosure of proprietary information during or after employment. Departing Aurora staff also signed a Settlement and General Release Agreement barring them from using Philips technical information to benefit a competitor.
Those agreements are why there was a case to prosecute. They are not why the theft was prevented, because it wasn’t.
Contracts are a recovery instrument. They give you standing, they establish that the information was in fact protected (a statutory element of a trade secret claim), and they support damages. They do not stop a file from moving. Any program where “we have everyone sign an IP agreement” appears in the insider threat control column has a category error in its risk register.
3. Nobody noticed the cluster
The single most legible signal in this entire case is that three long-tenured engineers from the same specialized product line went to the same newly formed local company at the same time. Jen recruited them while he was still employed.
That is a pattern any competent HR analytics function can surface from exit interview data and LinkedIn, and it costs nothing. A competitor incorporating in your own town, in your own product category, months after your closure announcement, and staffing itself from your bench, is not a subtle indicator.
Philips did eventually see it — the civil suit was filed April 19, 2019, roughly sixteen months after Jen walked out. By then the subsidiary had been sold on to a related Chinese firm, Kunshan Yiyuan Medical Technology, which was selling X-ray tubes in China.
The recovery math is worse than people assume
This is where the case stops being a cautionary tale about detection and starts being an argument about why prevention is the only part of the budget that reliably pays.
Count the clock. Theft in 2017. Civil suit in 2019. Federal indictment in December 2024. Conviction in August 2026. Sentencing in 2027. That is roughly nine years from exfiltration to verdict, and the tubes were on the market in China for most of it.
The three individuals in the U.S. were reachable. The people and companies that arguably drove the scheme were not — the Kunshan GuoLi VP and both Chinese companies were indicted, placed on the court’s Fugitive Calendar, and have never been arraigned. Philips also pursued claims in China; the Suzhou Intermediate People’s Court dismissed them in August 2025, and Philips’s appeal to the Jiangsu High People’s Court was still pending as of GuoLi’s spring 2026 annual report.
So the scoreboard reads: convictions against three retirement-age engineers, an attorneys’ fee award of roughly $2.5 million against entities that have not appeared in U.S. court, a dismissal in China, and nine years of a competitor building product with your engineering data. There is no version of this where litigation made Philips whole.
What to actually do about it
If you own security at an organization with real IP, this case argues for five specific things:
Know your crown jewels at the file level. Philips could enumerate ten discrete categories of trade secret when it mattered. Most organizations cannot. If you cannot name the specific repositories, drawings, parameter sets, and code that constitute the company’s actual advantage, you cannot monitor them, and you will struggle to prove they were protected.
Make organizational change a security trigger. Layoff, closure, divestiture, failed acquisition, or a large reorg — each should automatically raise monitoring on the affected population, tighten export controls, and shorten access review cycles. Write this into the RIF runbook so it happens without anyone having to ask.
Instrument the databases, not just the endpoints. The data left through legitimate queries against internal systems. Endpoint DLP alone would not have flagged normal-looking database access from a longtime engineer. Query-level logging with baseline anomaly detection is where this gets caught.
Seed canaries in the crown jewels. Uniquely watermarked documents and honeytoken records in your highest-value repositories serve two purposes: they alert on access, and years later they are the cleanest possible attribution evidence in court.
Watch the destination, not just the departure. Track where departing technical staff land, especially in clusters. A new entrant in your product category hiring three of your specialists is a competitive intelligence signal and a security signal at the same time. Most companies have someone doing the first job and nobody connecting it to the second.
The part nobody wants to say
Jen was 71 at conviction. Tendian is 57, Nevtonenko is 77. These were not disgruntled juniors or cyber-savvy operators. They were career engineers at the end of a long run at a plant that was closing, approached by someone offering continuity of the work they had spent decades doing, in the same town, without a relocation to Hamburg.
That is the recruitment pitch that works. It is not money, primarily, and it is not ideology. It is “keep doing the thing you are good at, right here.” Every organization that announces a facility closure is, that same day, generating a list of people for whom that pitch is compelling.
The security response to a shutdown announcement should begin the hour it goes out, not the week people hand in their badges.
Sources
- U.S. Department of Justice — “Federal Jury in Chicago Convicts Engineer for Stealing Trade Secrets from Philips Medical Systems on Behalf of Chinese Competitor”
- The Register (Connor Jones), Aug 25, 2026
- The Epoch Times, Aug 2026 — indictment detail and Chinese litigation status
- Crain’s Chicago Business, Feb 2025
- Radiology Business, Feb 2025
Charges against Xiaoqin Du, Kunshan GuoLi Electronic Technology Co. Ltd., and Kunshan Yiyuan Medical Technology Co. Ltd. remain allegations; those defendants have not been arraigned and are presumed innocent.



