Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Lessons to Learn from Coca-Cola’s Insider Trade Secret Theft

The Lessons to Learn from Coca-Cola’s Insider Trade Secret Theft

In today’s business, your data is your number one asset. For this reason it is important that you take steps to protect it. One case that accentuates this is the case of Xiaorong You, which is currently playing out in a Tennessee court. The accused is charged with stealing trade secrets and committing corporate espionage, as she is accused of allegedly stealing almost $120 million worth of BPA-free technologies from several companies, among them the Eastman Chemical Company and Coca-Cola.

Let’s take a look at how these two companies deployed their threat detection systems and the effect they had on the companies. 

You’s Story

Xiaorong “Shannon” You, a naturalized US citizen and Ph.D. in Polymer Science and Engineering, has worked at several companies since the early ‘90s. From December of 2012 to August of 2017, she worked for Coca-Cola as a principal engineer for global research, moving to the Eastman Chemical Company to work as a packaging application development manager from September of 2017 until June of 2018, when her employment was terminated.

During her tenure at both companies, You was given access to many trade secrets that only a handful of employees were privy to. In the indictment, You is charged with retaining these secrets (despite affirming that she hadn’t in writing) and then handing them over to the People’s Republic of China in an attempt to qualify for its The Thousand Talents program. This program has been used before to introduce advanced technologies to China, with the Department of Justice having prosecuted some cases similar to You’s.

Her modus operandi was that she retained this information by simply uploading data to her personal Google Drive account or captured especially sensitive information on her smartphone. Once she captured this data, You worked with a Chinese national named Xiangchen Liu to form a separate company in China that went ahead to use these trade secrets to begin revenue generation. They allegedly used an Italian BPA-free manufacturer to incorporate the stolen technologies onto their own products.

The theft of this information impacted several companies, including Coca-Cola and The Eastman Chemical Company, AkzoNobel, Dow Chemical, PPG, TSI, Sherwin Williams, and ToyoChem. This led to the charges she currently faces.

How You’s Employers Could Have Stopped Such Activities

There were stark differences between the way that Coca-Cola and The Eastman Chemical Company handled these issues. You left Coca-Cola in August of 2017, but her indictment states that the crimes she’s charged with didn’t happen until 2019. This means that Coca-Cola had no knowledge of the theft until after she had been exposed by her later employer. 

This fact is indicative of two reasonable hypotheses:

  1. Coca-Cola lacked the tools to detect such activities in real-time, making it far more difficult to prevent protected and sensitive data from successfully leaving the corporate environment.
  2. Coca-Cola also lacked the policies that could have prevented non-authorized devices from entering the workspace or otherwise being kept in proximity to sensitive company data or infrastructures. While old-fashioned, the concept of taking photographs of such information is no less effective for its age.

If you compare that to You’s sudden dismissal from the Eastman Chemical Company, you would have to consider that they had the data protection standards implemented to catch would-be thieves pretty rapidly.  If they hadn’t, the $120 million in trade secrets could have been substantially more. 

This just goes to show that any business can have the right idea about security, but not pay close enough attention to the details. Coca-Cola is a massive brand, but it couldn’t stop You from allegedly raking the company over the coals. 

If your business has information that you need to protect, whether it is covered by compliance regulations or not, the IT professionals at Voyage Technology can help you put in a platform that can keep your digital assets, intellectual property, and any other sensitive data secure. Give us a call today at 800.618.9844 for more information.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 01 April 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Efficiency Hardware Network Security User Tips Internet IT Services Malware IT Support Privacy Workplace Tips Computer Phishing Email Google Workplace Strategy Hosted Solutions Collaboration Small Business Users Backup Ransomware Managed Service Mobile Device Productivity Microsoft Passwords Quick Tips Saving Money AI Communication Cybersecurity Data Backup Smartphone Data Recovery Disaster Recovery Android VoIP Upgrade Smartphones Business Management Mobile Devices communications Windows Social Media Browser Managed IT Services Microsoft Office Current Events Network Tech Term Remote Internet of Things Information Automation Artificial Intelligence Facebook Holiday Miscellaneous Gadgets Compliance Cloud Computing Covid-19 Training Outsourced IT Server Managed Service Provider Remote Work IT Support Spam Encryption Employee/Employer Relationship Windows 10 Office Government Data Management Business Continuity Business Technology Wi-Fi Windows 10 Blockchain Bandwidth Virtualization Apps Managed Services Mobile Office Two-factor Authentication Data Security Vendor Employer-Employee Relationship App Tip of the week Voice over Internet Protocol Networking Mobile Device Management Chrome Gmail Budget BYOD WiFi Apple Access Control Conferencing Hacker Computing Avoiding Downtime Information Technology Managed IT Services Marketing How To BDR Office 365 HIPAA Physical Security Applications Health 2FA Help Desk Computers Operating System Retail Healthcare Risk Management Website Office Tips Analytics Augmented Reality Router Storage Password Bring Your Own Device Virtual Private Network Big Data Paperless Office Windows 11 Infrastructure Monitoring Going Green Excel Customer Service Document Management Remote Workers Cybercrime Managed IT Service Telephone Scam Data loss Cooperation Free Resource Project Management Windows 7 Firewall Patch Management Save Money Microsoft 365 Remote Monitoring End of Support Vulnerability Vendor Management Solutions The Internet of Things Display Printer Social Holidays Data Storage Customer Relationship Management Smart Technology Supply Chain Video Conferencing Machine Learning Managed Services Provider Saving Time Settings Virtual Machines Professional Services Printing Hacking Wireless Presentation Content Filtering YouTube Maintenance Downloads Antivirus Wireless Technology iPhone Cryptocurrency Licensing Entertainment Vulnerabilities Virtual Desktop Data Privacy Word Data storage LiFi Images 101 Multi-Factor Authentication Robot Mobility Outlook Telephone System Cost Management Money Humor Safety IT Management Meetings VPN Employees Sports Integration Mouse Modem User Tip Processor Computer Repair Mobile Security Administration IBM Cookies Monitors Cyber Monday Medical IT Best Practice Proxy Server Reviews Buisness Tactics Development Hotspot Transportation Small Businesses Legal IT solutions Websites Mirgation Hypervisor Displays Nanotechnology Optimization PowerPoint Business Growth Shopping SharePoint Addiction Electronic Medical Records Language Employer/Employee Relationships Outsourcing Navigation Management PCI DSS Competition Cortana Chatbots Lenovo Gig Economy Screen Reader Writing Distributed Denial of Service Workplace Alt Codes Downtime Service Level Agreement Internet Service Provider Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Private Cloud Identity Evernote Paperless Hosted Solution Server Management Regulations Compliance Superfish Bookmark Identity Theft Smart Tech Memes User Co-managed IT Typing Download Net Neutrality Twitter Alerts SQL Server Technology Care Error History Business Communications Google Drive Financial Data Knowledge Browsers Smartwatch IP Address Connectivity IT Social Engineering Break Fix Scams Upload Procurement 5G Remote Computing Azure Hybrid Work Cyber security Multi-Factor Security Tech Human Resources Google Docs Unified Communications Social Network Telework Experience CES Running Cable Tablet IoT Communitications Recovery Dark Web Cables Bitcoin Google Wallet Trends Supply Chain Management Hard Drives Alert File Sharing Regulations Dark Data Google Calendar Term Google Apps Managed IT Customer Resource management FinTech Domains Windows 8 Data Analysis Laptop Star Wars IT Assessment How To Microsoft Excel IT Maintenance Drones Gamification Flexibility Refrigeration Notifications Staff Value Business Intelligence Travel Social Networking Legislation Shortcuts Organization Public Speaking Techology Fileless Malware Digital Security Cameras Lithium-ion battery Halloween Google Maps Smart Devices Ransmoware Content Remote Working Wearable Technology Memory Vendors Entrepreneur Unified Threat Management Motherboard Data Breach Comparison Google Play Be Proactive Health IT Hacks Unified Threat Management Directions Videos Scary Stories Assessment Electronic Health Records Permissions Workforce Undo Fun Wasting Time Threats Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies Deep Learning User Error Microchip Internet Exlporer Software as a Service Fraud Meta Education Username Managing Costs Amazon Point of Sale eCommerce Black Friday SSID Mobile Computing Database Surveillance Application Virtual Assistant Outsource IT Media Network Management Search Tech Support IT Technicians Virtual Machine Environment

Blog Archive