01 / Executive brief
Executive summary
Jiaqiang Xu worked from 2010 to 2014 as a systems-software developer in China for a U.S. technology company identified by Reuters as IBM. His job gave him full access to proprietary source code for a clustered file system; after resigning, he retained a complete copy and used scripts to remove or change references that revealed its origin. S1S2S3
Xu marketed and demonstrated software built from that source code, including during an FBI undercover operation. He pleaded guilty to all six charged counts and admitted acting for his own profit and intending to benefit the PRC National Health and Family Planning Commission. The court sentenced him to five years in prison. S1S2
02 / The vignette
What happened
Full source access came with an ordinary development job
The asset was not a finished executable that could be bought on the market. Source code exposed the design of a clustered file system used to increase data-storage performance, along with the engineering choices needed to modify and support it. Xu's developer role allowed him to download that material before his voluntary resignation in May 2014. S1S2S3
Concealment turned employer code into a competing product
Xu did more than retain a backup. He created scripts that removed or altered identifiers connecting the files to their owner, then used the modified code to build software for customers. That transformation is the bridge between acquisition and use: conceal provenance, preserve functionality, and present the result as something available for sale. S1S2
Undercover infrastructure made the provenance visible
During meetings with undercover officers posing as startup representatives, Xu offered the source code as a platform for a data-storage business and uploaded files to a test network. A company employee confirmed that the files appeared to contain protected code. Xu ultimately admitted both commercial use and the intended benefit to a PRC government commission. S1S2
03 / Anatomy
How access became transfer
This chain reconstructs the sequence supported by the cited record. It does not imply that every legitimate relationship follows the same path.
- 01
- 02
- 03
- 04
- 05
- 06
04 / Evidence boundary
What is established—and what is not
Established in the record
05 / Sequence
Timeline
06 / People and institutions
Who appears in the public record
Jiaqiang Xu
Former China-based software developer
Outcome: Pleaded guilty to six counts; sentenced to five years
PRC National Health and Family Planning Commission
Government commission Xu admitted intending to benefit
Originator / affected institution
IBM
Employer identified by Reuters and developer of the proprietary source code
07 / Consequences
Documented and attributed harm
08 / Hindsight analysis
Where leadership could have seen risk
These are our analytic judgments based on the public record, not court findings. They are framed to improve controls without treating nationality as a risk factor.
Source access enabled full replication
A developer could copy an entire product foundation, not merely a report or a limited technical excerpt.
Provenance was technically erasable
Identifiers embedded in code were not a durable ownership control once the source tree left company systems.
09 / Apply the lesson
Actions leaders can take
- companies
Limit complete-tree access
Segment repositories and require task-based approval for bulk export or cloning of crown-jewel source code.
- companies
Detect provenance stripping
Monitor scripts and mass edits that remove copyright, product, package, or repository identifiers.
- both
Test post-exit exposure
Use code-fingerprint and market monitoring to identify protected software reappearing in demonstrations, bids, or outside products.
10 / Source record
Sources
Links point to the public record reviewed for this file. Government releases can summarize court proceedings but remain government-authored sources; the source note identifies those limits.
- S1 government release
Chinese National Pleads Guilty to Economic Espionage and Theft of a Trade Secret ↗
U.S. Attorney's Office, Southern District of New York · Published May 19, 2017 · Retrieved Aug 23, 2026
- S2 government release
Chinese National Sentenced for Economic Espionage and Theft of a Trade Secret from U.S. Company ↗
U.S. Department of Justice · Published Jan 18, 2018 · Retrieved Aug 23, 2026
- S3 reputable reporting
Ex-IBM employee from China gets five years in prison for stealing code ↗
Reuters via Business Standard · Published Jan 20, 2018 · Retrieved Aug 23, 2026
Identifies the otherwise unnamed victim company as IBM from Xu's public employment record.