{"id":7661,"date":"2023-11-27T17:29:45","date_gmt":"2023-11-27T14:29:45","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=7661"},"modified":"2026-02-18T11:13:25","modified_gmt":"2026-02-18T08:13:25","slug":"valeo-vs-nvidia-company-ip-still-too-easily-stolen-by-departing-employees","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/valeo-vs-nvidia-company-ip-still-too-easily-stolen-by-departing-employees\/","title":{"rendered":"Valeo vs NVIDIA: Company IP still too easily stolen by departing employees"},"content":{"rendered":"<p><em>The Valeo vs NVIDIA case highlights how easily departing employees can exfiltrate intellectual property such as source code and trade secrets. Insider threats often exploit legitimate access, using personal email, cloud storage, or USB devices to transfer sensitive data. Data Loss Prevention (DLP) and endpoint monitoring tools help detect, block, and remediate unauthorized transfers, reducing financial, legal, and reputational risk.<\/em><\/p>\n<p>Both NVIDIA and Valeo (a global automotive parts and technology supplier) have learned the hard way that it\u2019s all too easy for employees to exfiltrate valuable intellectual property (IP), and other sensitive data when they leave an organization.<\/p>\n<p>This week, Valeo filed a <a href=\"https:\/\/www.theverge.com\/2023\/11\/23\/23973673\/valeo-nvidia-autonomous-driving-software-ip-theft-lawsuit\" target=\"_blank\" rel=\"noopener\">lawsuit<\/a> against NVIDIA, alleging that a former employee stole six gigabytes of source code relating to parking and driver assistance technologies (as well as presentations and spreadsheets relating to the technology) and that NVIDIA has financially gained from its \u201cstolen trade secrets.\u201d<\/p>\n<p>The issue came to light this year when the two firms embarked on a joint project. During a Microsoft Teams video call, the former Valeo employee (now at NVIDIA) shared his screen, accidentally exposing a folder and file containing the Valeo source code.<\/p>\n<p>Valeo employees on the call immediately recognized it, took a screenshot of the offending data, and reported the incident. The former employee was subsequently <a href=\"https:\/\/www.bbc.com\/news\/technology-67489495\" target=\"_blank\" rel=\"noopener\">convicted<\/a> by German authorities over unlawfully holding the data, and his new employer, NVIDIA, was subjected to a lawsuit.<\/p>\n<p>&#8220;<em>NVIDIA\u00a0has saved millions, perhaps hundreds of millions, of dollars in development costs, and generated profits that it did not properly earn and to which it was not entitled,<\/em>&#8221; the complaint alleges.<\/p>\n<p>The issue is not a new one, in fact, we <a href=\"https:\/\/www.endpointprotector.com\/blog\/are-leavers-a-threat-to-your-data-what-the-great-resignation-means-for-your-data-protection-controls\/\" target=\"_blank\" rel=\"noopener\">wrote<\/a> about the threat of leavers to organizational data last year. But, this story puts into perspective the very real danger and financial impact that intellectual property theft can have on both the exited company, and also a new employer &#8211; who may very well be completely unaware that stolen IP has been introduced to their organization.<\/p>\n<p>Valeo\u2019s lawsuit alleges that the former employee downloaded source code without authorization by granting access to Valeo&#8217;s systems to his personal email account. He was then able to exfiltrate the data. It is not specified in the lawsuit, but, given the size of the data (over six gigabytes), we must assume that it was copied to removable media or transferred to a personal cloud store.<\/p>\n<p>Interestingly, the lawsuit outlines Valeo\u2019s technologies and process to protect IP &#8211; although this seems to have not been enough to mitigate the risk. The information points to the use of access controls within Google Drive that the employee managed to circumvent.<\/p>\n<h2>Can DLP protect Intellectual Property?<\/h2>\n<p>Tools like <a href=\"https:\/\/www.endpointprotector.com\/solutions\/data-loss-prevention\" target=\"_blank\" rel=\"noopener\">Endpoint Protector by CoSoSys<\/a> are designed to combat data loss that occurs either through accidental oversharing by employees, or maliciously. Policies can be built to protect common <a href=\"https:\/\/www.endpointprotector.com\/solutions\/pii-protection\" target=\"_blank\" rel=\"noopener\">PII<\/a> and <a href=\"https:\/\/www.endpointprotector.com\/solutions\/phi-protection\" target=\"_blank\" rel=\"noopener\">PHI<\/a> types, as well as <a href=\"https:\/\/www.endpointprotector.com\/solutions\/ip-theft-protection\" target=\"_blank\" rel=\"noopener\">company specific IP<\/a> &#8211; including <a href=\"https:\/\/www.endpointprotector.com\/solutions\/source-code-protection\" target=\"_blank\" rel=\"noopener\">source code<\/a>.<\/p>\n<p>It achieves this by protecting common data exit points on Windows, macOS, and Linux endpoints. These include email, messaging apps such as Slack and Microsoft Teams, browser uploads to cloud apps, printers, removable storage media, and more. Even if employees try to circumvent controls, perhaps by renaming files, trying to take screenshots, or printing files, Endpoint Protector allows organizations to <a href=\"https:\/\/www.endpointprotector.com\/blog\/if-70-of-data-loss-incidents-occur-at-the-endpoint-why-would-your-dlp-be-anywhere-else\/\" target=\"_blank\" rel=\"noopener\">monitor and protect data at the endpoint<\/a> \u2013 even when employees go offline. This gives organizations the visibility and control they need to control sensitive data and eliminate the risk of data leaving the endpoint.<\/p>\n<h2>Employers should be aware of the risks that new employees may bring with them<\/h2>\n<p>NVIDIA&#8217;s situation also highlights the need for employers to be aware of the data that new employees bring with them. Typically, there\u2019s no malice behind their actions. It\u2019s simply a desire to keep hold of data that could benefit them in their new role. Perhaps a list of potential sales contacts, or, simply, some examples of their work they\u2019d like to keep for reference. Of course, that\u2019s not to say it\u2019s all without malice. There are plenty of examples of employees taking confidential information with them to a new employer, just as this case highlights.<\/p>\n<p>Either way, the result is a loss of data for the original employer, and potential financial penalties for the new employer.<\/p>\n<h2>eDiscovery can identify data-at-rest on employee endpoints<\/h2>\n<p>NVIDIA claims that it has not benefited in any way from the stolen data and that it resided on the employee&#8217;s endpoint (laptop) only. Tools such as <a href=\"https:\/\/www.endpointprotector.com\/solutions\/ediscovery\" target=\"_blank\" rel=\"noopener\">Endpoint Protector\u2019s eDiscovery<\/a> module scans employee endpoints for sensitive data and allows security administrators to encrypt or delete it. This neutralizes any risk of that data later being exfiltrated, or putting the employer at risk of breaking any regulatory requirements (e.g., <a href=\"https:\/\/www.endpointprotector.com\/solutions\/gdpr-compliance\" target=\"_blank\" rel=\"noopener\">GDPR<\/a>, <a href=\"https:\/\/www.endpointprotector.com\/solutions\/nist-compliance\" target=\"_blank\" rel=\"noopener\">NIST<\/a>, HIPAA).<\/p>\n<h2>Learn more<\/h2>\n<p><a href=\"https:\/\/www.endpointprotector.com\/get-demo\" target=\"_blank\" rel=\"noopener\">Request a demo of Endpoint Protector<\/a> to learn more about how you can protect your data from unauthorized exfiltration, and mitigate the risk of leavers taking your intellectual property with them<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Valeo vs NVIDIA case highlights how easily departing employees can exfiltrate intellectual property such as source code and trade secrets. Insider threats often exploit legitimate access, using personal email, cloud storage, or USB devices to transfer sensitive data. Data Loss Prevention (DLP) and endpoint monitoring tools help detect, block, and remediate unauthorized transfers, reducing &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/valeo-vs-nvidia-company-ip-still-too-easily-stolen-by-departing-employees\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Valeo vs NVIDIA: Company IP still too easily stolen by departing employees&#8221;<\/span><\/a><\/p>\n","protected":false},"author":16,"featured_media":7663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[223],"tags":[],"class_list":["post-7661","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insider-threat-management","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/7661","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=7661"}],"version-history":[{"count":7,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/7661\/revisions"}],"predecessor-version":[{"id":8242,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/7661\/revisions\/8242"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/7663"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=7661"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=7661"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=7661"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}