TRAFEED

Is Six or Seven Years Enough for Stealing a Process Recipe? | Sentencing, and the Gate You Actually Control

Published2026-08-24Ryuta Hamamoto

Korean courts handed down six years four months and seven years for leaking Samsung DRAM process technology to a Chinese manufacturer. Against a development cost of 1.6 trillion won, is that proportionate? A look at Korean sentencing, Japan's far lower ceiling, and why criminal law can never protect your technology.

Is Six or Seven Years Enough for Stealing a Process Recipe? | Sentencing, and the Gate You Actually Control
Share

Hello, this is Ryuta Hamamoto from TIMEWELL. How did Chinese semiconductors close the gap with the industry leaders so quickly? Part of the answer surfaced in a Korean courtroom this year.

Reading the judgments, my first thought was whether the sentences match the weight of what was done. My second thought was the one that matters more commercially: however heavy you make the penalty, it will not protect a single gram of your technology. Criminal law only fires after the technology has gone.

Both halves are worth writing about.

What the Korean courts actually found

The facts first, and they need separating because coverage tends to blur them. Around the transfer of Samsung Electronics DRAM technology to ChangXin Memory Technologies (CXMT), there are several parallel matters.

One concerns a former Samsung employee who leaked 18nm DRAM process technology in 2016. The development cost of that technology is reported at 1.6 trillion won, roughly 180 billion yen. A sentence of six years and four months was finalised in April 20261.

The other is the seven-year custodial sentence handed down by the Seoul Central District Court on 22 April 2026. The defendant, a former researcher aged 56, was charged under the Industrial Technology Protection Act among other laws. The technology at issue was 10nm-class DRAM process technology that Samsung was first in the world to commercialise. The court found the leaked technology qualified as Korean "national core technology" and held that the harm extended beyond the company to Korea as a whole. Consideration received by the defendant totalled 2.9 billion won over six years, including a 300 million won signing payment and stock options2. This one is a first-instance judgment.

In August 2026, further courtroom testimony was reported: that CXMT management had intended from founding to obtain Samsung process information to develop DRAM, having at the time neither laboratories nor equipment nor any intention to develop independently. The claim is that acquiring some 600 process recipes was built into the business plan rather than an afterthought3.

This distinction matters. That account of founding intent is testimony given in court, not a fact found by the court. No corporate direction or liability on the part of CXMT has been established, and the seven-year judgment is first instance. The convictions are of individuals. This is not a finding that a company is guilty.

Even so, the shape of it is hard to ignore. Instead of researching from scratch, recruit the people and let the know-how travel with them. Add state support and a large domestic market and the catch-up accelerates. CXMT reportedly reached volume production seven years after the leak, in 2023, taking roughly 5% of the world market, and the Korean government estimates the economic damage from the leak in the tens of trillions of won1.

Why I think these sentences are light

Six years four months, or seven years. Against the nature of the act, I think both are light, for three reasons.

First, they are light against Korea's own standard. In 2024 the Supreme Court of Korea introduced and strengthened sentencing guidelines for technology leakage. Overseas leakage of national core technology carries a base range of three to seven years, an aggravated range of five to twelve, and up to eighteen years where harm is severe. General industrial technology leakage tops out at fifteen. Six to seven years sits inside the base band, below half the ceiling.

Second, they are light against what the defendant gained. 2.9 billion won over six years. If the assets survive the sentence, this works out as a crime that pays. A sentence that does not deter is not really a sentence.

Third, they are light against what other jurisdictions actually impose. Comparing real judgments rather than statutory maxima1:

Case Sentence
United States, GE Aerospace technology theft 20 years (finalised 2024)
Taiwan, TSMC-related case 10 years (first instance, April 2026)
Korea, Samsung Display OLED leak 5 years (Supreme Court)
Korea, this DRAM matter 6 years 4 months and 7 years

The gap to the United States is more than threefold.

Korean opinion runs the same way. A Korea Enterprises Federation survey of 1,000 adults nationwide in June 2026 found 90.7% wanting tougher punishment for technology leakage, and 90.6% supporting punitive economic sanctions such as fines and asset forfeiture1. Detections of core technology leakage rose from 9 cases in 2021 to 33 in 20251.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

An economic-crime yardstick does not fit

Why does it read as light to me? Because measuring this with the yardstick of economic crime does not work.

Manufacturing technology built over decades at a cost of trillions does not belong to the company alone. It carries the equipment and materials suppliers around it, tens of thousands of jobs, and part of the production capacity underpinning communications and energy infrastructure. Semiconductors are not just phones. Cars, AI data centres, networks, the power grid. That is why Japan designates semiconductors as a specified critical material under its economic security legislation.

One person's decision moves the core of that abroad, and once moved it can never be recovered. Stolen goods can be returned; a process recipe cannot. The harm cannot be restored and keeps compounding. That is why I think the sentencing framework needs designing as its own category rather than as an extension of embezzlement or breach of trust.

And Japan is lighter still

That was the neighbour. What about Japan?

Article 21 of the Unfair Competition Prevention Act sets up to 10 years' imprisonment and a fine of up to 20 million yen for individuals, rising to 30 million yen where there is intent to use the secret abroad, with both available together. For corporations the figures are 500 million yen, or 1 billion yen for overseas use. A ceiling of 10 years is plainly low beside Korea's guideline 18 or the 20 years actually imposed in the United States.

Enforcement is looser still. The bar for prosecution is high and the burden on companies to prove they managed the secret properly is heavy, so cases drop out or end in acquittal.

Meanwhile the incidence keeps climbing. National Police Agency statistics published in March 2026 recorded 38 cases of trade secret infringement cleared in 2025, up 16 cases or 72.7% year on year, the highest in a decade4. Most involve material taken on changing jobs or leaving to start a business. One cited example involved a former employee of a precision mould maker emailing drawing data to an overseas entity4.

Rising incidence, a low ceiling, loose enforcement. To anyone hunting technology, a country with all three is an easy place to work.

Criminal law still will not protect you

Having argued about sentencing, here is the operator's view.

Criminal law is after the fact. Heavier penalties will not take leakage to zero, and what has left does not come back. So the investment that actually pays is not in the severity of judgments but in the gate.

From my earlier years working on overseas sites and technology strategy, one thing stuck: the people seeking technical information are far more organised than most companies assume. And the entry point is almost always a person.

Japan already requires a specific check here. Under the clarification of deemed export controls effective 1 May 2022, providing technology even to a resident of Japan can require an export licence where the recipient falls into defined specified categories:

  1. A person under an employment or similar contract with a foreign government or foreign entity, subject to its direction or owing it a duty of care
  2. A person receiving, or promised, economic benefit from a foreign government or foreign entity amounting to 25% or more of annual income
  3. A person acting in Japan under the direction of a foreign government

The check is required before technology is provided. Properly, it belongs in hiring, in the start of joint research, and in the signing of outsourcing agreements, and it only works when HR, legal and research functions run it together. This is not a call for suspicion; it is a regulatory requirement.

What to do reduces to four things. At the entry point, verify the attributes of the person or organisation when hiring, starting joint research, or engaging a contractor. In steady state, restrict access to sensitive information to what the role requires and keep records. At the exit, have a way to check what left when someone departs or a contract ends. And for counterparties, keep verifying the ownership and regulatory status of suppliers and research partners.

To see how far your own operation covers those four, our export control check is a free starting point.

Screening a list is no longer enough

The question is whether people can carry this by hand.

Even the apparently simple question "is that company on a sanctions list" has no simple answer. Take CXMT.

On 8 June 2026 the U.S. Department of War expanded its Section 1260H list of Chinese military companies to 188 entities, adding 65 (17 parents and 48 subsidiaries) and removing 10. CXMT appears on that list; it was first named in the notice of 7 January 2025 and designated again in the June 2026 notice56.

Care is needed here. The 1260H list is not itself a sanctions list. Being on it does not prohibit commercial dealings; it bites through procurement restrictions. Under Section 805 of the FY2024 NDAA, direct contracting by the Department is barred from 30 June 2026, with indirect contracting following on 30 June 2027. Under Section 5949 of the FY2023 NDAA, all federal agencies are barred from procuring CXMT semiconductor products from 23 December 20275. And listing is a U.S. regulatory designation, not a finding that a company did anything unlawful.

Lists also move. A February 2026 version of the 1260H list reportedly dropped CXMT, but that version was withdrawn shortly after publication and a new one issued in June6.

Which list, which version, with what legal effect. Miss that and you get the judgement wrong. Add a framework like the BIS 50% rule, where control by a listed entity pulls subsidiaries in, and exact-name matching stops meaning much at all; you have to walk the ownership chain. I covered that in the complete guide to the BIS 50% rule.

In most companies and universities this work rests on a handful of people moving between spreadsheets and government websites. When they transfer, the knowledge goes with them.

That gap is why we build TRAFEED, an AI agent for economic security compliance covering export classification, counterparty research, and research security screening for universities, using a consensus of multiple models and showing its reasoning. A joint validation with Okayama University confirmed accuracy above 95%, it runs in production at more than 20 organisations, and the core technology is patented in Japan.

AI does not settle this on its own. The final classification decision rests with your own export control officer. But working out who might be caught, on which list, in which version, on what basis, and leaving a record of it, is machine work.

Closing: argue about sentencing, invest in the gate

The record. In Korea, six years four months was finalised and seven years imposed at first instance over Samsung DRAM technology reaching CXMT12. Korean guidelines allow up to 18 years for overseas leakage of national core technology, and a comparable U.S. case drew 20 years1. Japan's ceiling is 10 years, and cleared cases hit 38 in 2025, up 72.7% and the highest in a decade4.

I think Japan's framework is out of proportion to the seriousness of the act, and the legislative argument is worth having.

But arguing about penalties will not protect your technology. Technology leaks as a human decision before it leaks as a file. So the defence starts with people too: who you bring in, what you show them, who you partner with, handled as procedure rather than instinct. Dull, tedious, hard to show results for. Still cheaper than saying "we'll be fine" and being wrong.

Start by checking whether your hiring and joint research processes include the specified-category check. If not, that is where to begin. To talk it through, get in touch.

References

Judgments and statistics are confirmed through reporting and official material. Passages resting on courtroom testimony are flagged as such in the text.

Footnotes

  1. Six years four months for leaking semiconductor technology abroad; 90% of the public want tougher punishment — The Chosun Ilbo (Japanese edition) — 20 July 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7

  2. Former researcher sentenced to seven years for leaking Samsung semiconductor technology to China — Yonhap News — April 2026 (Japanese) ↩ ↩2

  3. Courtroom testimony on CXMT management's intent from founding — XenoSpectrum — August 2026 (Japanese) ↩

  4. Status of Cleared Cases of Economic Crime Affecting Daily Life, 2025 — National Police Agency — March 2026 (Japanese) ↩ ↩2 ↩3

  5. Notice of Availability of Designation of Chinese Military Companies — Federal Register — 10 June 2026 ↩ ↩2

  6. Entities Identified as Chinese Military Companies Operating in the United States in Accordance with Section 1260H — U.S. Department of War — 8 June 2026 ↩ ↩2

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

The BIS Affiliates Rule (50 Percent Rule) Readiness Checklist (2026)

A fill-in working checklist for trade compliance teams preparing for the BIS Affiliates Rule. Covers what the rule actually does (aggregation across owners and across lists, cascade/carry-forward, the rule of most restrictiveness, and why exactly 50% is in while below 50% is not automatically out), what is stayed and what is in effect now, where ownership data typically breaks, and a six-phase preparation list from scoping through governance. The stay is set to end on 9 November 2026 "absent a future extension"; in September 2026 the US and China announced an extension to 10 January 2027, which had not been published in the Federal Register as of 5 October 2026 — so the sheet is built to work whichever way it goes. Based on primary sources (90 FR 47201, 90 FR 50857, 15 CFR, and China's Ministry of Commerce). Designation is a regulatory classification, not a judgement about a company; final determinations rest with your export-control officer and the authorities' current guidance.

EAR Classification Flow & EAR99 Practical Checklist (for exporters from Japan, 2026)

A fill-in working sheet covering "subject to the EAR? → ECCN on the CCL? → EAR99?", the crucial "when EAR99 still needs a license" (embargoes, end-use, end-user), de minimis / FDP, counterparty screening, and the two-track cross-check with Japan's classification (FEFTA / Appended Table 1). Based on primary sources (15 CFR, the Federal Register, BIS, METI); the EAR changes frequently, so treat the authorities' latest guidance and your export-control officer as authoritative.

China Business Travel: Technology Pre-Departure Worksheet (fill-in, 2026)

A fill-in worksheet for engineers, sales and researchers travelling to China, and for the teams that send them. Under Japan's Foreign Exchange and Foreign Trade Act, taking technical information on a trip can amount to providing technology in a foreign country (Art. 25(1)), and carrying it on a laptop or opening it from abroad can fall within Art. 25(3)(i). Most trips stay within the exemptions in Article 9 of the Ordinance on Trade Relations Invisible Trade (publicly available technology, basic scientific research, patent filings, technology incidental to exported goods). This worksheet shows where the line sits, situation by situation, with fill-in sections for before, during and after the trip. The China side reflects State Council Order No. 841 (in force 15 September 2026) Arts. 3 and 5, the Exit and Entry Administration Law Art. 28, and Japan's MOFA overseas safety advisory. Classification and licensing decisions rest with your export-control officer.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles