Trade Secret Risks Rise for NC Firms with Remote Work and AI Use
Experts highlight new trade secret vulnerabilities from remote work and AI in North Carolina.
Why it matters: North Carolina companies must update trade secret protections as remote work and AI increase exposure to identity fraud and unauthorized data access. Legal counsel should urgently reassess risk strategies to prevent costly breaches and regulatory fallout.
- Over 100 U.S. companies infiltrated by North Korean operatives using stolen identities in remote IT roles, generating $5M+ illicit revenue.
- North Korean cyber operatives use AI and deepfake technology to secure multiple remote jobs simultaneously, evading detection.
- Public AI platforms risk trade secret exposure when employees enter confidential data into them.
- AI agents can stealthily harvest trade secrets and employees may bypass monitoring by capturing AI outputs on personal devices.
North Carolina companies face growing risk to trade secrets as remote work, foreign vendors, and AI technology reshape the workforce. North Korean operatives have infiltrated over 100 U.S. firms using stolen American identities to hold remote IT positions, generating more than $5 million in illicit revenue, according to Foley & Lardner LLP. These schemes use 'laptop farms' in the U.S. where employer-issued devices enable overseas actors to access corporate networks, creating a facade of legitimate employment.
Employing fabricated identities, deepfake AI videos, and stolen credentials, these remote workers funnel wages to North Korea, violating sanctions, and complicating detection. As Skadden reports, the U.S. government saw a 220% increase in remote infiltrations leveraging generative AI in the past year.
Public AI platforms present additional vulnerabilities. Jay Heidrick warns that "employees’ use of public generative AI platforms can expose proprietary information and may undermine trade secret protection" if confidential business data is entered into these non-confidential tools. Meanwhile, AI agents can "harvest, synthesize, and exfiltrate trade secrets" covertly without triggering security alerts, as detailed by Baker Donelson.
Employees can further evade monitoring by photographing AI-generated screens with personal devices, increasing the risk of insider theft. North Carolina legal teams and corporate counsel must evaluate and strengthen safeguards around remote work, AI usage, and vendor relationships to mitigate these evolving threats, especially given potential regulatory penalties from unauthorized data access highlighted by Holland & Knight LLP.
By the numbers:
- 100+ U.S. companies infiltrated by North Korean operatives — via stolen identities in IT remote roles
- $5 million+ illicit revenue generated from identity fraud schemes using remote work
- 220% increase in companies infiltrated by North Koreans leveraging generative AI — within last 12 months