Executive Summary
On September 13, 2026, South Korea’s revised Criminal Act took effect, and with it the meaning of the word “espionage” in Seoul changed. For decades, South Korean espionage law applied, in practice, only to acts benefiting North Korea — the “enemy state” of Cold War-era statute. The amendment passed by the National Assembly on February 26 creates a new, general offence: spying for any foreign country or equivalent organization, carrying a minimum sentence of three years in prison. The target is not Pyongyang’s agents. It is the slow, quiet hemorrhage of semiconductors, displays, batteries, and AI technologies — the crown jewels of the Korean economy — to foreign competitors, above all China.
This analysis argues that Seoul has just authored the sharpest legal expression yet of the defining doctrine of our era: economic security is national security. Where Washington’s export controls try to dam the flow of technology at the border, South Korea has moved the chokepoint into the courtroom — criminalizing the leak itself as espionage rather than misappropriating a trade secret. The model is deliberate, born of a decade of humiliating cases in which engineers walked DRAM process recipes out of Samsung in handwritten notebooks and walked away with sentences averaging under a year. The question now is whether the criminal-code deterrence model can do what the old regime could not: make the world’s most talented semiconductor workforce think twice before taking a better offer abroad — and whether Washington, Taipei, and Tokyo will follow Seoul’s lead.
1. What Changed on September 13
The facts are simple and the change is sweeping. South Korea’s revised Criminal Act took effect on Sunday, September 13, Reuters reported from Seoul, broadening espionage offences beyond acts involving North Korea to include espionage for all foreign countries. The National Assembly passed the amendment on February 26 after years of criticism that existing laws were ill-suited to punish technology and industrial espionage involving non-North Korean actors; promulgated on March 12, it took effect after a six-month grace period on September 13.
The operative change: a new offence covering espionage for “a foreign country or equivalent organisation,” carrying a minimum three-year prison sentence. The old provisions — espionage benefiting an “enemy state,” i.e., North Korea — remain in place. What changed is everything around them: the law now recognizes that a South Korean engineer passing DRAM process technology to a Chinese competitor is committing the same category of act as a North Korean agent passing military secrets to Pyongyang. The victim is the state in both cases; only the beneficiary has changed.
Under the previous law, prosecutors in cases involving foreign governments or companies were forced to rely on other industrial-technology or trade-secret laws. This was not a minor procedural inconvenience. It was the central failure of the old regime — and the cases that exposed it are why the amendment exists.
The National Intelligence Service welcomed the amendment when it passed, saying it would strengthen South Korea’s ability to prevent leaks of strategic technologies such as semiconductors, displays, batteries, and AI. Legal and security experts described it as closing a longstanding loophole that often left advanced industrial-technology leak cases subject to lighter penalties, with supporters arguing it will strengthen deterrence against industrial espionage. The framing matters: this is deterrence through the criminal code, not through the export-control list.
2. The Cases That Forced the Change
Laws like this are not written in the abstract. They are written in the image of particular humiliations.
The signature case is the one Reuters covered last December: South Korean prosecutors indicted ten people on suspicion of leaking memory-chip manufacturing technology to China’s ChangXin Memory Technologies (CXMT) — a case authorities say helped pave the way for China’s development of high-bandwidth memory (HBM), the critical component at the heart of AI computing infrastructure.
The details read like a counterintelligence briefing from another century. A former Samsung Electronics researcher, leaving his job to join CXMT, copied out hundreds of steps of proprietary DRAM manufacturing processes by hand — recording detailed process recipes covering equipment specifications, sequencing, and yield optimization. Handwritten notes, later used to reconstruct the manufacturing flow at CXMT. The Seoul Central District Prosecutors’ Office said five people, including the former Samsung executive and engineers, were charged and held in custody for violating South Korea’s industrial technology protection law, while five more were charged but released on bail.
The technology was 10-nanometer DRAM that Samsung had spent 1.6 trillion won developing — and at the time, prosecutors said, Samsung was the only firm in the world to have commercialized it. CXMT subsequently adjusted and validated the stolen data to suit its own equipment, achieving production of 10-nanometer DRAM in 2023, the first such achievement by a Chinese firm. The illegal use of the technology, prosecutors said, laid the groundwork for CXMT’s development of HBM. The losses for companies such as Samsung Electronics were estimated at at least tens of trillions of won.
And the critical detail: CXMT had also obtained additional DRAM technology from SK Hynix through a supplier. The leak was not an isolated betrayal but a pipeline — and the punishment available under the old legal framework treated it as something closer to a contract dispute than an attack on the state.
This was not an anomaly. Police announced in 2024 that they had uncovered a record 25 cases of technology leaks to foreign countries in that year alone — the highest number since the National Investigation Headquarters was established in 2021, with China accounting for 18 of the 25, the United States for three, and Germany, Vietnam, Iran, and Japan one each. Ten of the 25 involved critical technologies related to national security, itself a record. Around 32 percent of the illegally shared technologies were display-related; 28 percent were semiconductors. Another case that year involved a former Samsung executive accused of leaking trade secrets valued at 4.3 trillion won to establish a copycat chip factory in China.
The pattern was unmistakable: a small country that dominates the memory-chip market — Samsung and SK Hynix are the world’s top two DRAM producers — was bleeding its most valuable intellectual property to the country working hardest to replace it, and its criminal law could barely register the offense.
3. Why the Old Laws Failed
The core problem was architectural. South Korea’s espionage statute was a Cold War instrument pointed in one direction — north — while the actual threat had rotated 180 degrees toward the supply chain. Prosecutors dealing with leaks to Chinese firms had to fall back on the Industrial Technology Protection Act and trade-secret provisions, which carried lighter penalties and, more importantly, lacked the moral and deterrent weight of an espionage charge.
How light? Reporting on the trade-secret cases noted that from 2018 to 2022, offenders under South Korea’s Industrial Technology Protection Act received an average sentence of just 10.7 months. Ten months, on average, for stealing the process technology that cost trillions of won and years of R&D to develop — technology that a foreign competitor could use to shave years off its own development timeline. By contrast, the United States and Taiwan already classify such crimes as acts of espionage, imposing far harsher punishments.
This is the arithmetic that broke the old regime. Deterrence is a function of probability and severity: the probability of getting caught for technology theft is low (the USB drive, the handwritten notebook, the photographed document are hard to police), so the severity must be high to compensate. The old law inverted the formula — low detection, light punishment — and the result was predictable: a steady, rational stream of leaks to the highest bidder. The three-year minimum sentence in the new law is not cruelty; it is deterrence math finally being taken seriously.
There is a second, subtler failure the new law addresses. Trade-secret law is private law — it protects the company. Espionage law is public law — it protects the state. Moving chip-technology leaks into the criminal espionage framework is a declaration that Samsung’s DRAM process recipes and SK Hynix’s hybrid bonding technology are not merely corporate assets but national assets, and that their theft is an injury to the Republic of Korea itself. That reclassification has consequences beyond sentencing: it unlocks the investigative powers, intelligence resources, and prosecutorial priorities of the national security apparatus.
4. The Global Pattern: Espionage as the New Grammar of Tech Competition
Seoul did not invent this move. It joined a pattern that is rapidly becoming the grammar of 21st-century technology competition.
The United States wrote the first draft decades ago with the Economic Espionage Act of 1996, which criminalized the theft of trade secrets for the benefit of a foreign government — making America one of the first countries to treat economic spying as a federal crime on par with classic espionage. Washington has since built an entire enforcement architecture around it: the FBI’s counterintelligence divisions, the Commerce Department’s export-control lists, and the sanctions-and-Entity-List apparatus that this publication covered last week in its analysis of the AA26-251A distillation advisory, where the Trump administration is now threatening Chinese AI firms with sanctions for “industrial-scale” theft of American AI technology.
Taiwan has moved in parallel, amending its National Security Act to stiffen penalties for technology theft and expanding the definition of protected “national core critical technologies” — a direct response to cases of Chinese poaching of Taiwanese semiconductor engineers, the now-notorious “red supply chain” talent raids. China itself expanded its counterespionage law in 2023 to cover a broader range of activities and data, giving state security organs sweeping new powers — the mirror image of Seoul’s law, pointed in the other direction.
What is new about the Seoul amendment is its direction of travel. Beijing’s counterespionage expansion is a shield, aimed at keeping foreign intelligence out. Washington’s regime is a chokepoint strategy, aimed at keeping American technology in — export controls, deemed-export rules, Entity Lists. Seoul’s law is something else: a deterrence instrument aimed at its own citizens, criminalizing the act of leaving. It treats the Korean semiconductor engineer as the asset to be defended and the potential defector as the threat — and it puts the state’s heaviest criminal label on the wrong choice.
This is the criminal-code deterrence model in its purest form, and it is philosophically distinct from the American approach. Washington says: we will punish the foreign recipient. Seoul says: we will punish our own leaker, and we will call it espionage.
5. Deterrence by Courtroom: The Logic — and Limits — of Seoul’s Choice
Why did South Korea choose the courtroom over the export-control office? Because its leverage is different. The United States can deny the world advanced chips; it controls the chokepoints. South Korea does not control chokepoints — it is the chokepoint’s content. Korean firms make the memory; the memory is the product. You cannot export-control what is already in your own engineers’ heads, and you cannot Entity-List a handwritten notebook. The only instrument available to a country whose crown jewels are its people’s knowledge is the criminal law applied to its people.
There is a cold logic to it. The semiconductor talent market is global, and the wage gap between a Samsung process engineer in Giheung and a CXMT offer in Hefei is measured in multiples. No trade-secret injunction bridges that gap; only the credible threat of a multi-year prison sentence changes the expected value of the decision. The three-year minimum is the state entering the labor market as a counterbidder — not with money, but with fear.
But the model has limits, and honest analysis requires naming them.
First, deterrence requires detection. The law is only as strong as the NIS’s and prosecutors’ ability to find the leaks, and the history here is discouraging: the cases that get prosecuted are the careless ones. The sophisticated exfiltrator — the engineer who memorizes rather than photographs, who leaves slowly rather than all at once — remains hard to catch. A three-year minimum deters the marginal leaker, not the professional operation.
Second, overbreadth is a real risk. “Espionage for a foreign country or equivalent organisation” is a broad phrase, and its application to legitimate cross-border scientific collaboration, academic mobility, and the normal circulation of technical talent will require prosecutorial restraint that is not written into the statute. South Korea’s semiconductor dominance depends on its engineers moving, publishing, and collaborating internationally. A law that chills that circulation could protect the crown jewels while slowly starving the kingdom.
Third, the law is asymmetric in a way that may not survive contact with reality. It criminalizes the Korean engineer who leaks to a foreign firm, but the foreign firm that receives the technology — CXMT in the Samsung case — faces no Korean jurisdiction. The deterrence falls entirely on the supply side of the transaction, while the demand side — the Chinese state-backed firms offering the multiples — operates with impunity. Unless paired with allied cooperation (more on this below), the law punishes the symptom’s weakest link.
Fourth, and most politically sensitive: the National Intelligence Service just got more powerful. The NIS welcomed the amendment, which tells you something. Expanding espionage law in a country with a living memory of authoritarian-era intelligence abuses — the NIS’s predecessors were instruments of political surveillance — requires democratic guardrails that the current debate has barely begun. The law’s supporters emphasize deterrence; its skeptics will rightly ask who watches the watchers.
6. What This Means for Washington — and the Alliance
For the United States, the Seoul amendment is both a gift and a challenge.
The gift: Washington has spent four years building a technology-containment architecture around China that depends on allied cooperation — export controls that work only if the Netherlands, Japan, Taiwan, and South Korea enforce them; Entity Lists that bite only if allied firms comply. South Korea has now gone further than Washington asked, criminalizing at the source what American export controls try to block at the border. The two models are complementary: the U.S. punishes the recipient, Seoul punishes the leaker, and together they close the loop that either alone leaves open.
The challenge: the American model increasingly asks allies to absorb economic costs for American security — to restrict their own firms’ access to the Chinese market in the name of a containment strategy designed in Washington. Seoul’s law shows an ally taking ownership of the problem on its own terms, for its own reasons. That is healthy for the alliance, but it also means Washington cannot take Korean cooperation for granted or dictate its terms. The “Seoul Doctrine” is Korean statecraft, not American delegation.
There is a concrete agenda here. The United States and South Korea should now negotiate reciprocal enforcement cooperation on technology-espionage cases: intelligence sharing on talent-poaching operations, coordinated prosecution where jurisdiction overlaps, and common standards for what counts as a protected strategic technology. The CHIPS and Science Act era showed that industrial policy without allied coordination leaks; the espionage era will show the same about criminal policy. A Korean engineer convicted in Seoul and a Chinese firm sanctioned in Washington for the same technology transfer would be the first true demonstration that the democratic world’s economic-security regime is one system, not a collection of national gestures.
And there is a warning for American policymakers in Seoul’s example. The United States still relies overwhelmingly on the export-control chokepoint — a strategy this publication argued last week is already being outflanked at the API endpoint, where American AI models are being systematically harvested. Seoul’s insight is that when the asset is knowledge, the defense must follow the knowledge — into the workforce, into the courtroom, into the criminal code. Washington’s technology-security strategy remains, at its core, a border strategy. Borders are where the 20th century kept its secrets. The 21st century keeps its secrets in people’s heads, and Seoul just became the first American ally to legislate accordingly.
Conclusion: The Criminalization of Technology Transfer
September 13, 2026 will be remembered as the day South Korea stopped treating the theft of its technology as a business dispute and started treating it as an attack on the state. The expanded espionage law is the sharpest legal expression yet of the doctrine that now governs great-power competition: economic security is national security, and the semiconductor engineer is a strategic asset whose knowledge is protected by the full weight of the criminal law.
The model will be watched — and copied. Taiwan has already moved in this direction; Japan’s economic-security legislation points the same way; and Washington, which invented the concept of economic espionage as a federal crime, will study whether its own regime needs the same update Seoul just enacted. The question is not whether other technology-leading democracies will follow. It is how fast, and whether they will coordinate or merely imitate.
Two cautions should travel with the applause. First, a deterrence regime aimed at a country’s own citizens is a delicate instrument: applied with precision, it protects the national interest; applied carelessly, it chills the scientific openness that made the interest worth protecting. South Korea’s semiconductor miracle was built by engineers who studied abroad, collaborated internationally, and brought knowledge home. The law must not criminalize the circulation that created the thing it protects.
Second, no criminal statute, however severe, substitutes for the harder work: paying and retaining the talent, securing the supply chains, and building the allied enforcement cooperation that makes a single country’s law part of a system. Deterrence by courtroom is a necessary condition. It is not a sufficient one.
Seoul has thrown down the gauntlet — not to Beijing, but to every capital that claims to take economic security seriously. The criminalization of technology transfer has begun. The race now is to build the rest of the regime around it.
Vladimir Tsakanyan is a cybersecurity policy analyst and political commentator covering cyber diplomacy, geopolitical threat intelligence, and the intersection of technology and national security.
Sources: – Reuters, “South Korea’s expanded espionage law takes effect amid push to protect chip technology,” September 13, 2026 — https://www.reuters.com/world/china/south-koreas-expanded-espionage-law-takes-effect-amid-push-protect-chip-2026-09-13/ – Reuters (via Communications Today), “South Korea charges 10 over alleged chip technology leak to China’s CXMT,” December 2025 — https://www.communicationstoday.co.in/south-korea-charges-10-over-alleged-chip-technology-leak-to-chinas-cxmt/ – Korea JoongAng Daily, “Police uncover record 25 technology leaks to foreign countries this year,” November 2024 — https://koreajoongangdaily.joins.com/news/2024-11-25/national/socialAffairs/Police-uncover-record-25-technology-leaks-to-foreign-countries-this-year/2185524 – TrendForce, “Semiconductor Tech Leaks Heat Up: Latest on Samsung, SK hynix, and TSMC Trade Secret Cases,” October 2025 — https://www.trendforce.com/news/2025/10/09/news-semiconductor-tech-leaks-heat-up-latest-on-samsung-sk-hynix-and-tsmc-trade-secret-cases/


Leave a comment