A traveller in an airport terminal. Stock photograph: Yousef Alfuhigi / Unsplash. The person pictured has no connection to the case.
Dr. Yunhai Li was eight days out of a job when U.S. Customs and Border Protection officers stopped him at Houston's George Bush Intercontinental Airport in July 2025, before he could board a flight to China. On his devices they found roughly 90 gigabytes of unpublished research: the working files of a breast cancer vaccine programme funded by the National Institutes of Health and the U.S. Department of Defense.
Li, 35, had worked at the University of Texas MD Anderson Cancer Center since 2022 on a vaccine designed to stop cancer from metastasising. By the time he resigned, the project was roughly 70% complete.
MD Anderson was not oblivious to the risk. Its security team had caught Li uploading confidential data to a personal Google Drive while he was still employed, confronted him, and watched him delete the files. What nobody at the institution knew was that a second copy already sat in a Baidu cloud account, on servers in China, beyond the reach of Western monitoring. The detection worked. The response worked. The theft happened anyway.
That is why the case repays close attention. The failure came years earlier, in the vetting that never happened before Li was given access.
The paperwork and the record
Li entered the United States on a J-1 research scholar visa. On joining MD Anderson he signed the standard confidentiality agreements and conflict-of-interest forms, certifying that he had no foreign research ties and no foreign funding. Those certifications were false.
Throughout his American appointment, Li remained on the books of the First Affiliated Hospital of Chongqing Medical University, which paid him a reduced salary through 2023 and held his position open for his return. He drew grant funding from the National Natural Science Foundation of China, and his name continued to appear on medical research published in China.
MD Anderson learned none of this from Li. Yet none of it was hidden in any meaningful sense. Publications are indexed, funding acknowledgements are printed on the papers themselves, and hospital affiliations sit in institutional directories. A structured open-source assessment before the collaboration began would have surfaced the contradictions, and forced the hard questions, while there was still time to act on the answers.
Two clouds
The method was not sophisticated. While still employed, Li uploaded confidential research data to his personal Google Drive. MD Anderson's monitoring flagged the transfer; when confronted, Li deleted the files and demonstrated proof of the deletion.
What the institution could not see was the parallel copy on Baidu's cloud service, hosted in China and outside any Western monitoring framework. Li then allegedly ran software to scrub evidence of the Baidu uploads from his devices.
After his arrest, in a sworn statement to investigators, Li acknowledged that he knew the files were sensitive and that he was not permitted to leave the country with them. He kept the Baidu copy, he said, precisely so that U.S. officials would not discover he had the data. The research was "going to waste," he told them; he intended to continue the work at his hospital in Chongqing.
The case is moving through Texas state court, and federal charges may yet follow. On the current counts, theft of trade secrets and tampering with government records, Li faces up to 11 years.
What 90 gigabytes costs
Cases like this are usually discussed in abstractions: sensitive research, national security implications, foreign interference. The arithmetic here is concrete. NIH and DoD grants of this kind typically run from $500,000 to several million dollars a year, and a project 70% complete could easily represent $3 to 5 million in direct federal investment before counting institutional matching funds, equipment, and facilities.
The commercial stakes are larger still. Oncology therapeutics routinely command licensing deals in the hundreds of millions, and a vaccine that prevents metastasis would sit at the top of that market. If the research is commercialised abroad, the institution that funded the development watches another entity capture the value.
Then come the slower costs. Federal funders now scrutinise institutional security practices, and program officers remember which institutions have had problems; a high-profile breach follows a university into its next grant cycle. MD Anderson is one of the world's premier cancer research institutions, and the case drew national media coverage along with uncomfortable questions about security at elite research universities. Taken together, the exposure from a single compromised collaboration can reach eight figures.
A structural weakness
This was not an isolated lapse by one compliance office. Most research institutions run conflict-of-interest checks on self-certification: researchers fill in forms, compliance staff screen the names against sanctions lists and restricted-entity databases, and if nothing flags, the collaboration proceeds.
The weaknesses compound. The system assumes honest disclosure from precisely the people with the strongest incentive to withhold it, and it mistakes database screening for intelligence. Checking a name against a list is not the same as understanding a researcher's network, funding relationships, and institutional obligations.
Nothing technical stands in the way of doing better. The material needed to assess partnership risk sits in open sources: publications, funding acknowledgements, patent filings, institutional directories, professional networks. What most institutions lack is the tradecraft to work through it systematically before the decision is made. Detection and response are the second line of defence. The first is not inviting the risk through the door.
The enforcement pendulum
The case landed in a charged regulatory environment. The U.S. Department of Justice's "China Initiative," launched in 2018 to counter economic espionage, was shut down in February 2022 amid criticism that it disproportionately targeted ethnic Chinese researchers, often over administrative lapses rather than misconduct. MIT Technology Review, reviewing 77 identified cases, found that fewer than a quarter ended in conviction, and that most charges against university employees involved disclosure failures rather than espionage or trade secret theft.
The Li case is different in kind: a physical interception at an airport, digital forensics, and the researcher's own sworn admissions. But the institutional lesson holds wherever the enforcement pendulum happens to sit. International collaboration creates exposure; some partners present more of it than others; funders increasingly expect demonstrated diligence; and an institution that cannot show it took reasonable steps will bear the consequences whether or not anyone is prosecuted.
The question facing research leaders is not whether to collaborate internationally. Collaboration is where scientific progress comes from. The question is whether the processes exist to tell high-risk partnerships from routine ones before institutional resources and reputation are committed.
Moving the assessment forward
Prevention is a matter of sequence: the serious evaluation has to happen before access is granted, not after. In practice, that means a genuine open-source review of a prospective collaborator's publication network, funding acknowledgements, affiliations, and professional history, rather than a pass through the sanctions lists. It means checking self-reported disclosures against what the record independently shows; a discrepancy is not proof of bad faith, but it is grounds for a direct conversation. It means calibrating scrutiny to risk, because a visiting scholar on basic research is not the same proposition as a postdoctoral fellow with access to federally funded applied work of commercial value. And it means documentation a third party can stand behind, because funders increasingly want evidence of genuine diligence rather than ticked boxes.
None of this treats international researchers as suspects. The point is consistent, professional evaluation of any collaboration that touches sensitive research, whatever the researcher's nationality. The same assessment that would have flagged Li's undisclosed affiliations also clears, with documentation, the far larger number of researchers who have nothing to hide.
The asymmetry
The economics of prevention are lopsided. Proper due diligence costs thousands of dollars and a few weeks. A compromised collaboration costs millions, years of lost work, strained relations with funders, and a reputation that took decades to build.
MD Anderson had protocols. It detected an exfiltration attempt, confronted the researcher, and watched him delete the files. Ninety gigabytes of federally funded cancer research reached the departure gate anyway. Monitoring matters, but it is the second line. The first is knowing who is walking through the door before handing them research that took years to develop and millions to fund. That assessment never happened. It is the one that would have counted.
Sintra Advisory provides independent collaboration risk assessment for research institutions navigating sensitive international partnerships. We evaluate partnership risks, develop mitigation strategies, and deliver third-party validation that funders trust. To discuss your institution's approach to collaboration security, schedule a conversation.
Sintra Advisory