Lambda Research Settled Export Control Violations
The firm avoided a $2 million penalty after admitting to 66 unauthorized software exports over four years.
Updated on Oct. 6, 2026 in Cybersecurity

Live Poll
Should the government enforce strict financial penalties on companies for unintentional export control violations?
The U.S. Bureau of Industry and Security has reached a settlement with Lambda Research Corporation for 66 export control violations occurring between 2021 and 2025. The company disclosed the breaches voluntarily in October 2025.
Why it matters
The settlement underscores the rigorous enforcement of export controls on software and maintenance subscriptions involving entities on the U.S. Entity List. It highlights the regulatory risks companies face when lacking formal compliance infrastructure.
The settlement involved 55 counts of prohibited conduct and 11 counts of acting with knowledge of a violation. The company must now appoint two compliance staff members and complete an audit within nine months to avoid the $2 million penalty.
The players
Bureau of Industry and Security
The U.S. agency responsible for regulating and controlling the export of sensitive goods and technologies.
Lambda Research Corporation
A technology firm that lacked formal export compliance programs during its period of unauthorized software distribution.
Huawei Technologies Japan
A subsidiary of the telecommunications conglomerate added to the U.S. Entity List in 2019.
Shenzhen SiCarrier Technologies
A technology entity added to the U.S. Entity List in 2024.
Sun Yat-Sen University
An academic institution whose laboratory received software licenses from Lambda Research in 2023.
The details
Lambda Research Corporation lacked written compliance procedures and trained staff, leading to unauthorized software and maintenance exports to Huawei Technologies Japan and Shenzhen SiCarrier Technologies. The company also sent software licenses to a Sun Yat-Sen University laboratory without required end-user documentation. The Bureau of Industry and Security suspended the financial penalty due to the company's limited ability to pay.
Timeline
2019: Huawei Technologies Japan was added to the U.S. Entity List.
2021-2025: Period of unauthorized exports to Huawei Technologies Japan.
2023: Software license exported to Sun Yat-Sen University.
2024: Shenzhen SiCarrier Technologies was added to the U.S. Entity List.
October 2025: Lambda Research Corporation voluntarily disclosed the violations.
The Tech Race
This settlement follows the enforcement patterns established by the Bureau of Industry and Security to maintain international technology restrictions. It marks a push to hold firms accountable for software updates and maintenance support sent to entities on the U.S. Entity List.
Lambda Research must train its compliance staff within three months and complete an internal audit within nine months. Failure to adhere to these mandates or additional breaches within one year will trigger the collection of the $2 million penalty.
The takeaway
The case illustrates the high cost of operating without defined export compliance, as regulators increasingly target software maintenance and update chains. Industry participants should monitor the Bureau of Industry and Security's ongoing enforcement actions for entities added to the Entity List.
Further reading
For broader trends in compliance and trade regulation, see the Cybersecurity section.
Source note: This article includes information reported by Global Sanctions.
Live Poll
Should the government enforce strict financial penalties on companies for unintentional export control violations?









