Extra production without Sideshow knowledge is quite possible (since I ordered one, I need to convice myself!).
I work in software/electronic in engineering and it is a reality when producing in China. We send our "recipe" and ask for X to be produced but we have no idea how many they will produce without our knowledge. It is so much a reality that all the firmware that we send (for QC tests) is a special firmware that can be used for tests only and is useless for real users. Once we receive the production we flash all the devices with the real firmware (that is a lot of work but we need to protect our technology). Also, different factories make different parts of our solution so that a single factory doesn't have all the components (even with a useless firmware).
I had a similar experience in my previous job. We built machines that inspected electronic devices for defects and we needed sample products to make our tests. Our main client was in Germany and they were really strict: they would lend us a sample but we had to send it back within a specific timeframe because it was owned by the company that requested that hardware, not the company that produced it. Let's say that experience was quite different in Asia, they didn't really care if the samples were not returned...