Apple Lawsuit Highlights Risks in Employee Offboarding and Data Access

Apple alleges that a former engineer who had already joined OpenAI exploited a previously unknown authentication flaw to keep reaching internal storage and download confidential hardware files. The July 10 complaint is not a court finding, but it gives security teams a concrete offboarding lesson: disabling an account is not enough unless devices, credentials, sessions, storage permissions, and post-departure activity are all verified.
Apple filed a federal complaint on July 10 accusing OpenAI, io Products and two former Apple employees of trade-secret misappropriation and breach of contract. The claims are allegations, not findings; the case was newly filed and the court had not ruled on liability at the time of this audit.
What Apple alleges
The complaint says Chang Liu left Apple for OpenAI in January 2026 without returning an Apple-issued laptop. Weeks later, Apple alleges, he discovered that a previously unknown authentication flaw still let him reach shared network folders. Apple says Liu used that access while working for OpenAI to download dozens of confidential hardware files, including material about unreleased products, engineering specifications and project data.
Apple also alleges that Liu used a then-current employee's Apple device and advised that colleague about copying materials and preparing for an OpenAI interview. Separately, the complaint accuses OpenAI hardware chief Tang Tan of using Apple project code names in recruiting, asking candidates to bring hardware components to interviews, and circulating an internal Apple document about departure-security procedures.
Apple says it fixed the authentication flaw after discovering it. The complaint states that server logs showed a few other users could have been affected, but that those users did not appear to have accessed or taken confidential information. OpenAI said publicly that it has no interest in other companies' trade secrets and remains focused on building its own technology.
Why offboarding controls matter
For security and data teams, the practical issue is not whether a termination ticket was marked complete. It is whether every path to sensitive systems was actually closed. That includes managed devices, identity-provider sessions, VPN and storage tokens, service credentials, shared-folder permissions, delegated access, and applications whose authorization state may outlive the central account.
LDS interpretation: high-risk departures should pair immediate access revocation with device recovery, session invalidation, a review of recent downloads, and short-term alerts for post-departure authentication or data movement. Logs should be preserved because they may be needed both for incident response and later legal review.
What remains unproven
The complaint is Apple's account of the events. It does not establish that the defendants are liable, that every file Apple describes reached OpenAI, or that the alleged information shaped a product. Those questions would require evidence and court proceedings. The useful operational takeaway is narrower: offboarding controls should be tested against residual access, not assumed effective because a worker's status changed.
Key Points
- 1Apple alleges a former engineer retained access after leaving and used an authentication flaw to download confidential hardware files while employed by OpenAI.
- 2The complaint says Apple fixed the flaw and found no similar access by the few other potentially affected users, but the allegations have not been adjudicated.
- 3For practitioners, offboarding should verify device return, revoke sessions and tokens, review downloads, preserve logs, and monitor for post-departure access.
Scoring Rationale
The newly filed complaint presents a credible, specific example of residual-access and offboarding risk at two major technology companies. Its practitioner value is meaningful for identity, endpoint, and data-security teams, but the claims remain unproven and the operational lessons are established security practice rather than a new technical development.
Sources
Primary source and supporting public references used for this report.
Practice with real Ad Tech data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Ad Tech problems

