Apple's OpenAI filing: offboarding is a cloud problem
Apple alleges an ex-engineer pulled a confidential schematic from company cloud storage two months after leaving. Revoking the laptop is not revoking access.
Apple filed forensic evidence on August 31 in its trade secrets case against OpenAI, and the detail that should stop every operator cold has nothing to do with either company's size. Apple alleges a former engineer downloaded a confidential circuit schematic from Apple's third-party cloud storage two months after his last day. The badge was off. The account was not.
What actually happened
TechCrunch reported that Apple submitted findings from a forensic review tied to former senior system electrical engineer Chang Liu, now at OpenAI. Per MacRumors' read of the filing, Apple alleges Liu retained an Apple-issued MacBook after departing, that a confidential circuit schematic was pulled from Apple's third-party cloud storage in March, and that device sync between a Mac mini and the retained MacBook is what produced the evidence trail.
Apple further alleges Liu built an AI agent to drive LTspice, an electrical simulation tool, cutting a run from a full day to about two hours — and that after learning of Apple's investigation, he sent instructions to destroy evidence to an OpenAI colleague. Apple expanded its claims in August to cover 11 former employees. Judge Edward J. Davila is set to hear arguments on October 1.
These are allegations in an active case. Neither OpenAI nor the named engineers have been found liable of anything. Read the mechanism, not the verdict.
Why offboarding access control matters for your business
Apple has a security organization. It still took months and a lawsuit to notice. Your offboarding is a checklist in a shared doc, and it almost certainly stops at the same place Apple's did.
Here is the gap. Most teams treat offboarding as three items: collect the hardware, disable the email account, change the shared passwords. That covers your identity provider. It does not cover the twenty places a token was minted outside of it — a personal Dropbox or Google Drive that was granted access to a shared folder, a GitHub personal access token, a Stripe or QuickBooks invite accepted with a personal address, a CI secret, a .env file that synced to a laptop and then to a home machine. Sync is the part people miss. A file does not need to be exfiltrated if it is already replicating to a device you never had.
Four things worth doing this week. Inventory every SaaS tool that can be joined with a personal email, and audit membership quarterly instead of at departure. Kill tokens, not just logins — rotate API keys, revoke OAuth grants, and expire personal access tokens the same hour you disable SSO. Turn on access logging wherever you store documents, because Apple's case exists only because there was a log. Retrieve or wipe devices immediately; a retained laptop that still syncs is a live connection, not an asset recovery problem.
Twenty minutes of revocation now beats a forensic report later.
Key takeaways
- Apple alleges a confidential schematic was downloaded from its third-party cloud storage two months after the engineer left
- The alleged evidence trail came from device sync between a Mac mini and an Apple-issued MacBook the engineer retained
- Apple's August filings expanded the claims to 11 former employees; a hearing is set for October 1. All of it is unproven allegation
- Offboarding that stops at hardware and SSO leaves live tokens, personal-account grants, and syncing devices in place
Do you know every system a departed employee could still reach? We map access across your SaaS stack, cut tokens and OAuth grants down to what's actually needed, and turn offboarding into a script instead of a doc nobody finishes. Book an access audit or see what we build.
Sources: TechCrunch — Apple shares 'shocking evidence' against former employee accused of stealing company data for OpenAI, MacRumors — Apple Says Former Engineer Used Stolen Trade Secrets at OpenAI.
- #offboarding
- #insider-risk
- #access-control
- #cloud-storage
- #security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Defender falsely says it's off. Alert fatigue is the bug.
Microsoft confirmed Defender Antivirus shows false 'turned off' notifications you can't dismiss. Here's the PowerShell check, and why teaching staff to ignore alerts costs more than the bug.
Read itAustralia's data centre power rules: no carve-outs
Canberra will legislate a 100% renewable standard for AI data centres over state objections. Energy policy is now a cloud region variable — price it.
Read it