How an Apple iCloud Policy Fueled Employee Leaks Ahead of OpenAI Suit
Resumo
Mais de 400 ex-funcionários da Apple que trabalham na OpenAI continuaram tendo acesso a documentos confidenciais da Apple após sair da empresa através do iCloud, gerando situação delicada onde ex-funcionários de outras companhias também enfrentaram o mesmo problema de sincronização automática em dispositivos pessoais.

In a lawsuit early last month, Apple accused former employees who are now at OpenAI of stealing a trove of trade secrets from the iPhone maker—in part by improperly accessing confidential Apple documents after they left the company. Even before the suit was filed, some of the more than 400 former Apple employees who now work at OpenAI began receiving stern letters from Apple lawyers informing them they were in possession of confidential Apple material, people familiar with the matter said.
But the reason many of them had access to that material was due to an Apple policy, not because the former employees were attempting to steal its secrets, the people said. The issue: Even though Apple kicked them off most of its corporate systems after they resigned, the former employees continued to have access to Apple files shared with them when they still worked there.
It isn’t just Apple alums at OpenAI who have encountered this awkward situation. More than half a dozen former Apple employees who left for other companies over the past decade told The Information they, too, continued to have access to confidential documents after leaving the company, even though they made no effort to do so.
The former employees said many Apple files they had been shared on over their careers at the company—including planning documents for product launch events—continued to sync to their personal devices through the iCloud storage service after they left Apple. In some cases, they even received notifications about fresh updates to the documents. Some former employees said they were petrified to delete the files for fear that doing so would attract Apple’s attention.
The apparent lapse in Apple’s security practices is at odds with its reputation as a ferociously secretive company. Apple is well known for its aggressive internal hunts for and litigation against leakers and ex-employees whom it suspects of taking its secrets to other companies. “The trade secrets spanning Apple’s hardware operations collectively constitute one of the most valuable intellectual assets in all of American business,” Apple said in the lawsuit it filed against two former employees, Chang Liu and Tang Tan, and OpenAI last month.
Apple could well have a strong case against OpenAI. In its complaint, it accuses Liu and Tan of various deliberate efforts to violate its trade secrets, with the goal of helping OpenAI compete with Apple in the hardware business.
For example, in the suit, Apple alleges that Liu exploited a “rare, previously unknown” security bug to gain access to the company’s shared network folders after he left Apple, downloaded dozens of confidential files and bragged about it to a colleague. And it accused Tan of emailing himself confidential Apple documents before leaving the company and, after joining OpenAI, soliciting trade secrets from Apple people he was recruiting.
OpenAI has denied that it or its employees engaged in theft of trade secrets. “We have no interest in other companies’ trade secrets,” an OpenAI spokesperson said in a statement shortly after Apple filed its lawsuit. “While we take these allegations seriously, we’re not aware of any evidence that this complaint has merit.”
In a statement, Apple said: “This case is about OpenAI employees wrongfully taking Apple’s secret and confidential information regarding our unreleased technologies, processes, and products. Nothing in the filing relates to documents shared by, or stored in, iCloud.” The company said it doesn’t pursue legal claims against former employees who accidentally hold on to Apple documents in their personal iCloud accounts.
Former Apple employees say an unusual company policy that encourages them to blend professional and workplace technologies is why they unexpectedly ended up with access to confidential files after their departures.
When new employees join Apple, the company often issues them an iPhone and Mac and pays for an iCloud account with a large amount of online storage capacity. Crucially, during the onboarding process, Apple encourages new hires to use their preexisting personal Apple IDs with this iCloud account, through which their co-workers can share internal Apple documents and other files with them.
There’s a practical reason for Apple’s policy. Users of iPhones can only log into a single primary Apple ID that unlocks all iCloud capabilities at a time. Apple employees who want to maintain separate work and personal Apple IDs need to carry two iPhones with them. As a result, most Apple employees opt to use their personal Apple IDs to access their iCloud accounts, former employees said.
When employees leave Apple, the company revokes access to a dedicated iCloud directory for Apple work files, as well as an authentication system for logging into other internal services, such as Slack. But former employees say the company doesn’t do a thorough job during the offboarding process of looking for confidential files that have slipped through the cracks. Because those former employees typically continue to use their personal Apple IDs with their iCloud accounts, any Apple documents stored outside workplace directories remain available to them.
The striking contrast between that lapse and Apple’s stance on corporate security has fueled speculation that the company lets former employees leave with confidential materials on purpose. In 2023, Rivos, a chip startup that had recruited former Apple employees, accused Apple in a court filing of using that tactic deliberately to intimidate people who have either left Apple already or are contemplating leaving.
“Whether by neglect or as part of a planned effort to generate a pretextual basis to sue the employees and their new employer for ‘stealing’ Apple material, Apple lets these employees walk out the door with material they may have inadvertently ‘retained’ simply by using the Apple systems (such as iCloud or iMessage) that Apple effectively mandates they use as part of their work,” Rivos said in a counterclaim to a lawsuit that Apple had filed against the startup, accusing it of theft of trade secrets.
It’s hard to find a tech company more dedicated to secrecy than Apple.
The company prefers to keep an air of mystery around itself and attempts to minimize leaks ahead of announcing new products. Its trade secrets, the company said in its lawsuit against OpenAI, “enable Apple to bring new products with unique features to consumers at extraordinary speed and scale.”
Apple is particularly focused on preventing secrecy in its supply chain. In the 2000s and early 2010s, its leaders were furious about a series of leaks from the Asian factories that assemble and make the parts for its iPhones. In 2013, for instance, a warehouse worker at one of Apple’s top suppliers, Jabil, stole casings for the iPhone 5c, The Information previously reported. Images of the casings soon appeared on the internet, spoiling Apple’s public reveal of the new device.
Similarly, in the U.S., Apple workers are subject to an array of strict security protocols. Many of its teams operate in information silos, unaware of what their colleagues are working on. The company drills the importance of secrecy into staffers through training, confidentiality agreements and product code names.
That’s why the consequences of its decision to encourage employees to use their personal Apple IDs at work are so notable.
Apple takes pride in using the same technology it makes for consumers to run its own operations. Apple workers collaborate in shared documents using Apple software, such as its Pages word processing and Keynote presentation apps. In addition to email, iMessage is a popular way for Apple employees to communicate with each other and share files.
Apple’s iCloud online storage is central to how the company collaborates internally on projects. When a new employee joins, Apple gives employees 2 terabytes of iCloud Drive space at no cost and asks if they want to merge the additional capacity with their existing iCloud plan or access it from a separate account, according to former Apple employees.
Other big companies have stricter IT policies that allow them to more completely revoke access to workplace files once employees leave. Even when companies permit employees to log in to their personal iCloud accounts from work-issued MacBooks, for example, they encourage those employees to share files with colleagues in ways that make it easier to police those files when they depart.
In the late 2010s, Apple introduced a new Apple-managed folder for workplace files that lives in employees’ iCloud accounts. The folder was designed to make it easier for the company to delete confidential material from people’s systems when they leave. As soon as they hand in their employee badges, the Apple Work folder vanishes from their accounts.
The problem is that while people are still employed at Apple, many internal documents aren’t automatically saved to that folder, former employees say. Many shared Apple files end up outside the folder, mixed with personal photos, documents and other files in the employee’s iCloud account.
For a time, it is also commonplace at Apple for teams to use iMessage chats to communicate with each other and share confidential files. In some cases, that has resulted in staffers retaining access to those chats and files even after they left Apple, according to former Apple employees. Around 2019, Apple attempted to partly remedy this issue by rolling out the Slack messaging tool; as soon as Apple staffers leave, they lose access to their Apple Slack accounts.
Apple’s offboarding process for some employees appears to be more thorough than for others. When more senior Apple leaders leave the company, an Apple staffer often sits down with them to review their devices and make sure confidential files don’t remain on them, former employees said. But for rank-and-file staffers who leave, the experience is more perfunctory, the people said.
In the case of the flood of former Apple employees who have gone to OpenAI, some of them have opted to skip Apple’s offboarding process entirely, Apple said in its July lawsuit. “Apple has observed a recent trend of employees who are leaving Apple for OpenAI and taking steps to evade security measures,” Apple’s lawsuit said. “This includes ignoring outreach by security personnel to schedule exit processes and security reviews.”
In the past, the blending of personal and work identities at Apple has become a centerpiece of lawsuits against smaller companies.
In 2019, a chip startup called Nuvia, which was working on an efficient processor for data center servers, began heavily recruiting from the ranks of Apple’s semiconductor team. Apple soon sued Nuvia co-founder Gerard Williams, one of several former Apple employees who formed the company. It accused him of breaching his Apple employment contract by starting the concept for Nuvia and recruiting Apple employees while he was still employed at Apple.
Apple’s complaint was filled with copious details about Williams’ personal communications with other people, including non-Apple employees. Even before any legal discovery took place, Apple had extensive phone and text records showing his communications with Nuvia co-founders and external investors. The complaint contained a precise tally of Williams speaking with two co-founders “at least 88 times for a total of 2,361 minutes” between October and December 2018.
In a counterclaim, Williams later alleged that Apple was attempting to intimidate future employees who might consider leaving for Nuvia by monitoring their phone logs and text messages. In the filing, lawyers for Williams called it “a stunning and disquieting invasion of privacy.”
Apple settled with Nuvia in 2023.
When chip startup Rivos formed in 2021 and began recruiting from Apple’s semiconductor engineering ranks, those staffers took precautions to avoid the legal entanglements that befell Nuvia. They messaged each other in Signal, an encrypted chat app, about their plans to join Rivos, rather than using iMessage, former Apple and Rivos employees said. They also attempted to make sure any confidential Apple files on their devices were stored in their Apple Work folders or on a corporate account for the Box storage service so they wouldn’t have access if and when they left the company, the people said.
Despite those efforts, Apple still sued Rivos in 2022 after the startup hired more than 40 Apple chip employees. In its lawsuit, Apple accused some Rivos employees of taking gigabytes of sensitive information about Apple’s proprietary chip technology with them after they left the company.
Apple’s complaint alleged that some employees used USB storage devices to download the material, while others saved presentations on existing and unreleased Apple chips to their personal iCloud drives.
In court filings, Apple accused one former employee of retaining work files in his personal iCloud after his departure for Rivos, even after he moved thousands of those files to a work folder. Apple accused another employee of copying terabytes of information from his Apple work laptop to an external storage device. But the employee did so using Time Machine, a Mac feature that automatically backs up files and documents, and hadn’t accessed the files, a person familiar with the matter said.
Apple and Rivos settled the case in 2024. But the damage was done: Rivos struggled to recruit more Apple staffers after the lawsuit, people familiar with Rivos’ hiring said. Meta Platforms acquired Rivos for a reported $2 billion late last year.