Apple’s trade secret lawsuit against OpenAI expanded on August 4, 2026 — the company’s latest court filing names 11 additional former employees who may have transferred confidential hardware secrets to OpenAI, bringing the total alleged participants to at least 13. The twist is that Apple’s own iCloud practices created the leak. By encouraging employees to merge personal Apple IDs with company-funded iCloud storage, Apple inadvertently left confidential documents syncing to personal iPhones long after those employees departed for OpenAI.
The iCloud Backdoor Apple Built Itself
Apple provided new hires with 2TB iCloud storage plans linked to their existing personal Apple IDs. Since an iPhone supports only one primary Apple ID for full iCloud sync, most employees merged their personal and work accounts rather than carry a second device. Apple introduced an “Apple Work” managed folder to revoke corporate access upon departure — but the folder didn’t capture everything. Files shared via iMessage, stored in ad-hoc shared directories, or saved outside the managed path remained mixed into personal iCloud storage and stayed there.
The damning detail: former employees weren’t just passively sitting on old files. According to reporting by The Information, some received real-time notifications when confidential Apple documents were updated — weeks after leaving the company. That’s active sync, not residual access. Apple, the company that built the world’s most recognizable privacy marketing, had enterprise cloud controls weaker than most startups’ MDM setups.
Related: Keyv npm Supply Chain Attack: Shai-Hulud Hits 2B Installs
Thirteen Employees and a Coordinated Pattern
The original July 10 lawsuit named two defendants: Chang Liu, a former senior systems electrical engineer who allegedly failed to return his Apple laptop and downloaded hundreds of confidential technical documents before leaving for OpenAI in January 2026; and Tang Yew Tan, OpenAI’s Chief Hardware Officer, who spent 24 years leading iPhone and Apple Watch product design at Apple. Tan is accused of using Apple’s confidential project code names during OpenAI recruiting and coaching departing employees on “how to evade the company’s security procedures.”
Tuesday’s court filing adds 11 more. One unnamed former employee allegedly met with Liu and Yu-Ting Peng before Peng’s OpenAI interview to share Apple proprietary information. Another took screenshots of confidential product planning documents specifically before sitting down with OpenAI. Apple is requesting expedited discovery from all parties and a preliminary injunction to bar OpenAI from using or disclosing any Apple IP. OpenAI responded: “We do not have, nor want, any of their trade secrets.”
Why OpenAI Specifically Wanted iPhone Secrets
OpenAI is building a direct iPhone competitor. The company acquired Jony Ive’s hardware firm io Products for approximately $6.5 billion in 2025 and is developing both a screenless AI companion device and a full AI phone. Tang Tan — who knows Apple’s hardware supply chain, manufacturing processes, and design decision history better than almost anyone outside Apple’s executive suite — leads that effort. The materials allegedly acquired from Apple include a proprietary metal finishing technique, physical hardware components (candidates were reportedly told to bring these to OpenAI interviews), CAD artifacts, and technical specifications for unreleased Apple products.
This reframes the entire case. The usual “rogue ex-employee” defense requires showing individual misconduct disconnected from company intent. When the Chief Hardware Officer is the alleged orchestrator, and when 13+ individuals across multiple teams show the same pattern, Apple is arguing this was OpenAI’s recruiting strategy — not an isolated incident.
The Enterprise Security Lesson Nobody Wants to Hear
Apple’s iCloud gap is not unique. Any company that lets employees use personal Google Drive, personal Dropbox, or personal iCloud to access work files faces the same structural vulnerability on offboarding. The legal stakes are compounding: under U.S. trade secret law, companies must demonstrate they took “reasonable measures” to protect secrets. If a court finds that Apple’s own iCloud policy made confidential files accessible to departed employees, Apple’s ability to enforce those secrets against defendants becomes legally complicated — a point Rivos (another company Apple previously sued over similar conduct) already raised in counterclaim.
The fix isn’t complicated but it requires enforcement: separate corporate credentials (Managed Apple IDs via Apple Business Manager, dedicated Google Workspace accounts with no personal sync), MDM-enforced device containers, and an offboarding checklist that explicitly revokes access to every cloud service — not just the obvious ones. If your company is using “connect your personal iCloud for work storage,” run this drill: can you confirm right now that a departed employee from six months ago cannot access any current work documents? For most teams, the honest answer is no.
Key Takeaways
- Apple’s own iCloud policy — linking employee personal Apple IDs to company storage — created a data access gap that persisted after employees departed, with some receiving live sync notifications on confidential documents.
- Apple’s lawsuit has expanded to 13+ former employees, with the latest filing alleging a coordinated pattern: candidates coached to bring hardware components, meetings to share IP before interviews, screenshots of unreleased product plans.
- The context matters: OpenAI is building a direct iPhone competitor, making Apple’s hardware IP directly valuable to its new hardware division led by a 24-year Apple product design veteran.
- Any company using personal cloud accounts for work faces the same offboarding liability. The iCloud “Apple Work” folder approach is insufficient — complete credential separation is the only reliable control.













