Apple sued Chang Liu, a former employee, for stealing trade secrets when he left Apple to work for OpenAI.
According to the allegations contained in Apple's lawsuit, Liu, a senior system electrical engineer, left the company in January to work at OpenAI. After leaving, the engineer failed to return at least one laptop, on which he had discovered an authentication bug that allowed him to access Apple's internal network storage. Once accessed, the storage revealed confidential engineering documents.
The engineer allegedly did not report this bug. Instead, Apple alleges he contacted an employee who still worked at Apple and instructed her on how to access and copy even more confidential files for his use. Later, that employee also left Apple to work for OpenAI after studying specific confidential Apple files ahead of her interview at the urging of Liu.
Source: https://finance.yahoo.com/technology/ai/articles/lol-funny-apple-says-ex-190000424.html
Commentary
Organizations may be monitoring for theft of all kinds, including trade secrets, when an employee is fired or leaves on bad terms. However, neutral, and even amicable, departures should not be overlooked as relates to the potential for trade secret theft.
Employees who leave to pursue other opportunities often are acutely aware of where their former employer kept valuable files. They may retain credentials or access keys, or they may know of bugs in the system that would allow continued access even if all exit protocols were correctly followed.
To help reduce the risks of trade secret theft when an employee leaves, organizations should:
· Suspend credentials, access tokens, hardware access, and more the moment notice is given by the departing employee
· Regularly conduct security audits to detect and fix any bugs that would leave a pathway open to company files even when access is revoked
· Review the leaving employee's file access, download activity, printing, and email during the 90 days prior to their departure
· Forbid sharing of company devices, credentials, tokens, or any other access pathways between current and former employees
· Preserve any non-disclosure agreements where applicable and document the employee's exit interview records
· Never fail to engage in the above protocols simply because an employee is believed to be "friendly" or "harmless" when they depart
The final takeaway is that trade secret theft by departing employees often flies under the radar and the losses may not be realized until long after the employee is gone. Organizations that stay proactive and engage thorough departure protocols are better prepared to reduce the risks.
