Former Apple Staff Retain Access to Confidential Files via Personal iCloud Accounts
Departed employees continue receiving updates for internal documents stored on personal iCloud, exposing gaps in offboarding security protocols despite permission revocations.
Woofun AI reports that Apple’s policy of allowing staff to use personal Apple IDs for work creates persistent data access risks. Although internal permissions are revoked upon departure, files stored on personal iCloud, iMessage, and unmanaged folders remain accessible and continue to receive update notifications. Several former employees confirmed they could still access internal documents years after leaving, denying any intent to retain data.
The vulnerability surfaced during litigation against OpenAI, where Apple accused two ex-employees of stealing unpublished product details and supply chain information. OpenAI denied the allegations. Apple clarified that the lawsuit targets intentional trade secret theft rather than the inadvertent retention of files on personal devices.
Comments
No comments yet.