Professional headshot of the former Apple engineer accused of using a login glitch to download confidential files for OpenAI after leaving the company.
Portrait of the former Apple engineer at the center of the OpenAI trade-secret lawsuit.

Apple is suing a former engineer who allegedly used a login glitch to steal secrets for OpenAI

Think your company files are safe after an employee leaves? 😳 Apple is suing an ex-engineer who allegedly used a simple login bug to download secrets long after quitting. Here is why proper offboarding is a must 👇 #Apple #Cybersecurity #TechNews


Advertisements

MANILA, Philippines (Jul 2026) — A recent lawsuit filed by Apple highlights a massive cybersecurity nightmare: how a former engineer allegedly used a login glitch to download confidential files weeks after leaving the tech giant.

The legal complaint, filed on July 10, 2026, accuses Chang Liu, a former senior electrical engineer, of stealing trade secrets before leaving for rival artificial intelligence company OpenAI in January 2026. According to the court documents, Liu allegedly kept his company-issued laptop and exploited a previously unknown authentication vulnerability to access internal cloud storage.

A simple loophole with massive consequences

While this sounds like a high-profile Silicon Valley dispute, it serves as a wake-up call for Pinoy business owners and local IT departments. Leaving access doors open after an employee departs is one of the most common ways companies get breached.

Takanori Nishiyama, senior vice president for Asia-Pacific and country manager for Japan at Keeper Security, explained that the most damaging security failures rarely involve cinematic cyberattacks.

"The most damaging breaches rarely begin with a dramatic break-in," Nishiyama said. "They begin with access that was never fully switched off. When an employee leaves, their credentials, devices and permissions often outlive their employment, and that lingering access becomes an open door."

This vulnerability is not just limited to full-time employees. Many enterprises in the region rely heavily on system integrators, outsourced IT teams, and third-party vendors. Each of these partnerships requires creating custom credentials and remote access routes that are frequently forgotten once the project ends.

The high cost of credential abuse

The scale of this issue is backed by industry data. The 2026 Data Breach Investigations Report by Verizon revealed that credential abuse was present in 39% of all analyzed breaches, making it the most common attack method in the study.

To address this vulnerability, security experts recommend that organizations treat offboarding as a critical safety defense rather than a routine HR task.

How to secure company data

The solution is straightforward but requires strict operational discipline. Organizations must automate their offboarding workflow to instantly revoke all system access the moment an employee or vendor contract ends.

Nishiyama also advised companies to implement least-privilege policies, monitor privileged accounts in real time, and shift toward "just-in-time" access. This security method eliminates permanent access by granting user privileges only when needed and immediately revoking them once the session is completed.


What's Your Reaction?

Wakeke Wakeke
0
Wakeke
BULOK! BULOK!
0
BULOK!
Aww :( Aww :(
0
Aww :(
ASTIG! ASTIG!
0
ASTIG!
AMP#*@! AMP#*@!
0
AMP#*@!
Nyeam! Nyeam!
0
Nyeam!
ASTIG PH Team

Pinoy experiences online. A community dedicated to serving the best stories from the Philippines to the rest of the world. Want to work with us?