Apple left some former employees with continued access to confidential internal documents because shared files synced through personal iCloud accounts were not fully revoked during offboarding, according to reporting citing former staff. The exposed material reportedly included sensitive product launch planning documents, and in some cases updates to those files continued generating notifications on ex-employees’ personal devices after they left the company. The issue appears tied to Apple encouraging workers to use a combined personal Apple Account with work iCloud storage while not placing all internal files inside managed folders that are automatically cut off at departure.
A separate publication from OpenAI included what it described as message transcripts showing a departing Apple employee discussing copying or transferring files from an Apple iCloud account, including by AirDrop and external storage, while preserving personal notes and shared work files around the time of resignation. The messages also showed the former employee continuing to discuss Apple internal engineering and product matters with a current employee after leaving, adding to concerns about insider risk, weak access revocation, and gaps between Apple’s security posture and its controls for protecting corporate data during employee exits.

See attribution, scope, and your downstream exposure.
9 events from the most recent confirmed update back to the earliest known activity.
On February 14, 2026, Apple Employee #1 asked the former employee for help recalling a technical topic, and the former employee provided guidance and suggested other Apple personnel who might know more. The transcript shows continued exchange of internal technical information after the employee's departure.
On January 31, 2026, Apple Employee #1 said they had signed out of the former employee's iCloud account and chose not to keep a copy when prompted. The former employee thanked them afterward.
On January 30, 2026, the former employee said they realized the folder was gone from their iCloud and asked whether Apple Employee #1 had obtained all needed material. They suggested contacting IST for backup if necessary.
On January 27, 2026, a participant told Apple Employee #1 they could keep the former employee's iCloud connected if more time was needed for files, while also asking them to sign out of iMessage so new company information would not appear. Apple Employee #1 said they would finish up and log everything out the next day.
Messages dated January 22-23, 2026 describe a participant copying files to a 64GB drive, restarting an AirDrop transfer, and planning to complete the transfer before clicking the Workday button. The exchange indicates efforts to move files from an Apple iCloud account around the time of departure.
Apple accused former Vision Pro engineer Di Liu of downloading thousands of corporate documents to personal cloud storage before leaving for Snap. The accusation was made in 2025.
In the Gerard Williams dispute, the court rejected Williams' claim and Apple dropped the case in 2023. The reference cites this as part of Apple's broader legal conflicts with former employees.
The Information reported that Apple's mixing of personal Apple Accounts with work iCloud storage left some former employees with continued access to confidential documents after leaving. Former employees said shared files kept syncing to personal devices and sometimes still generated update notifications.
Apple sued former employee Gerard Williams for breach of contract after he started processor company Nuvia. The dispute later featured Apple presenting extensive phone and text records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.