Full Breakdown
Apple Sues Former Engineer Over Alleged Theft of Confidential Files After Joining OpenAI
7/15/2026, 5:58:43 AM
Core Event
Apple has filed a lawsuit in the U.S. District Court for the Northern District of California against former system electrical engineer Chang Liu. The complaint alleges that Liu exploited a previously unknown authentication bug—a “zero-day exploit”—to access Apple’s shared network folders weeks after his employment ended. According to the filing, Liu downloaded confidential engineering files related to unreleased products, technical specifications and internal project documentation while employed at OpenAI. Apple says Liu retained his Apple-issued laptop and also used the work laptop of another Apple employee, Yu-Ting Peng, who was still employed at the time, to continue accessing internal storage. Server logs allegedly identified the unauthorized access, and Apple reports that the vulnerability has since been patched and Liu’s access terminated.
Background & Context
The lawsuit highlights the importance of immediate off-boarding and robust access-management controls. Apple notes that the authentication bug had not been identified before Liu’s alleged misuse, and that “no evidence that others had exploited the same vulnerability” was found. The complaint underscores that retaining company assets and failing to report discovered security flaws violate employment obligations.
Official Statements & Responses
Apple’s filing seeks a jury trial and pursues legal action over the alleged misappropriation of trade secrets. The company emphasizes that it has “fixed the security vulnerability” and terminated Liu’s access after discovering the breach. OpenAI has not been accused of wrongdoing in the complaint and has previously stated that it “has no interest in acquiring competitors’ trade secrets.” OpenAI’s response to the filing reiterates this position.
Potential Implications
The case draws attention to corporate data-security risks when employees depart, especially in high-tech sectors where proprietary information is a competitive asset. It may prompt firms to review off-boarding procedures and accelerate vulnerability remediation to prevent similar incidents.
