
Apple’s case against OpenAI shows how easily trade secrets can cross company lines when trusted employees carry knowledge, files and access from one employer to the next.
NurPhoto via Getty Images
In the common imagination, corporate espionage plays out like a scene from Ocean’s Eleven, a velvet-gloved crew rappelling past laser grids to crack a vault that was never meant to open. The reality, more often than not, could hardly be further from it.
The threat wears a lanyard and badges through the front door each morning, showing up as the North Korean operative posing as a remote engineer, the hacker working for an hostile nation, and, most unassuming of all, our own people, who leave with what lives in their heads and, now and then, with a laptop that was never returned.
That final figure sits at the heart of Apple’s lawsuit against OpenAI, filed last week in the Northern District of California, and if you want to keep your own people off both sides of that fight, the case is worth reading closely.
The dullest heists happen in tech
Apple’s complaint reads less like a caper and more like an HR audit gone nuclear.
The company alleges a coordinated pattern of theft running across former employees, from rank-and-file technical staff up to OpenAI’s chief hardware officer Tang Tan, a 24-year Apple veteran who once led design for the iPhone and Apple Watch.
The engine behind it, Apple says, is OpenAI’s push into consumer hardware through io Products, the Jony Ive startup it acquired for $6.5 billion, and the roughly 400 former Apple employees who now work at OpenAI.
What makes the filing land is how little of it resembles a Hollywood heist. Chang Liu, a former senior engineer, allegedly held onto his Apple laptop after leaving and later found he could still reach the company’s network storage, messaging a former colleague that he found it funny he still had the keys, per Axios. Tan, for his part, is accused of asking candidates still on Apple’s payroll to bring “actual parts” to interviews for show-and-tell sessions, and of coaching departing staff on how to slip past exit checks. Apple’s own summary is that the scheme operated at every level, while OpenAI counters that it has no interest in anyone else’s trade secrets.
None of this is new, and that is rather the point.
The crown jewels almost always leave through the front door, whether it was Anthony Levandowski carrying Waymo’s self-driving files toward Uber or the steadier and far more common pattern the data keeps surfacing, in which the people already inside the building pose the real danger. One analysis of federal prosecutions found that 55% of trade-secret perpetrators were current employees and another 27% were former ones, which leaves the shadowy outside hacker as a rounding error next to the colleague who already has a badge.
Perimeters and endpoint monitoring earn their keep, and any serious security chief will defend them, yet the perimeter has a habit of collecting its final paycheck and walking itself out at five o’clock.
The vulnerability every leader carries on the balance sheet is the very same asset the annual report celebrates under the heading of talent. It is the most valuable input a company owns and the least patchable.
“Your most trusted people hold the most access, and that access is rarely reviewed and tested. It’s identity management 101,” Aaron Shilts, CEO of NetSPI told me. “Further, companies are quick to point the finger at IT and cybersecurity teams while dismissing the human layer altogether.”
Traditional penetration testing works from the outside in, asking what an intruder could exploit to seep through the walls. The insider-risk equivalent is penetration testing in reverse. Give someone the access of a trusted employee, then ask what they could carry away before anybody noticed. The question is no longer whether an attacker can reach the crown jewels, but how far the crown jewels can travel in the hands of someone the system already trusts.
That visibility must extend in both directions. Leaders need to know not only who can come through the door, but what can leave through it, on whose laptop, under which credentials, and for how long after the person carrying them has supposedly gone.
Both sides of the door
Protection runs in two directions, outbound and inbound, and most leaders only guard one of them. Start with the leaks that flow out, most of which carry no ill intent whatsoever.
The departing manager reuses a deck at the next job, the engineer syncs a folder to a personal cloud out of muscle memory, and neither of them thinks of it as theft. That instinct is the norm rather than the exception, given that negligent insiders account for roughly 58% of insider incidents.
A second group means no harm but was never told which information the company considered precious, which is a failure of clarity long before it becomes a failure of loyalty. The remedy there is unglamorous legal hygiene, the NDAs and confidentiality reminders and the reasonable measures the Defend Trade Secrets Act expects a company to take before any court will agree that a secret was ever treated like one.
Apple’s complaint doubles as a checklist of exactly these controls, since the exit interview and device return that Liu allegedly skipped are precisely the mechanisms that would have left a record. The malicious minority is where the real work lives, and it clusters in the window between a resignation letter and a last day, when the temptation to take something for the road runs highest.
“You cannot defend what you have never tested,” Amitai Ratzon, CEO of Pentera, told me. “Most companies assume their controls hold right up until someone walks out and proves otherwise. A resignation should trigger a change-of-privilege workflow, not merely an HR checklist.”
Then flip the frame to the side leaders forget. As you hire, the gleaming résumé arrives with baggage, because the star you just poached may bring a rival’s secrets through your door and hand you a lawsuit along with them.
This is Apple’s complaint viewed from the opposite chair, and it is the more precarious seat, since the plaintiff is another company’s legal department and the liability is now yours. The care that protects your own secrets happens to be the same care that keeps you clean on intake, the written instruction never to bring prior-employer material, the interview that would never dream of asking a candidate to haul in “actual parts,” the onboarding that documents what a new hire may and may not touch.
Read Apple’s filing closely and the tell is right there, because the alleged asks happened during interviews, the exact moment a disciplined company shuts the door rather than props it open. Both problems, the secret leaving and the secret arriving, answer to the same charmless rigor.
The Ocean’s Eleven fantasy gets one thing exactly backward.
The vault was never the weak point, and the sophisticated outsider was never the likeliest villain. The exposure was always the people who knew the combination and had every legitimate reason to be trusted with it.
Apple’s legal fight against OpenAI will grind through the Northern District of California for years, and the ultimate outcome will matter less to most leaders than the lesson sitting in plain sight, that the ones who come through intact are those who learned to read their own roster as an attack surface well before a lawsuit arrived to force the question.