Business
Apple Lawsuit Puts Employee Offboarding and Digital Access in the Spotlight
A trade-secret lawsuit filed by Apple against OpenAI is drawing attention to a less visible aspect of employee departures: ensuring former workers can no longer access company systems after they leave.
According to the lawsuit filed in July, Apple alleges that a senior electrical engineer who left the company in January later accessed confidential file storage from outside Apple due to an authentication issue.
The case centers on allegations that the former employee left Apple without completing an exit interview, did not return a company laptop, and later discovered that access to part of Apple’s internal storage system was still available.
Apple alleges that the former employee then downloaded dozens of engineering files.
OpenAI has denied wrongdoing and said it has no interest in obtaining other companies’ trade secrets.
While the legal dispute will focus on what happened in that specific case, the allegations also point to a broader security problem that many employers face when workers leave.
A departing employee may turn in a badge, key card, and laptop, but those visible steps are only part of the process.
Passwords, cached credentials, virtual private network access, email accounts, single sign-on systems, and cloud services can all remain active if they are not properly disabled.
That means a former employee may still be able to reach company information even after physically leaving the workplace.
According to Apple’s complaint, the company has an internal term for the immediate departure process used in some resignations: the “dreaded walk out.” Under that process, an employee can be escorted out and have access cut off without having to remain at work for a traditional two-week notice period.
Apple says it disables network access on the day an employee departs.
In the case described in the lawsuit, however, Apple alleges that an authentication bug left one path open.
The complaint says the former engineer later wrote to a former colleague that he had discovered he could still reach network storage. Apple alleges that he then used that access to download confidential engineering material.
The allegation highlights a basic lesson for companies: recovering equipment is not the same thing as ending access.
A laptop can be locked or erased remotely if it is enrolled in company management software. But remote controls generally require the device to be connected to the internet.
If a machine stays offline, administrators may not be able to reach it immediately.
More importantly, access to company systems can sometimes exist independently of the device itself.
If a user account, browser-based login, cloud credential or other authentication method remains valid, a former employee may not need the original company laptop at all.
That is why security teams often focus first on disabling access to email, VPN services, single sign-on systems and cloud platforms as soon as an employee leaves.
The Apple allegations suggest that even companies with formal offboarding procedures can face problems if a technical flaw leaves access active.
For employers, the concern is not limited to workers leaving for a competitor.
Any former employee with active credentials can create a security risk, whether intentionally or accidentally. The longer those accounts remain open, the greater the chance that confidential material, customer information, or internal systems could be exposed.
The case also shows why offboarding has become an important part of cybersecurity planning.
Many companies invest heavily in firewalls, monitoring tools, and other defenses, but an active account belonging to someone who no longer works there can bypass many of those protections.
Good offboarding procedures generally involve coordination among human resources, managers, and information technology staff to ensure physical and digital access end at the same time.
The Apple lawsuit remains an allegation, and the claims have not been established in court.
Still, the security issue raised by the case is broader than the dispute itself.
When an employee leaves, collecting the laptop may be the easiest part to see.
Making sure every digital door is actually closed can be much harder.








