Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster


The way Apple combines work and personal iCloud accounts left some employees able to access confidential documents after departing the company, reports The Information. The site spoke to more than half a dozen former Apple employees who were unknowingly left with access to sensitive content.

General-iCloud-App-Feature.jpg

The former employees said many Apple files they had been shared on over their careers at the company—including planning documents for product launch events—continued to sync to their personal devices through the iCloud storage service after they left Apple. In some cases, they even received notifications about fresh updates to the documents. Some former employees said they were petrified to delete the files for fear that doing so would attract Apple's attention.
Apple files get mixed in with employees' accounts because the company encourages them to use their personal Apple Accounts with their work iCloud account. Employees are given a 2TB iCloud plan and are able to merge the storage with their existing Apple Account or create a new account. Since only one primary account can be signed in at a time, most opt to use their existing account to avoid having to carry two iPhones.

Apple has a managed folder for workplace files that it revokes access to when an employee leaves, but some internal documents aren't saved there automatically and shared files end up mixed in with personal content. Employees can also retain access to iMessage chats and files shared via the Messages app.

Lingering access to Apple systems is central to Apple's lawsuit against OpenAI. In its filing, Apple alleged that former employee Chang Liu breached Apple's systems using a "rare, previously unknown authentication bug" to download files while he was working at OpenAI.

Apple told The Information that the OpenAI lawsuit is unrelated to any files left available on iCloud and that it does not pursue legal claims against former employees who accidentally have Apple documents in their personal iCloud accounts.
This case is about OpenAI employees wrongfully taking Apple's secret and confidential information regarding our unreleased technologies, processes, and products. Nothing in the filing relates to documents shared by, or stored in, iCloud.
Former employees say Apple does not do a thorough enough job going through personal devices to remove sensitive files that have been stored in iCloud. In a now-settled legal dispute, chip company Rivos claimed Apple intentionally lets former employees retain access to files "as part of a planned effort to generate a pretextual basis to sue the employees and their new employer for 'stealing' Apple material." In the Rivos case, an employee was targeted for keeping work files in his personal iCloud account.

Another former Apple employee sued by Apple, Gerard Williams, countersued and accused the company of using intimidation tactics to scare people thinking of leaving. Apple sued Williams for breach of contract after he started processor company Nuvia, presenting extensive phone and text records of his communications. The court rejected Williams' claim, and Apple dropped the case in 2023.

In 2025, Apple also accused former Vision Pro engineer Di Liu of downloading thousands of corporate documents to his personal cloud storage shortly before leaving the company for Snap.

The Information does not outright suggest Apple is purposefully allowing former employees to retain access to iCloud files, but points out that Apple's use of iCloud for file sharing and its incomplete wiping of employee accounts are at odds with its heavy focus on privacy and security.

Article Link: Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents
 
Maybe if they didn't kill this feature they announced years ago, this problem would have been solved:
 
The way Apple combines work and personal iCloud accounts left some employees able to access confidential documents after departing the company...
... for OpenAI?

 
Interesting conundrum.

Cloud accounts tend to be attached to people, almost like a digital version of them. One user = one account. One user cannot have more than one account.

It'd make more sense if cloud accounts attached to people's roles in life. Same account, just different "rooms" in the same house.

Per-user accounts are a real anachronism.

A huge issue for families is that Amazon doesn't offer a family account, for example. They offer family sharing but it's not the same. It should be possible for everybody in a house to use an account to buy household stuff, for example.

But everybody in tech is still very wedded to the idea of one user = one account. Crazy that this concept hasn't changed for maybe 50 years.
 
Another former Apple employee sued by Apple, Gerard Williams, countersued and accused the company of using intimidation tactics to scare people thinking of leaving.
While other companies lay off their long time employees and replace them with Indian H1Bs, Apple discourages people to leave their job and even scares them into keeping it. God I love Apple.
 
Apple files get mixed in with employees' accounts because the company encourages them to use their personal Apple Accounts with their work iCloud account. [...] Since only one primary account can be signed in at a time, most opt to use their existing account to avoid having to carry two iPhones.
Truly unhinged.

I'll never understand why iOS doesn't allow for multiple user accounts like the Mac has had for decades now. (I mean, I understand this is to drive device sales, but it's arbitrary and kind of awful.)
 
Maybe if they didn't kill this feature they announced years ago, this problem would have been solved:
Yeah this is stupid. You'd think they'd at least have this ability for Apple employees.
 
Maybe if they didn't kill this feature they announced years ago, this problem would have been solved:
You can create some version of this now by setting up a separate iCloud account and then setting up Family Sharing to share certain data between your main account and your secondary. You can share many app and media purchases, iCloud storage, services like Apple Music etc if you use those -- and of course the usual stuff like calendars and mail accounts if you care to. It's a bit of work to set up, but super useful if you want to keep a barrier between two areas of use.

On a Mac, you can then set up a separate user account with the secondary iCloud account and switch between the two on the fly. You can even register separate fingerprints on your hand to use the TouchID sensor to very quickly toggle between accounts. I did this with freelance work for a while, so I could leave my other working environment all set up the way I want, but then totally switch away from it when I wanted. (None of this works on an iPad, sadly.)
 
Last edited:
There are separate iCloud Accounts for Personal and Work. The work ones are called Managed Apple Accounts and can be integrated with an organization's SSO. BYOD iOS devices can sign into both at the same times.

 
Apple needs to fix this issue, but this has to be one of the more ridiculous claims related to Apple in a lawsuit ever made: “Rivos claimed Apple intentionally lets former employees retain access to files ‘as part of a planned effort to generate a pretextual basis to sue the employees and their new employer for 'stealing' Apple material.’”
 
Apple needs to fix this issue, but this has to be one of the more ridiculous claims related to Apple in a lawsuit ever made: “Rivos claimed Apple intentionally lets former employees retain access to files ‘as part of a planned effort to generate a pretextual basis to sue the employees and their new employer for 'stealing' Apple material.’”
“They let me keep access because they want cause to sue me!” If it were me and the new gig was a gig I wanna keep long term, I’d be doing anything in my power to get my ex-employee to remove me from anything I shouldn’t have access to. BEFORE my first day at the new place.

For some people, their ex-Apple identity is the most important thing in their lives.
 
"Some former employees said they were petrified to delete the files for fear that doing so would attract Apple's attention."
Why petrified? If they didn't notice during the exit process that one would assume involves remove access etc, and noticed later on, then why wouldn't they just reach out to Apple to let me know, and Apple can note the safest way to remove etc without issue, since they would be able to see how and when they were shared and that the employee didn't intentionally steal them unless I'm missing smoething? That being said, if you allow sharing to personal iClouds, for a company obsessed with keeping its secrets, I have to imagine that would be a major issue and that after all these years would have a process to make sure that doesn't happen other than rare occurrences. If common place that would seem like Apple is intentionally letting it happen to be able to sue later, but of course that's based on nothing other than doesn't make sense apple would allow such as an issue persist?
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.