
Apple has stepped up its legal battle with OpenAI over allegations that confidential information was taken by former employees and used to support OpenAI’s push into consumer hardware.
On July 10, Apple sued OpenAI, hardware subsidiary io Products, and two former Apple employees, Tang Tan and Chang Liu. The company alleges that the defendants misappropriated trade secrets to accelerate OpenAI’s hardware development. OpenAI denies allegations of systematically collecting confidential information and has stressed employees’ right to change employers freely.
Tang Tan worked at Apple for 24 years and served as vice president of product design, working on products including the iPhone and Apple Watch. He later co-founded io Products, which OpenAI acquired in 2025, and became OpenAI’s chief hardware officer.
Apple alleges that, before leaving the company, Tan forwarded supplier information and other internal materials to his personal email account. The lawsuit also claims that confidential Apple project code names were used during recruitment interviews and that candidates were encouraged to discuss unreleased products, prototypes, and technical work.
The second defendant, former Apple engineer Chang Liu, is accused of retaining his company-issued laptop after joining OpenAI and continuing to access confidential Apple systems and hardware files. Apple claims he exploited a security weakness that allowed his access to remain active after his departure. The allegations have not been proven in court.
The dispute has since widened beyond the two named employees. According to the Financial Times, Apple sent legal letters to around 40 former employees now working at OpenAI, instructing them to preserve emails, documents, notes, and other potentially relevant material. Some were also asked to meet Apple’s legal team.
More than 400 former Apple employees are now reported to work at OpenAI. Receiving a document-preservation notice does not mean that a person has been accused of misconduct; such notices are intended to ensure that potentially relevant evidence is not deleted while litigation is under way.
Apple is seeking damages and court orders that would prevent the disputed information from being used or disclosed. The case will ultimately depend on whether Apple can show that the information qualifies as protected trade secrets and that it was improperly obtained or used in OpenAI’s hardware programme.
Colombian state-controlled energy company Ecopetrol has disclosed a cyberattack involving unauthorized access to cloud-based file storage and the theft of corporate data.
Ecopetrol is Colombia’s largest company and one of Latin America’s biggest energy producers, accounting for more than 60% of the country’s hydrocarbon output.
According to the company, an unidentified external attacker gained access to cloud storage environments used across the Ecopetrol Group. The breach affected systems used by Ecopetrol and 15 subsidiaries, and data linked to approximately 3,300 user accounts was downloaded.
The attacker issued extortion demands and threatened to publish the stolen information. At the time of disclosure, the company had not identified any critical disruption to operations, reduction in production, or direct financial loss. Its main operational systems remained available, and the stolen data had not yet been released publicly.
Ecopetrol is still assessing the scope of the breach. It said the compromised files may contain confidential business information, proprietary data, or personal information. The company has brought in external specialists, notified law enforcement and regulators, and introduced additional security measures.
Both incidents put valuable corporate information at risk, including personal data, trade secrets and confidential product developments. In Apple’s case, the alleged leak involved former employees who had legitimate access to internal projects before moving to another company. In Ecopetrol’s case, an external attacker gained access to corporate files by compromising cloud infrastructure.
Companies need to protect sensitive data regardless of whether the threat comes from an insider or an external attacker. SearchInform DLP helps control access to confidential information, prevents illicit and potentially dangerous data transfers, and monitor how sensitive data is accessed, used and shared. Learn how SearchInform DLP system helps prevent hacker intrusions and data breaches.
SearchInform uses four types of cookies as described below. You can decide which categories of cookies you wish to accept to improve your experience on our website. To learn more about the cookies we use on our site, please read our Cookie Policy.
Necessary Cookies
Always active. These cookies are essential to our website working effectively.
Cookies does not collect personal information. You can disable the cookie files
record
on the Internet Settings tab in your browser.
Functional Cookies
These cookies allow SearchInform to provide enhanced functionality and personalization, such as remembering the language you choose to interact with the website.
Performance Cookies
These cookies enable SearchInform to understand what information is the most valuable to you, so we can improve our services and website.
Third-party Cookies
These cookies are created by other resources to allow our website to embed content from other websites, for example, images, ads, and text.
Please enable Functional Cookies
You have disabled the Functional Cookies.
To complete the form and get in touch with us, you need to enable Functional Cookies.
Otherwise the form cannot be sent to us.
Subscribe to our newsletter and receive a bright and useful tutorial Explaining Information Security in 4 steps!
Subscribe to our newsletter and receive case studies in comics!