New Twist in Apple Case, a $9.3M Privacy Fine and Healthcare Data Theft

03.09.2026

Apple Adds New Claims to OpenAI Trade Secrets Case

In July, Apple filed a lawsuit against OpenAI and two former Apple employees, accusing them of unlawfully using confidential information related to the company’s device development and manufacturing processes.
Apple now claims that former senior systems engineer Chang Liu continued accessing confidential Apple information after joining OpenAI. According to new court filings submitted by Apple to a US federal court, Liu accessed a power converter schematic in March 2026 that Apple considers a trade secret.

The company alleges that the engineer used the information to model an electrical circuit and to train an AI agent capable of independently running simulations and analysing their results. Apple says it uncovered the activity after examining a work MacBook provided by OpenAI as part of the litigation.

The new allegations broaden the original dispute, which focused primarily on the alleged transfer of Apple’s technical and manufacturing information to OpenAI’s new hardware development team. Apple is now claiming that its confidential information may also have been used directly in AI related workflows.

OpenAI denies the allegations and is seeking to have the case dismissed. The company argues that Apple has failed to provide sufficient evidence of trade secret misappropriation and is attempting to restrict employees from moving to a competitor. OpenAI has also pointed to Apple’s practice of allowing employees to use personal iCloud accounts for work, which could leave them with access to certain materials after leaving the company.

GS Retail Fined $9.3M After Data Breach

South Korea’s Personal Information Protection Commission has fined GS Retail 12.84 billion won, approximately $9.3 million, following a breach that exposed the personal data of around 1.66 million users of its GS Shop and GS25 services.
The attacker used credential stuffing, systematically testing previously compromised username and password combinations against the company’s websites. Attacks targeting GS Shop continued from June 2024 to February 2025, while GS25 was targeted from late December 2024 to early January 2025. 

As a result, the data of approximately 1.58 million GS Shop users and more than 79,000 GS25 users was compromised.

The exposed information included:

  • Names
  • Dates of birth
  • Phone numbers
  • Email addresses
  • Physical addresses

According to the regulator, one of the key issues was GS Retail’s insufficient ability to detect anomalous activity. The company had not implemented adequate mechanisms to identify and block large volumes of login attempts originating from the same IP addresses and failed to respond promptly to a sharp increase in unsuccessful account login attempts.

In addition to the fine, the PIPC ordered GS Retail to strengthen its suspicious access detection controls, assign dedicated personnel responsible for personal data protection and more clearly define the authority and responsibilities of its Chief Privacy Officer.

McKesson Confirms Data Theft in Cyberattack

US based McKesson, one of the country’s largest distributors of pharmaceuticals and medical supplies, has confirmed a cyber incident in which attackers gained unauthorised access to third party applications and stole data.
McKesson detected the incident on August 25. According to the company, the attack affected some customers of its Oncology & Multispecialty and Medical-Surgical businesses.

The investigation is ongoing, and McKesson has not yet disclosed the exact volume or types of information stolen. In a filing with the US Securities and Exchange Commission, the company said it had not identified any material impact on its financial condition or operating results at this stage.

The ShinyHunters group has claimed responsibility for the attack. According to the attackers, initial access was obtained through vishing and other social engineering techniques, with several McKesson employees allegedly persuaded to provide access to corporate accounts. 

The group claims it subsequently gained access to Salesforce and Snowflake environments and extracted approximately 1 TB of data between August 21 and 25.

ShinyHunters also claims to have stolen around 284 million records containing personal and medical information. However, this figure refers to the number of database records and does not mean that 284 million individual patients were affected.

McKesson has not confirmed either the volume of data claimed by the attackers or their account of how the systems were compromised.


Social engineering remains one of the most common ways to bypass technical security controls. By compromising an employee account, attackers can operate under legitimate credentials, making malicious activity harder to distinguish from normal user behavior.

Learn how DLP can help detect such attacks and prevent data theft through compromised accounts in our white paper material, How DLP Systems Prevent Hacker Intrusions and Data Breaches.