Site icon techcoffeehouse.com

Apple Lawsuit Exposes Offboarding as a Security Blind Spot

Advertisements

Apple has sued Chang Liu, a former senior electrical engineer, accusing him of stealing trade secrets after he left the company for OpenAI in January 2026. The complaint, filed on 10 July 2026, alleges that Liu retained an Apple-issued laptop and exploited a previously unknown authentication flaw to access Apple’s cloud network storage weeks after his departure, downloading dozens of confidential files.

The allegations are unproven, but the case has drawn attention from security vendors for a reason that goes beyond the specifics of the lawsuit: it illustrates how offboarding — revoking an employee’s access the moment they leave — functions as a security control rather than an administrative afterthought.

Lingering access as an open door

“The most damaging breaches rarely begin with a dramatic break-in. They begin with access that was never fully switched off. When an employee leaves, their credentials, devices and permissions often outlive their employment, and that lingering access becomes an open door,” said Takanori Nishiyama, Senior Vice President APAC and Country Manager, Japan, at Keeper Security.

Nishiyama noted that the exposure extends well beyond individual employees, particularly for organisations across Asia-Pacific. Enterprises in the region rely heavily on system integrators, managed service providers and outsourced IT, and every such engagement creates accounts, credentials and remote access paths that routinely outlive the contract itself. When a project ends, the people leave, but the access frequently remains.

Credential abuse tops the breach data

Verizon’s 2026 Data Breach Investigations Report found credential abuse present in 39 percent of breaches, making it the most pervasive technique in its dataset. Keeper Security argues the fix is straightforward in principle: organisations should revoke access automatically the moment an employee or vendor engagement ends, enforce least-privilege access, and audit privileged accounts in real time.

A stronger model, Nishiyama argued, removes standing access altogether. Just-in-time access grants privileges only when needed and revokes them the moment a session ends, closing the window that attackers — or, in Apple’s allegations, departed insiders — depend on. Building this discipline into offboarding and vendor lifecycle management, he said, is increasingly what regulators and customers across the region expect as a baseline, not an advanced practice.

Author

Exit mobile version