Apple's iCloud Account Mixing Lets Ex-Employees Access Internal Files
Apple has been found to have gaps in its iCloud sharing and account management that allow former employees to access internal confidential files after leaving the company. Former staff reported that documents shared during employment, including product launch planning materials, continue syncing to personal devices and receiving update notifications. The issue stems from Apple's practice of encouraging employees to bind personal accounts with 2TB of work iCloud storage, complicating permission revocation at departure. No evidence shows intentional retention, but the gap contrasts with Apple's stated data security standards.
Apple has recently been exposed to gaps in its iCloud sharing and account management mechanisms, allowing multiple former employees to access internal confidential files after leaving the company. Several former employees revealed that a large number of Apple internal files shared through iCloud during their employment, including planning documents for product launch events, continued to sync to personal devices after departure, with some files even still receiving update notifications.
The root cause lies in Apple's internal personnel management and account binding mechanisms. Apple typically encourages employees to merge personal Apple accounts with work iCloud accounts, providing 2TB of iCloud storage space. Since a single iPhone and other devices can only log into one primary account at a time, most employees choose to bind work storage directly to personal accounts to avoid carrying two phones. Although Apple has dedicated enterprise management folders to uniformly revoke access when employees leave, many internal files are not automatically stored in these controlled directories, and files shared through apps such as Messages are mixed with personal data, leaving gaps in the cleanup of permissions after departure.
Similar legacy access permission issues have previously triggered litigation disputes. In legal proceedings against companies such as OpenAI and former employees, Apple has accused former employees of illegally downloading or retaining company technical secrets; some defendant employees and related companies have argued that Apple's cleanup of files in former employees' iCloud accounts was not thorough, using this as a defense. Apple responded that the lawsuits target malicious theft of unreleased technology and products, and are unrelated to normal iCloud file sharing or storage mechanisms, and that the company does not sue departing employees who inadvertently retain files in personal accounts due to system legacy issues.
There is currently no evidence that Apple intentionally retains departing employees' file access permissions, but the gaps in iCloud sharing and account wipe operations clearly fall short of the high standards of data security and privacy protection that Apple emphasizes externally.