When employees leave, your data might leave too
You’ve just handed out the final pay cheque, collected the laptop, and said goodbye to a staff member who’s moving on. You think everything is locked down. But what if they can still open the folder containing your client contracts? What if your confidential plans are still syncing to their phone? That’s not a hypothetical scenario. A recent report reveals that Apple’s own file-sharing practices left former employees with access to secret documents for months — and the same risks are quietly sitting in your Malaysian SME right now.
What happened
According to a report by The Information, covered by MacRumors, Apple’s use of personal iCloud accounts for work files meant that some ex-employees could still access confidential documents after they left the company. The former employees told The Information that files shared with them during their careers, including planning documents for product launch events, continued to sync to their personal devices through iCloud. Some even received notifications when the documents were updated. A few were “petrified to delete the files for fear that doing so would attract Apple’s attention.” (MacRumors)
Apple encourages employees to use their personal Apple Accounts with their work iCloud account, giving them a 2TB plan. Since only one primary account can be signed in at a time, most employees use their existing account to avoid carrying two iPhones. Apple has a managed folder for workplace files that revokes access when an employee leaves, but some internal documents aren’t saved there automatically, and shared files end up mixed in with personal content. Employees can also retain access to iMessage chats and files shared via the Messages app. (same source)
The lingering access issue has also become central to Apple’s lawsuit against OpenAI. Apple alleged that a former employee breached its systems using a “rare, previously unknown authentication bug” to download files while working at OpenAI. Apple told The Information that the OpenAI lawsuit is unrelated to any files left available on iCloud and that it does not pursue legal claims against former employees who accidentally have Apple documents in their personal iCloud accounts. Yet, in a separate settled dispute, chip company Rivos claimed Apple intentionally lets former employees retain access to files “as part of a planned effort to generate a pretextual basis to sue the employees and their new employer for ‘stealing’ Apple material.” (MacRumors)
Why this matters for Malaysian SMEs
If a trillion-dollar tech company with a security-first reputation can leave outgoing employees with access to confidential files, your business is not automatically safe. In Malaysian SMEs, the situation is often worse. Many small teams rely on shared cloud drives like Google Drive, Dropbox, or iCloud, and employees commonly use personal accounts for work because it’s convenient. You might not have a formal offboarding process at all. When someone resigns, you might delete their user account from your accounting software or email, but what about files they received as shared links? Those links often remain active indefinitely.
Consider a typical scenario: your marketing executive has access to a shared folder containing upcoming product prices, supplier invoices, and customer lists. When they leave, you remove them from your company’s central drive. But if they had previously copied files to their personal device or backed them up to their personal cloud, that data is gone. Even if they haven’t copied anything, the shared links embedded in their phone’s files app can still work. As the Apple case shows, notifications about updated files can continue to appear on their devices, making it obvious your company still has secrets living on ex-employee hardware. Malaysian SMEs are also bound by the Personal Data Protection Act (PDPA) – and retaining access to customer data after an employee leaves may expose you to compliance risks.
Another layer: the blurry line between work and personal devices. Your staff might use their personal WhatsApp to discuss business, send documents to themselves by email, or save files to a personal cloud storage app because the company system is slow. When they leave, those personal storage accounts retain everything. Apple’s mistake was not checking personal devices thoroughly. For you, the lesson is to assume every departing employee has a copy of your data until proven otherwise. That is a sobering thought, but it’s the starting point of a proper offboarding plan.
The bigger picture
What Apple’s situation reveals is not just an isolated slip, but a structural weakness in how modern teams share information. Cloud services make collaboration effortless, but they multiply the points where access can outlive employment. The Information notes that Apple’s use of iCloud for file sharing and its incomplete wiping of employee accounts are at odds with its heavy focus on privacy and security. That same tension exists in every SME. You want employees to move fast and share freely, but you also need to know exactly who has access to what, at all times.
“If Apple — with its entire reputation built on privacy — can’t perfectly cleanse a leaver’s devices, imagine how much harder it is for a 20-person retail shop in PJ to track every copy of a spreadsheet that was emailed, downloaded, and forwarded.”
The good news is that automation can close these gaps. Instead of relying on manual checklists, Malaysian SMEs can use automated offboarding workflows that revoke access, transfer files, and verify that shared links are disabled the moment an employee’s account is deactivated. Tools that integrate with your cloud drive and identity provider can flag files that are still accessible to former staff, as well as files that were saved outside the company folder. This is not about limiting your team’s flexibility; it’s about building a safety net without adding administrative burden.
Consider the key actions you need to take today. The Apple story is a fresh reminder that employee exits are risky moments for data security. Even if you trust your leavers completely, you might be trusting a system that automatically leaves traces of your business in their personal cloud. Review how your team shares documents, what devices they use, and what your offboarding procedure includes. Then, treat this as a checklist: revoke all permissions, change shared links, and check for personal storage usage.
Key takeaways for your SME
- Review your current offboarding process – does it cover shared files as well as email accounts?
- Ask employees to identify any work files stored on personal drives before they leave.
- Disable or change shared link permissions on your cloud storage after every exit.
- Use automated tools to scan for files still accessible by former staff, as part of your monthly security routine.
Ready to Streamline Your Operations?
Technology moves fast. Your operations should keep up. AutoRunBiz builds AI systems that run your daily workflows — from WhatsApp order capture to accounting. Book a free 15-min ops audit →
