Apple filed a lawsuit alleging that former employee **Ethan Lipnik** shared confidential iOS 26 development features with **Michael Ramacciotti**, who later disclosed them to leaker **Jon Prosser** via a FaceTime call. Ramacciotti accessed Lipnik’s **development iPhone** (containing unreleased trade secrets) while Lipnik was away, though he claims no prior conspiracy or payment agreement existed. Prosser later paid Ramacciotti **$650** post-call, allegedly without Ramacciotti’s expectation. The breach involved **unauthorized access to proprietary software**, including unreleased iOS features, which were subsequently leaked. Ramacciotti denies tracking Lipnik’s location or retaining further confidential data, but the incident exposed Apple’s **trade secrets**—specifically **unreleased iOS functionality**—to external parties, risking competitive disadvantage and reputational harm. Apple is pursuing legal action, with Prosser facing a **default judgment** for non-response.
TPRM report: https://www.rankiteo.com/company/apple
"id": "app1602216103125",
"linkid": "apple",
"type": "Breach",
"date": "10/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology (Consumer Electronics, '
'Software)',
'location': 'Cupertino, California, USA',
'name': 'Apple Inc.',
'size': 'Large (Multinational)',
'type': 'Corporation'}],
'attack_vector': ['Physical Access to Device',
'Insider Threat (Former Employee)',
'Social Engineering (Trust Exploitation)'],
'data_breach': {'data_exfiltration': ['Screen Sharing via FaceTime',
'Potential Video Recording by Prosser'],
'sensitivity_of_data': 'High (Unreleased Software Features)',
'type_of_data_compromised': ['Trade Secrets (iOS 26 Features)',
'Confidential Development '
'Information']},
'description': 'Apple sued leaker Jon Prosser and Michael Ramacciotti, '
'alleging a coordinated scheme to break into an Apple '
'development iPhone, steal trade secrets (iOS 26 features), '
'and profit from the theft. Ramacciotti admitted accessing the '
'device and sharing details with Prosser via FaceTime but '
'denied pre-planning, location tracking, or knowing Prosser '
'would record the call. He claimed the $650 payment from '
'Prosser was unsolicited and received after the fact. '
'Ramacciotti also stated he was unaware of the sensitivity of '
'the iOS development version, as the original owner (former '
'Apple employee Ethan Lipnik) had previously shown him '
'features. Prosser has not responded to the lawsuit, and Apple '
'is pursuing a default judgment against him.',
'impact': {'brand_reputation_impact': ['Negative Publicity',
'Perception of Weak Insider Threat '
'Controls'],
'data_compromised': ['iOS 26 Features (Trade Secrets)',
'Development iPhone Contents'],
'legal_liabilities': ['Lawsuit Against Prosser and Ramacciotti',
'Potential Default Judgment Against Prosser'],
'operational_impact': ['Potential Compromise of Unreleased '
'Software Features',
'Legal and Reputational Risks'],
'systems_affected': ['Apple Development iPhone']},
'initial_access_broker': {'entry_point': 'Physical Access to Unattended '
"Development iPhone (Ethan Lipnik's "
'Device)',
'high_value_targets': ['iOS 26 Features',
'Apple Trade Secrets']},
'investigation_status': 'Ongoing (Lawsuit in Progress, Default Judgment '
'Sought Against Prosser)',
'motivation': ['Financial Gain',
'Reputation/Influence (Leaking Exclusive Information)'],
'post_incident_analysis': {'root_causes': ['Insufficient Physical Security '
'for Development Devices',
'Lack of Awareness/Training on '
'Trade Secret Sensitivity',
'Insider Trust Exploitation']},
'references': [{'source': 'The Verge'}],
'regulatory_compliance': {'legal_actions': ['Civil Lawsuit',
'Default Judgment Pursuit'],
'regulations_violated': ['Trade Secret Laws (e.g., '
'Defend Trade Secrets Act)',
'Potential Violation of '
"Apple's Internal "
'Policies']},
'response': {'communication_strategy': ['Public Disclosure via Lawsuit '
'Filings',
'Media Statements (e.g., to The '
'Verge)'],
'containment_measures': ['Legal Action (Lawsuit)',
'Pursuit of Default Judgment Against '
'Prosser'],
'incident_response_plan_activated': True},
'threat_actor': ['Michael Ramacciotti', 'Jon Prosser'],
'title': 'Apple Trade Secret Theft Allegations Involving Jon Prosser and '
'Michael Ramacciotti',
'type': ['Trade Secret Theft', 'Unauthorized Access', 'Data Leak'],
'vulnerability_exploited': ['Lack of Physical Security for Development Device',
"Insider Knowledge (Ethan Lipnik's Willingness to "
'Share)',
'No Technical Vulnerability (Human Factor)']}