Articles / Samsung, ChatGPT, and Three Leaks in Twenty Days
Incident File · 2023

Samsung, ChatGPT, and Three Leaks in Twenty Days

In the spring of 2023, Samsung's semiconductor division became the textbook example of a risk that no firewall catches: employees handing confidential data to a public chatbot, one helpful paste at a time. As The Economist Korea first reported and outlets including The Register and Bloomberg relayed, it happened at least three times in under a month.

Samsung had only just relaxed a ban on ChatGPT for parts of its Device Solutions unit. Within roughly twenty days, three separate incidents were reported. In the first, an engineer pasted proprietary source code from an internal semiconductor database into ChatGPT to debug it. In the second, another employee submitted code related to yield and defect-measurement equipment, asking the model to optimise it. In the third, a worker fed ChatGPT a recording of an internal meeting — transcribed by a separate third-party tool — to generate minutes.

None of this was a hack. No credential was phished, no server misconfigured. Each was an ordinary employee using a genuinely useful tool to do their job faster. That is exactly what makes it instructive.

Why a paste is a data transfer

The core problem is that text pasted into a consumer AI service leaves the company's control the moment it is submitted. At the time, OpenAI's terms allowed conversations to be used to improve its models unless users opted out, and the data resided on third-party infrastructure outside Samsung's governance. Source code for an unreleased chip fabrication process is among the most closely guarded assets a semiconductor firm holds; once it is in an external system, you cannot prove where it went or compel its deletion with any confidence.

pastesSamsung engineerConfidential sourcecode & meeting notesPasted into ChatGPTpublic text boxOpenAI serversoutside the boundaryNo file transfer —DLP and perimetersee nothing
How a helpful paste became an uncontrolled data transfer.
Why it matters: The exposure vector was a text box, and the actor was a trusted, well-meaning employee. Perimeter controls, DLP tuned for file transfers, and endpoint agents all see nothing when the payload is a clipboard paste into a browser tab.

Samsung's response

Samsung reportedly capped the length of prompts employees could submit, opened an internal investigation, and — as Forbes and others reported — moved within weeks to ban generative AI tools on company-owned devices and internal networks, weighing the option of building an in-house alternative. The company warned that violations could lead to dismissal. It was one of the earliest high-profile corporate bans, and many banks and manufacturers followed with similar policies through 2023.

The defender's lesson

An outright ban is the blunt instrument; it tends to push usage underground rather than eliminate it. The more durable lessons are about discovery and design:

  • Assume the tools are already in use. Employees adopt AI faster than policy is written. The question is not whether staff are pasting data into chatbots, but what and how often — and you cannot answer that without visibility into egress to AI endpoints.
  • Provide a sanctioned path. An enterprise tier with data-retention controls, or a self-hosted model, removes the incentive to reach for the consumer version. People take the shortcut that works; make the safe option the convenient one.
  • Classify before you connect. Source code, unreleased hardware specs, and meeting transcripts are exactly the material that should never touch an unmanaged endpoint. Label it, and gate it.
  • Treat prompts as an egress channel. DLP and monitoring should watch text submitted to AI services the same way they watch email attachments and uploads.

Samsung's misfortune was to learn this publicly and early. The engineers were not careless in any ordinary sense — they were productive. That is the uncomfortable core of shadow AI: the behaviour you most want to stop looks identical to the behaviour you hired people to perform. You cannot govern what you have not discovered, and you cannot discover it by trusting that no one would paste the crown jewels into a text box.

Keep reading
100,000 Stolen ChatGPT Logins on the Dark Web