In March 2023, within weeks of Samsung Electronics allowing staff in its semiconductor division to use ChatGPT, employees entered confidential company information into the public chatbot at least three times. According to Economist Korea, which broke the story on 30 March 2023, one engineer pasted the full source code of a semiconductor equipment measurement program to fix an error, another pasted code from a yield and defect analysis program to optimise it, and a third fed in a transcript of a recorded meeting to produce minutes. Samsung limited prompts to 1,024 bytes as an emergency measure and investigated the staff involved. On 1 May 2023 it temporarily restricted generative AI tools on company devices and internal networks, telling staff the data sent to external AI servers was hard to retrieve and delete. No attacker was involved and no machine identity was compromised. This page is in our database as a human-identity incident because it is a defining early case of shadow AI.
Key takeaways
- Economist Korea reported on 30 March 2023 that Samsung had confirmed three cases of staff entering company information into ChatGPT after its device solutions (DS) division allowed the tool from 11 March.
- Two cases involved full source code from internal semiconductor programs; the third was a meeting recording transcribed with Naver's Clova app and pasted in to generate minutes.
- Samsung limited each ChatGPT question to 1,024 bytes, warned staff that data entered could not be retrieved, and later restricted generative AI on company devices and networks from 1 May 2023, TechCrunch reported.
- This was data leakage by employees using an approved but uncontrolled public AI service, not a breach by an attacker. No misuse of the data has been reported, and Samsung did not publicly detail what was disclosed.
- The identity lesson: every person or agent using an external AI service is creating an untracked data flow, so AI use needs the same discovery and policy as any other third-party access.
At a glance
| Organisation | Samsung Electronics, device solutions (semiconductor) division |
|---|---|
| When | Three cases in March 2023, after ChatGPT was allowed from 11 March; first reported 30 March 2023; restriction on generative AI from 1 May 2023 |
| Attacker | None. Samsung employees entered the data themselves while using ChatGPT for work |
| Entry point | Employees' own use of the public ChatGPT service, which Samsung's DS division had permitted |
| Identities abused | No credential was abused. Staff used their own access to an external AI service outside any data control |
| Impact | Proprietary source code and meeting content sent to OpenAI's servers; Samsung restricted generative AI use and investigated staff; no reported misuse of the data |
| Category | Human identity (not listed as an NHI or AI agent breach). Incident class: human-identity breach (employees pasted confidential code and meeting notes into a public AI chatbot) |
What happened
Samsung's device solutions (DS) division, which runs its semiconductor business, had restricted ChatGPT but began allowing it on 11 March 2023, Economist Korea reported. Staff were told to pay attention to internal information security and not to enter private content. The division's sister unit for mobile and consumer electronics still banned the tool.
Within about three weeks, Samsung found three problems. According to Economist Korea, one employee copied the entire source code of a program that downloads data from semiconductor equipment measurement databases into ChatGPT and asked how to fix an error. A second entered the full source code of a program used to identify yield and defective equipment and asked for it to be optimised. A third recorded a meeting on a smartphone, turned it into text with Naver's Clova app and pasted the transcript into ChatGPT to draft minutes. Economist Korea reported that Samsung had told staff that data entered into ChatGPT is sent to and stored on external servers where the company cannot retrieve it, and that it could be exposed to other users if the model learned from it. When asked to comment, a Samsung spokesperson declined, describing it as an internal matter.
As an emergency measure, Samsung limited each question to ChatGPT to 1,024 bytes, according to Economist Korea and GIGAZINE. It said it would investigate the employees involved and discipline them if necessary, that it might block ChatGPT on its internal network if similar cases recurred, and that it was considering building an in-house AI service.
On 2 May 2023 Bloomberg reported a Samsung memo, which TechCrunch and CSO Online covered. According to CSO, the memo said engineers had "accidentally leaked internal source code by uploading it to ChatGPT". Samsung restricted generative AI tools on company-owned devices and on non-company devices connected to internal networks from 1 May, and asked staff who used such tools elsewhere "not to submit any company-related information or personal data." A Samsung spokesperson told TechCrunch: "until these measures are ready, we are temporarily restricting the use of generative AI through company devices." An internal survey in April had found that about 65% of respondents saw a security risk in generative AI tools, TechCrunch reported. CSO noted that the memo did not say what the code was or whether anyone outside Samsung had seen it.
Timeline
| Date | Event |
|---|---|
| 11 March 2023 | Samsung's DS division begins allowing staff to use ChatGPT. |
| March 2023 | Three cases of staff entering source code and meeting content into ChatGPT are identified. |
| 30 March 2023 | Economist Korea reports the three cases and Samsung's 1,024-byte limit. |
| 10 April 2023 | GIGAZINE reports the three cases in English, citing Economist Korea. |
| 1 May 2023 | Samsung's temporary restriction on generative AI tools on company devices and internal networks takes effect. |
| 2 May 2023 | Bloomberg reports Samsung's memo; TechCrunch and CSO Online report the restriction. |
How it happened: the identity attack path
- Tool allowed, flows not controlled. Samsung's DS division permitted ChatGPT with a written warning, but had no technical control over what staff sent to it.
- Personal use of a public AI service. Engineers used the public ChatGPT service with their own accounts, outside any enterprise agreement or data protection setting that Samsung controlled.
- Sensitive data in prompts. To get help with real work, staff pasted full proprietary source code and a meeting transcript into the chatbot.
- Data leaves the organisation. The content was sent to and stored on OpenAI's servers, where Samsung said it could not retrieve or delete it.
- Containment by restriction. Samsung responded with a byte limit, an investigation and, from 1 May, a temporary restriction on generative AI tools.
Impact
- Confirmed: Samsung's memo, as reported by CSO Online, said engineers accidentally leaked internal source code by uploading it to ChatGPT. Economist Korea reported three cases, two involving source code and one meeting content.
- Not reported: any exposure of the data to other ChatGPT users, or any misuse of it. Samsung did not publicly say exactly what was disclosed.
- Business impact: staff lost access to generative AI tools on company devices while Samsung developed security measures and considered an in-house alternative.
What this means for NHI and AI agent security
This incident turned on people, not machine credentials, which is why it is marked as a human-identity incident and not listed on our NHI hub. It is in our database because it is one of the clearest early examples of shadow AI: an external AI service becoming part of everyday work faster than the organisation could see or govern the data flowing into it. The same pattern now applies to AI agents and coding assistants, which can send code, documents and secrets to external models on a user's behalf without anyone pasting anything.
The lesson is to treat AI services as third parties with access to company data. Find out which tools are in use, approve enterprise versions with data protection terms, and enforce what may be sent to them, rather than relying on a written warning. Our Shadow AI Discovery Guide and Enterprise AI Copilot Security Guide cover discovery and controls. The OmniGPT breach claim shows what can happen when the AI service holding those conversations is itself breached.
Recommendations
- Discover which AI services staff and agents actually use. Use network, browser and SaaS discovery to find AI tools in use before setting policy. See our Shadow AI Discovery Guide.
- Provide an approved enterprise option. Staff turn to public tools when there is no sanctioned alternative. Offer enterprise AI services with contractual data protection and no training on your data. See our Enterprise AI Copilot Security Guide.
- Enforce data controls, not just warnings. Use data loss prevention on AI traffic to block source code, secrets and personal data, instead of relying on guidance alone.
- Scan prompts for secrets. Source code often contains credentials. Strip or block secrets before any code reaches an external AI service, and rotate any that may have been sent. See our Secrets Management Guide.
- Write a clear AI use policy and train staff on it. Explain what may and may not be entered into AI tools and why, with examples from real work. See our Agentic AI Security Policy Template.
- Treat AI tools as third parties. Review their data retention, training use and access in the same way as any vendor that receives company data.
Frequently asked questions
What did Samsung employees leak to ChatGPT?
According to Economist Korea, in March 2023 one engineer pasted the full source code of a semiconductor equipment measurement program, another pasted source code from a yield and defect analysis program, and a third entered a transcript of a recorded meeting to create minutes. Samsung's memo said engineers accidentally leaked internal source code.
Did Samsung ban ChatGPT?
Samsung temporarily restricted generative AI tools, including ChatGPT, on company-owned devices and on other devices connected to its internal networks from 1 May 2023, while it developed security measures. Staff using such tools elsewhere were told not to submit company information or personal data.
Was the Samsung ChatGPT leak a hack?
No. There was no attacker. Employees entered confidential data into a public AI service themselves while trying to do their work. The risk was that the data left Samsung's control and could not be retrieved or deleted. No misuse of the data has been reported.
Related NHI Mgmt Group resources
Samsung source code leak 2022 · OmniGPT breach claim 2025 · Vercel and Context.ai breach 2026 · Shadow AI Discovery Guide · Enterprise AI Copilot Security Guide
How NHI Mgmt Group can help
Shadow AI starts with people and spreads to agents, plugins and integrations that act on their behalf. We help organisations find the AI services and agents in use, decide which to approve and put controls on what data and credentials can reach them. See our NHI and AI agent security training.
References
- Economist Korea (Jung Du-yong): Concerns become reality as misuse surfaces after Samsung lifts ChatGPT restrictions (in Korean, translated title) (30 March 2023)
- GIGAZINE: A security incident occurs in which Samsung engineers paste confidential source code into ChatGPT (10 April 2023)
- TechCrunch: Samsung bans use of generative AI tools like ChatGPT after April internal data leak (2 May 2023)
- CSO Online: Samsung bans staff AI use over data leak concerns (2 May 2023)