Slide 12 of 27
Part 2 · TypesSlide 12
Slide 12 · Sensitive Business Data Disclosure — Real Example
Samsung's 20 Days — three leaks, one company-wide ban.
Confirmed Incident · Late March – April 2023 · Reported by The Economist Korea
Samsung Semiconductor Engineers Leak Proprietary Data to ChatGPT
No CVE · Disclosed via The Economist Korea, reported widely April 2023

The setup: Samsung's Device Solutions division had just lifted its internal ban on ChatGPT, letting semiconductor engineers use it to speed up their work.

What happened: Within about 20 days, three separate engineers pasted confidential material into ChatGPT — source code for a facility measurement database, code for identifying defective chip equipment, and a transcript of an internal company meeting.

The consequence: Under ChatGPT's default settings at the time, conversation content could be used to improve future models — meaning that proprietary code and meeting content was now outside Samsung's control, with no way to delete it.

Why it matters for LLM02: this incident sits on the “consumer” side of OWASP's definition — the part about users needing to understand the risk of providing sensitive data in the first place. By May 2023, Samsung banned external generative AI tools company-wide.
The Defense This Would Have Stopped

User Education (OWASP mitigation) with specific, concrete guidance issued before the ban was lifted, not after the leaks happened — plus an enterprise data-retention agreement excluding prompts from training.

← BackNext → Training Data Memorization