The setup: Samsung's Device Solutions division had just lifted its internal ban on ChatGPT, letting semiconductor engineers use it to speed up their work.
What happened: Within about 20 days, three separate engineers pasted confidential material into ChatGPT — source code for a facility measurement database, code for identifying defective chip equipment, and a transcript of an internal company meeting.
The consequence: Under ChatGPT's default settings at the time, conversation content could be used to improve future models — meaning that proprietary code and meeting content was now outside Samsung's control, with no way to delete it.
User Education (OWASP mitigation) with specific, concrete guidance issued before the ban was lifted, not after the leaks happened — plus an enterprise data-retention agreement excluding prompts from training.