
Leak
A leak is the premature or unauthorized disclosure of information that was supposed to remain secret. In the tech industry, this often involves unreleased products, internal documents, or user data.
A leak is the leaking out of information that is not yet, or was never meant to be, made public. The English word literally means a hole through which something escapes unintentionally. At tech companies, this might mean photos of a phone that isn’t due to be unveiled for another three months. But it can also involve internal emails, salary lists, or customer data. A leak can happen deliberately, when an employee passes documents on to journalists. Or unintentionally, when a server is misconfigured and anyone on the internet can access the files.
What a leak means for companies and users
For companies, leaks are costly. Product launches planned for weeks lose their element of surprise if all the details are already online beforehand. Competitors learn earlier what’s being worked on and can react accordingly. At publicly traded companies, leaked figures can even move the stock price before official quarterly results are released.
Far more serious are leaks of personal data. When email addresses and passwords from millions of accounts end up online, criminals try these combinations on other services. This often works because many people reuse the same password across multiple sites. In the EU, companies must report such incidents to authorities within 72 hours. Violations can result in fines in the millions.
There are also leaks that serve the public interest. Internal documents have shown that companies knew about risks in their own products and kept them quiet. Such cases are usually called whistleblowing—the exposure of wrongdoing by insiders. The line between betrayal and disclosure is therefore not always clear.
How information gets out
The most common route is through people. Companies work with suppliers, advertising agencies, and testers. The more people who know a secret, the more likely it is to become public. That’s why companies have partners sign contracts guaranteeing confidentiality. Some companies deliberately distribute slightly different versions of a document so they can later figure out who talked.
The second route is technical. Data sits on servers on the internet, and these servers are sometimes misconfigured. A single missing access control is enough for a database to be openly accessible to everyone online. Attackers use automated programs to systematically search for such open doors. Others sneak in via fake emails designed to phish employees' login credentials.
With AI systems, there’s a third variant. A language model is trained on huge amounts of text and can later reproduce parts of it. If that text contained private data or company secrets, the model can reveal them in conversation. That’s why many employers warn against copying internal documents into public chatbots.
Leaks in tech news
If you read tech sites, you’ll encounter leaks almost daily. Ahead of every major phone or console launch, images, prices, and specs circulate. Some of these reports are accurate, others aren’t. Experienced outlets therefore name their source and assess how reliable it has been in the past.
Leaks are also a fixture in the AI industry. Internal strategy papers, model sizes, or investor presentations regularly leak out. For investors, such information is interesting because it offers a glimpse behind the official announcements.
What affects you personally is mainly the data leak. On sites like “Have I Been Pwned,” you can check whether your email address shows up in known leaks. If it does, you should change your password and use a unique one for each service. Two-factor authentication also helps, since it requires a code from an app in addition to the password. That way, a leaked password alone is useless to an attacker.