Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is exfiltration?

Exfiltration is unauthorised transfer of data from an account, device or environment to another location. Large outbound traffic alone does not prove theft, because backups, synchronisation and cloud services can produce similar volumes.

Establish what data was involved, its origin, the initiating account and process, transfer mechanism, destination and completion status. The strongest chain connects file or record access, staging, a transfer event and destination-side evidence.

Network volume can show bytes moved without identifying their content. A file-access record can show collection without movement. Use object identifiers, hashes, archive details, API logs or provider records to connect the two.

Recognise varied routes and patterns

Transfers may use web uploads, cloud storage, email, remote tools, DNS, removable media or another compromised system. Repeated low-volume events can be more significant than one spike when they share a process, account or destination.

Distinguish internal staging movement from the final boundary-crossing transfer. A destination subscriber may be false, shared or compromised, so successful exfiltration and offender attribution remain separate conclusions.

Key takeaway

Prove exfiltration by connecting identified source data to a completed unauthorised transfer and destination - not by traffic volume or access alone.

Reference: CIM-159Cyber Incidents & Offender Methods