Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is exfiltration over email or messaging?

This route sends data as attachments, links, copied text, screenshots or automated forwards. Drafting, sending, delivery and recipient access are separate stages.

Preserve the communication chain

Retain the message or draft, stable sender and recipient IDs, message ID, attachments or links, time, delivery status, mailbox or platform audit and device process. A draft shows preparation; a sent item may fail delivery; delivery does not prove opening.

Where a link was sent, examine the linked storage object, permissions and recipient access rather than treating the message as the data transfer itself.

Capture automated and provider-held evidence

Forwarding rules, bots and APIs can send continuing copies without a separate user action each time. Establish when the rule was created, its criteria, matching messages and delivery outcome.

Provider retention for deleted or edited messages and attachments may be short, so preserve promptly. The recipient account may be false, compromised or shared and should not be equated automatically with an offender.

Key takeaway

Separate preparation, sending, delivery and access, and connect the actual attachment, link or forwarding rule to each evidenced stage.

Reference: CIM-163Cyber Incidents & Offender Methods