Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

Does outbound traffic volume prove data theft?

No. Backups, synchronisation, updates, calls, replication and remote desktop can create large outbound flows. Small transfers can also carry selected or highly sensitive data.

Explain the traffic source

Identify the device, process, account, application, protocol, destination and time. Compare the flow with normal behaviour for that same system, process and period rather than broad organisational averages.

An approved cloud provider can host an unauthorised upload, while an unfamiliar address can support legitimate work. Check whether the destination and volume fit the user's or device's expected business activity.

Connect volume to data handling

Traffic becomes stronger exfiltration evidence when preceded by targeted access or staging and confirmed by destination receipt. It still may not identify content without object, hash, manifest or provider records.

Absence of a large spike is not proof of no loss; activity may be compressed, split or sustained at low volume. Use volume as context within the complete source-to-destination chain.

Key takeaway

Treat outbound volume as contextual evidence and require process, source-data and destination links before concluding theft.

Reference: CIM-170Cyber Incidents & Offender Methods