Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

How should suspected exfiltration be reported?

Report exfiltration in stages: data accessed, selected, staged, transfer attempted, received and later accessed. One uncertain stage should not be hidden or allowed to contaminate every other conclusion.

State each supported proposition

Identify source data, account and process, staging, mechanism, destination, time, completion and content scope. Say which findings come from direct records, correlation or inference.

Use precise wording. Archive creation is not upload; upload start is not completion; increased traffic is not proof that named customer records left. Explain encryption, logging gaps, missing destination records and legitimate alternatives.

Handle partial proof

Where preparation and transfer attempts are strong but receipt is unproved, describe attempted or suspected exfiltration. Where receipt is confirmed but exact content is unknown, report the completed transfer separately from data scope.

Use supported minimum, maximum or category where exact items cannot be established. Account, device and destination identifiers provide technical attribution, not automatic personal attribution.

Key takeaway

Report access, preparation, transfer, receipt and content scope separately, marking each as direct, correlated or inferred at the confidence the evidence supports.

Reference: CIM-171Cyber Incidents & Offender Methods