Does encryption prove data was stolen?¶
No. Encryption establishes disruption or denial; exfiltration requires evidence that data was transferred. An offender can perform either action without the other.
Investigate the pre-encryption period¶
Look independently for discovery, file access, exports, archive creation, staging, cloud or network transfer, destination records and genuine samples. Collection and transfer often occur before the visible disruptive phase, so the encryption window alone may omit the strongest evidence.
A ransom claim that all data was taken does not prove it. Conversely, absence of a large traffic spike does not disprove slow, compressed or internally staged transfer.
Limit sample evidence¶
Compare any supplied sample with source content and metadata. Genuine possession supports at least that item, but it may be a small subset or data exposed earlier.
Do not infer theft from similarity to known double-extortion incidents. Where no transfer evidence survives, report the claim as unverified rather than proved or disproved.
Key takeaway
Treat encryption and exfiltration as independent propositions, testing data collection and transfer - especially before disruption - rather than inferring theft from impact or claims.