Precursor Security
Glossary

Data Exfiltration

Data exfiltration is the unauthorised transfer of data from within an organisation to an external location controlled by an attacker. It is the theft stage of many breaches, in which sensitive information such as customer records, credentials or intellectual property is copied out of the environment. Detecting and preventing exfiltration is a key defence against the damage of a breach.

Data exfiltration is the unauthorised removal of data from an organisation to somewhere an attacker controls. It is the point in many attacks where the actual harm is realised: an intruder who has gained access and located valuable information copies it out, whether that is customer personal data, payment details, credentials, source code or commercial secrets. In a data breach, exfiltration is usually the objective the whole intrusion was building toward.

Attackers move data out in many ways, and much of it is designed to blend in with normal traffic. Common channels include transfers over web protocols to attacker-controlled servers, uploads to legitimate cloud storage services, tunnelling data through protocols such as DNS that are rarely inspected, and even physical removal via removable media by an insider. Attackers frequently compress and encrypt the data first, both to reduce its size and to make inspection harder, and may drip it out slowly to avoid triggering volume-based alarms.

Exfiltration is increasingly central to extortion. Modern ransomware operators typically steal data before encrypting it, then threaten to publish it unless paid, a technique known as double extortion. This means that even organisations with excellent backups, which could once recover from ransomware by restoring systems, now face the separate threat of their stolen data being leaked. It has made preventing and detecting exfiltration more important than ever.

Detecting exfiltration relies on recognising abnormal data movement. Behavioural analytics can flag an account or system suddenly transferring unusual volumes, connecting to unfamiliar external destinations, or accessing large amounts of data it does not normally touch. Network detection is valuable because the data has to cross the network to leave, and monitoring for connections to known-malicious infrastructure or anomalous outbound patterns can catch exfiltration in progress, ideally before all of the data is gone.

Prevention combines several controls. Data loss prevention tools inspect and block sensitive data leaving through monitored channels. Strong access control and least privilege limit how much data any compromised account can reach in the first place. Network segmentation and egress filtering restrict where data can be sent. Encryption of data at rest reduces the value of what is stolen. None is complete alone, but together they narrow the opportunities and increase the chance of detection.

The shift to double extortion has changed the calculus of ransomware defence. Where reliable backups once allowed an organisation to recover from encryption without paying, the theft of data before encryption creates a separate threat of publication that backups do not address. This makes detecting and preventing exfiltration, through data loss prevention, egress monitoring and least privilege, as important as the ability to restore systems.

Precursor helps organisations detect exfiltration through its managed SOC, which monitors for the abnormal data movement that signals theft in progress, and identifies the access paths an attacker would use to reach and remove sensitive data through penetration testing.