Data Security & PrivacyIntermediateAttack Technique1 validated evidence record

Data Exfiltration

Also known as: Exfiltration

30 sec

Unauthorized transfer of data out of an environment, account, application, or device.

Know

What is Data Exfiltration?

Unauthorized transfer of data out of an environment, account, application, or device. In practice, data exfiltration should be understood in the context of the identities, systems, applications, data, trust relationships, and business processes it affects. The useful question is not only what the term means, but how it changes attacker capability or defensive control.

Why it matters

Unauthorized transfer of data out of an environment, account, application, or device. Attackers can use this behavior to turn a single weakness, identity, or interaction into broader compromise, so defenders need to recognize both the mechanism and the business consequence.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Standards / FrameworkStandard / framework

MITRE and NIST connect data theft to defensive data-loss controls

2026MITRE ATT&CK / NISTCross-sector

MITRE ATT&CK defines exfiltration as adversary behavior for stealing data, while NIST describes DLP as the ability to identify, monitor, and protect data in use, in motion, and at rest against unauthorized use or transmission.

Why this is evidence

The pair makes the attack-and-control relationship clear: defenders need to understand both how data leaves and how policy, classification, and telemetry can constrain that movement.

See the source — NIST: Data Loss Prevention — CSRC Glossary

Understand the mechanics

How it works

  1. 1

    An adversary identifies a condition where data exfiltration can provide access, control, information, or evasion.

  2. 2

    The attacker executes the technique directly or combines it with credentials, social engineering, exploitation, or trusted tools.

  3. 3

    Successful activity creates a new capability such as access, execution, persistence, privilege, movement, collection, or impact.

  4. 4

    Defenders investigate the surrounding identity, host, application, network, and cloud telemetry to determine scope and interrupt the attack chain.

Practice

What to watch for

  • Activity consistent with data exfiltration in identity, endpoint, email, application, cloud, or network telemetry
  • Unexpected authentication, privilege, execution, or data-access behavior
  • New or unusual infrastructure, domains, processes, tokens, or administrative actions
  • A sequence of events that matches a known adversary technique rather than normal business activity

Perform

What to do

  1. 1

    Stop or contain the risky activity without destroying useful evidence.

  2. 2

    Determine which identities, systems, applications, data, and sessions are affected.

  3. 3

    Revoke exposed access, isolate compromised assets, and block malicious infrastructure as appropriate.

  4. 4

    Hunt for related data exfiltration activity and adjacent attacker behaviors before declaring the incident contained.

How to reduce the risk

  • Classify sensitive data and know where it resides.
  • Limit access and sharing to business need.
  • Monitor unusual transfer, download, and egress patterns.
  • Apply encryption, retention, and DLP controls appropriate to risk.

Business impact

  • Data breach
  • Regulatory exposure
  • Intellectual-property loss
  • Customer trust damage

What different roles should do

Employee / Operator

  • Pause when an interaction or system behavior is unexpected.
  • Use approved verification and reporting paths rather than improvising.

Security

  • Correlate identity, endpoint, network, application, and cloud evidence.
  • Contain the attack path and hunt for follow-on activity.

Framework & standards context

  • MITRE ATT&CK TA0010

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02