Back to the glossary
    Data & leaksCybersecurity glossary

    Data exfiltration

    Unauthorized transfer of information from the victim's systems to the attacker. It is the end goal of most intrusions.

    Full definition

    Data exfiltration is the unauthorized transfer of information from the victim's systems to a location the attacker controls. It is the phase that turns an intrusion into real loss: until the data leaves, the damage is still containable.

    To avoid detection, the attacker disguises the outflow: compressing and encrypting files, sending them in small volumes mixed with normal traffic, or using legitimate cloud services as the destination. In double-extortion ransomware, exfiltration happens before encryption and underpins the threat of publication.

    Detection relies on watching outbound traffic and anomalous access to sensitive repositories, and prevention on limiting who can read what: the attacker can only take what the compromised account could access.

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.