Data exfiltration
Unauthorized transfer of information from the victim's systems to the attacker. It is the end goal of most intrusions.
Full definition
Data exfiltration is the unauthorized transfer of information from the victim's systems to a location the attacker controls. It is the phase that turns an intrusion into real loss: until the data leaves, the damage is still containable.
To avoid detection, the attacker disguises the outflow: compressing and encrypting files, sending them in small volumes mixed with normal traffic, or using legitimate cloud services as the destination. In double-extortion ransomware, exfiltration happens before encryption and underpins the threat of publication.
Detection relies on watching outbound traffic and anomalous access to sensitive repositories, and prevention on limiting who can read what: the attacker can only take what the compromised account could access.
Related terms
Data breach
An incident where protected information is accessed, stolen or exposed without authorization. Its credentials fuel the next attacks.
Ransomware
Malware that encrypts the victim's data and demands payment to release it. It now adds the threat of publishing what was stolen if no payment is made.
Account takeover (ATO)
Taking control of a legitimate account with stolen credentials. From inside, the attacker reads, impersonates and escalates without raising alarms.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.