# What is Data Exfiltration?

> Data exfiltration is the unauthorized transfer of data from a system, service, device, or organization to a location or party that should not receive it.

- Canonical URL: https://yellowcube.eu/glossary/data-exfiltration/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It may be performed by an external attacker, a malicious or careless insider, compromised software, or an abused third-party connection.

Exfiltration can be fast and obvious or divided into small transfers that blend into ordinary activity. Channels include cloud storage, email, web uploads, messaging, remote administration tools, DNS, encrypted tunnels, removable media, printing, and photographs. Investigation should determine what data was transferred, which account, process, device, and path were involved, who or what received it, and whether the transfer succeeded.

### Key points

- **Prevention:** Least privilege, data classification, segmentation, controlled egress, DLP, secure collaboration, and well-governed third-party access.
- **Detection:** Endpoint, identity, network, cloud, application, and data-access telemetry examined in business context.
- **Response:** Preserve evidence, contain the path, protect affected identities, assess the data and recipients, and meet notification duties.
- **Important limitation:** A large transfer is not necessarily malicious, while a small transfer may contain the organization’s most sensitive information.

### Related terms

[Data loss prevention (DLP)](<https://yellowcube.eu/glossary/data-loss-prevention/>) · [Data breach](<https://yellowcube.eu/glossary/data-breach/>) · [Insider threat](<https://yellowcube.eu/glossary/insider-threat/>) · [Ransomware](<https://yellowcube.eu/glossary/ransomware/>) · [Data classification](<https://yellowcube.eu/glossary/data-classification/>) · [File-sharing security](<https://yellowcube.eu/glossary/file-sharing-security/>)

### Sources

[NIST glossary: Exfiltration](https://csrc.nist.gov/glossary/term/exfiltration) · [MITRE ATT&CK: Exfiltration](https://attack.mitre.org/tactics/TA0010/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

