Back to glossaryCyber

Data exfiltration

Unauthorized transfer of data outside an organization's controlled perimeter, constituting the key component of double extortion and a trigger for regulatory obligations.

Definition

Data exfiltration is the unauthorized transfer of information from an organization's information system to an external destination controlled by an attacker. It is a central element of ransomware double extortion, since it is the threat of publishing that data that creates additional pressure on the victim beyond simple encryption. Exfiltration channels are varied: DNS tunneling (concealing data inside legitimate DNS queries), exfiltration via HTTPS to standard cloud services, transfer through legitimate synchronization tools such as Mega or OneDrive, or direct transmission to command-and-control servers. From a regulatory standpoint, an exfiltration of personal data constitutes a data breach under GDPR, triggering a notification obligation to the supervisory authority within 72 hours and, depending on severity, notification to the affected individuals. For the cyber insurer, exfiltration enriches the loss with several components: notification costs, credit monitoring for affected individuals, potential regulatory fines and civil liability defense costs. Establishing the precise extent of the exfiltration is often difficult, generating uncertainty in the quantification of the loss.

Example

During a ransomware attack against a healthcare operator, the attackers exfiltrate 500,000 medical records to an anonymous server before encrypting the systems. The institution must notify the supervisory authority, individually inform patients, fund 12 months of data monitoring and face liability claims, pushing the total cost far beyond the ransom alone.

Related terms
Also known as

exfiltration, vol de données, data exfiltration, data breach exfiltration