Skip to main content
Get a Free Trial

What is Data Exfiltration?

Data Exfiltration Comes in Many Forms, and Most Amount to Theft

In simple terms, data exfiltration is the transfer of data from one system to another without authorization or consent. While sometimes an honest mistake by an innocent user, data exfiltration is most often performed by a malicious insider or outsider as a form of cybercrime. In this case, the attacker can either sell the stolen data on the black market, or threaten to do so in order to extort a payment from the victim—sometimes increasing the pressure by using ransomware to forcibly encrypt the victim’s own copy of the data. Given the sensitive nature of the data involved, which can include usernames and passwords, personal financial information, personally identifiable information (PII), cryptographic keys, and intellectual property, data exfiltration can be extremely damaging to the targeted organization.

Key Takeaways

  • Data exfiltration is the unauthorized transfer of data from one system to another. It is most often performed by a malicious insider or external attacker. Stolen data can be sold on the black market or used to extort payment from the victim.
  • Exfiltrated data can include passwords, financial information, PII, cryptographic keys, and intellectual property. The impact on targeted organizations can be severe. Attackers often combine data exfiltration with ransomware to maximize pressure.
  • Encrypted data exfiltration is invisible to most security tools. Attackers encrypt stolen data before transmitting it outside the network. Standard network security tools cannot detect what they cannot inspect.
  • SSL/TLS inspection is the primary defense against encrypted data exfiltration. Decrypting and inspecting traffic at scale allows organizations to catch attackers in the act. It also renders ransomware and malware hidden in encrypted traffic visible.

A data exfiltration attack typically occurs via the internet or a corporate network, often using a trojan or other malware, though physical media and even the theft of a server itself can also be involved. The hacker can use one of several common methods for data exfiltration to avoid detection while removing it, including encrypting the stolen data prior to transmission outside the corporate network, leaving the victim unaware of the crime. Best practices to prevent data exfiltration range from simple measures such as replacing default or weak passwords on remote access applications, to blocking unauthorized communication channels, educating users about the dangers of phishing attacks, and maintaining strict access control protocols.

How A10 Networks Helps Companies Avoid Data Exfiltration

When stolen data is encrypted before being transmitted outside the corporate network, it can’t be detected by network security tools, leaving the organization unaware that a crime is in progress. Ransomware and malware can be rendered invisible as well. A10 Networks Thunder® SSL Insight (SSLi®) allows organizations to decrypt and inspect network traffic at scale without impacting performance through a highly efficient approach to TLS decryption/SSL decryption. As a result, they can catch attackers in the act and prevent the exfiltration of sensitive data.


FAQs

Data exfiltration is the unauthorized transfer of data from one system to another. It is performed by malicious insiders or external attackers. Stolen data can include passwords, PII, financial information, and intellectual property.

A data breach is the unauthorized access to sensitive data. Data exfiltration is the next step: actively removing that data from the network. All exfiltration involves a breach, but not all breaches result in exfiltration.

Attackers encrypt stolen data before transmitting it outside the network. Standard security tools cannot inspect encrypted traffic. This makes the exfiltration invisible until SSL/TLS inspection is deployed to decrypt and analyze outbound traffic.

Effective prevention requires SSL/TLS inspection, strict access controls, and monitoring of outbound traffic. Replacing weak passwords, blocking unauthorized communication channels, and educating users about phishing attacks are also essential measures.

5 Steps to Enhance Your Enterprise Security with High Performance SSL/TLS Decryption

Get the eBook
< Back to Glossary of Terms