Data Exfiltration
Data exfiltration is the unauthorised removal of data from an organisation, often for extortion purposes.
Data exfiltration is the unauthorised transfer of data from an organisation. Attackers use the stolen information for extortion, espionage or resale.
How it works
Attackers first gather valuable data like contracts, customer details or personnel files. They often compress this data into archives before transferring it externally. Methods include using cloud storage, file transfer tools, encrypted web connections or DNS. With ransomware attacks, exfiltration usually occurs before the files are encrypted. The attackers then threaten to publish the stolen data.
An example from practice
A server uploads 40 GB to an unapproved cloud storage provider overnight. An archiving tool was launched on the server just before the upload. NDR detects the unusual data volume, while EDR shows the responsible process. The SOC interrupts the connection and isolates the server to stop the attack.
What to look out for
- Monitor outbound data volumes, particularly during nights and weekends.
- Restrict the use of cloud storage and transfer services to approved providers.
- Look for archiving tools on servers that do not normally create archives.
- Know where your sensitive data is stored to assess potential damage accurately.
Switzerland and regulation
If personal data is exfiltrated, you must assess under the revFADP (revised Federal Act on Data Protection) whether a high risk for the affected individuals is likely. If so, the Federal Data Protection and Information Commissioner (FDPIC) must be notified as soon as possible. Financial institutions and critical infrastructure operators have additional reporting duties to FINMA and the National Cyber Security Centre (NCSC).
How it relates to DLP
DLP solutions can help to detect or prevent the outflow of specific data. However, they are rarely sufficient against an attacker who has administrator rights. A combination with NDR, EDR and cloud logs is more effective.
Typical mistakes
Often, organisations cannot determine what data was stolen after an incident. This happens because network and proxy logs were not retained long enough. This lack of information complicates breach notifications and damage assessment.
How we implement it
We detect unusual data outflows using NDR, EDR and cloud logs, stopping them within our mandate. We provide available data about the incident's scope to support your reporting decisions.