Data Exfiltration Signs: How to Detect a Silent Data Theft

Data Exfiltration Signs: How to Detect a Silent Data Theft

Data exfiltration signs - Jaymon Security

1. Introduction

Ransomware screams; exfiltration whispers. While data hijacking produces a visible outage and ransom notes, the silent theft of information can go on for months without anyone noticing. The average lifecycle of an exfiltration breach is 258 days from initial access to containment, and the global average cost of a breach reached $4.88 million, according to IBM’s Cost of a Data Breach report. Detecting earlier is the lever with the highest return: breaches detected internally cost almost one million dollars less than those discovered by a third party.

This article is written for executives, IT managers and security teams that want to stop discovering the theft through a phone call from the police or a story in the news. We show you the complete attack chain, the data exfiltration signs that appear in the systems you already own, and a triage procedure that lets you respond without destroying the evidence.

2. The Exfiltration Chain in Six Phases

Data theft is not a single event: it is a chain built over weeks. The attacker starts by reconnoitering the target, obtains initial access, establishes persistence, moves laterally until they reach the valuable documents, collects and compresses them and, finally, transfers them out of the network while blending in with legitimate traffic. Every phase leaves traces if you know where to look:

Phase What the attacker does Where to look
1. Reconnaissance Profiles the company on LinkedIn and public sources OSINT, HIBP leaks
2. Initial access Spear phishing or valid credentials Email logs, Entra ID
3. Persistence Scheduled tasks and OAuth tokens Tasks, authorized apps
4. Lateral movement Credentials in memory, domain Events 4624, 4672, 4688
5. Collection Compresses data and prepares it Recent archives, DLP
6. Exfiltration Uploads data to MEGA, OneDrive, Dropbox or C2 Outbound traffic, NDR, CASB

Fig. 1 – The six-phase exfiltration chain and where to observe each phase.

The key observation is that the most silent phases are the last ones: collecting and transferring data generate no encryption alerts and no service outages, only patterns that deviate from normal behavior. That is why detection depends on knowing what is normal in your organization and on systematically monitoring the behaviors described below.

3. Five Data Exfiltration Signs You Should Not Ignore

3.1. Mass downloads and access to old resources

An employee downloads 40 gigabytes from SharePoint on a Friday at 10 p.m. A user opens repositories they have not touched for years. An application server reads invoicing files it never accessed before. Unusual read volumes on valuable documents — and especially access to old resources, a behavior that does not match normal work patterns — are among the first data exfiltration signs your team should watch for. The audit telemetry of SharePoint and OneDrive, together with file server telemetry, is where these patterns show up most clearly.

3.2. Impossible travel and sessions that do not add up

A sign-in in Madrid and, twenty minutes later, in another country. Or access from a distant region using a browser nobody in the company uses. Identity systems flag these patterns as impossible travel, and they are especially suspicious when no second factor was involved: it means the attacker is using a stolen session cookie, not a password. A UEBA needs between four and eight weeks learning the workforce’s normal behavior before it can separate the anomalous from the everyday; from that baseline on, every impossible travel event should open an investigation.

3.3. Forwarding rules and uploads to personal clouds

Forwarding rules on corporate mailboxes pointing to external accounts, uploads of internal documentation to personal Google Drive or Dropbox accounts, massive downloads to USB devices. These are among the easiest data exfiltration signs to automate: any Exchange Online administrator can list forwarding rules in minutes, and if a rule appears that nobody created, the mailbox is compromised or was. Review them periodically, not only when an investigation is open.

3.4. Compression and anomalous outbound traffic

Recent WinRAR or 7-Zip archives on file servers, especially password-protected ones. Nightly outbound volume toward cloud storage services you do not use. DNS or ICMP traffic with unusual patterns that could be exfiltration tunnels. Network detection and response (NDR) tools and cloud traffic inspection (CASB) are what capture this phase; without them, the SIEM sees little more than bytes leaving without explanation.

3.5. The invisible infostealer

Before all of the above lies the origin of the problem: infostealers. An infected personal device collects credentials and session cookies for M365, Slack or Salesforce in less than three minutes, and the log sells for a few dollars on markets such as Russian Market. The cookie lets an attacker impersonate the user without a password or MFA until it expires. Many breaches start like this, with an account whose owner never touched your perimeter; the common origin is an infected personal device, and pirated software is the classic distribution channel for this malware.

4. Triage: What to Do When a Sign Appears

When a sign is confirmed, the most expensive mistake is to overreact: powering off the server, rebooting the machine or deleting logs “so they do not take more data”. Each of those actions destroys the evidence the forensic team needs later. Correct triage isolates without powering off — through the EDR, the switch or the VLAN —, revokes sessions and captures memory dumps and logs before touching anything, following the order of volatility in RFC 3227.

# Triage on suspected exfiltration (PowerShell)
# 1. Suspicious forwarding rules in Exchange Online mailboxes
Get-Mailbox -ResultSize Unlimited | Get-InboxRule |
  Where-Object { $_.ForwardTo -or $_.RedirectTo } |
  Select-Object Identity, Name, ForwardTo, RedirectTo
# 2. Risky sign-ins in Microsoft Entra ID
Get-AzureADAuditSignInLogs -Filter "createdDateTime ge 2026-09-01"
# 3. RAM dump of the suspicious endpoint BEFORE powering it off
# (EDR collection module or Live RAM capture tool)

Fig. 2 – Basic triage commands to validate a suspected exfiltration.

If the incident is real, the forensic analysis must answer five questions: where the attacker entered, how far they got, what was stolen, whether they are still inside and who did it. An expert with chain of custody from minute one, aligned with ISO/IEC 27037, turns data into valid evidence for legal proceedings. And your insurer usually requires notification within a contractual 24 to 72-hour window: do not wait until the investigation is over.

5. The Cost of Detecting Late

Slowness has a price, and the price has been measured. The average cost of a breach was $4.88 million in 2024, 10% more than the previous year, and the average lifecycle was 258 days; when the breach involves stolen credentials, the lifecycle rises to 292 days. But the most interesting difference is the origin of detection: organizations that detect the breach internally save almost one million dollars and 61 days compared with those discovered by a third party.

That figure justifies the investment in the tools that feed detection: UEBA with a baseline, DLP in monitor mode for two or three months before moving to blocking, and proactive threat hunting with hypotheses based on threat intelligence. The price of all of it is small compared with the alternative of discovering the theft on the front page.

And which assets do attackers choose? The answer is predictable: Active Directory, source code repositories, ERP and CRM databases — anything that turns digital noise into leverage for a future negotiation. If the same files keep appearing in downloads, archives or outbound transfers, you are looking at a targeted operation, not curiosity. That pattern is exactly what proactive threat hunting with CTI-driven hypotheses is designed to surface: know what is valuable, watch it, review the alerts weekly, and the data exfiltration signs start making sense. If the telemetry to watch them is missing, buy it before the incident, not after.

6. Legal Obligations: The Clock Does Not Wait

Even the silent theft comes with loud legal obligations. If the breach involves personal data, you must notify the supervisory authority within 72 hours of becoming aware, under Article 33 of the GDPR, and if the risk is high, inform the affected individuals without undue delay. Organizations under NIS2 must send the early notification to the CSIRT within 24 hours and the full one within 72. DORA, for the financial sector, has its own sequence with an intermediate report within 72 hours. The deadlines run from awareness of the breach, not from identifying the actor.

None of these notifications requires exact figures: a preliminary report describing the nature of the incident meets the deadline. That nuance is decisive, because the most repeated mistake is waiting until the investigation is complete — and it is usually what costs the fine. Communication with the affected parties must be honest: minimizing the scope or promising solutions without verification destroys the trust the incident has already damaged. In Spain, the criminal path (Article 197 and following of the Criminal Code) is activated by the police report, and digital forensics prepared from the start is the basis of the process.

7. Conclusion

Data exfiltration signs are only useful if someone looks for them and acts: telemetry without analysis is noise. Build your organization’s baseline, automate searches for the five signs you have seen, rehearse the triage and have the legal protocol written down before you need it.

If you want to go deeper into how attackers exfiltrate data without leaving traces during real operations, our article on anonymous exfiltration and traces in Red Team operations shows you the offensive side of the problem. And to decide how much to protect the affected assets, a company risk analysis gives you the framework to prioritize. Silent theft is fought with constant observation: the sooner you see the sign, the cheaper the end of the story.

Need help with Data exfiltration signs?

At Jaymon Security, we help organizations protect their systems. From security audits to SIEM/SOC implementation, our expert team designs custom solutions.

Contact us for a free infrastructure assessment.

No puedes copiar el contenido

ENES