Data exfiltration is the unauthorized removal of information from a network to an attacker-controlled location. The stolen data may be copied slowly over time or compressed into archives and sent out in a burst, often to cloud storage, a command-and-control server, or a leak site.
It matters because the theft of data can be as damaging as encryption. Attackers use exfiltrated payroll files, contracts, email, and internal documents for extortion, phishing, impersonation, and business email compromise. In real attacks, defenders look for unusual outbound traffic, large file transfers, archive creation, cloud-sync spikes, and access from compromised accounts. Logs from VPN, endpoint, proxy, email, and directory services help confirm whether a public leak claim reflects actual data removal or just threat actor noise.


