Home  ›  Glossary  ›  Data Exfiltration

What is data exfiltration?

Data exfiltration is the unauthorized copying of data out of an organization's systems to a place an attacker controls. The original files usually stay where they were, so nothing looks missing. What is lost is control over who holds a copy.

Why data exfiltration matters for backup and recovery

Most ransomware groups now steal data before they encrypt it. The stolen copy gives them a second lever: even after the victim restores every system from backup, the attacker can still threaten to publish customer records, contracts or employee files. This is the basis of double extortion ransomware.

Backups answer one question, whether data can be brought back. Exfiltration raises a different one, who else now has it. A clean restore ends the outage but not the incident, and it does nothing about legal duties once personal data has been taken. Under GDPR Article 33, a controller notifies the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it.

How data is taken out

An exfiltration usually follows the same broad sequence.

  1. Finding the data. The attacker browses file shares, databases, mailboxes and storage buckets for what is worth stealing.
  2. Gathering it. Selected files are copied to one machine and packed into compressed, often encrypted archives, so their content cannot be inspected on the way out.
  3. Sending it out. The archives are uploaded, frequently to an ordinary cloud storage service the organization already uses, so the traffic blends in with normal activity.
  4. Staying quiet. Transfers are split up or spread over nights and weekends to stay below alert thresholds.

Bandwidth limits how much can leave. One terabyte over a 100 Mb/s uplink takes about 22 hours, so attackers pick the most valuable data rather than copying everything they can reach.

What data exfiltration means for backup teams

A backup repository is one of the most attractive places to steal from. It holds a complete, organized copy of the organization's data in one location, often going back months, including records that have since been deleted from production. An attacker who reaches the backup storage does not need to search the network share by share.

That changes how backup storage looks from a security point of view. Immutability decides whether backups can be deleted or encrypted; it says nothing about whether they can be read. A locked bucket can still be copied in full by any identity with read access. In a typical setup, the S3 key the backup software uses can read every object in the repository, and that key is stored on the backup server. Once the backup server is compromised, the entire backup history is readable.

Three things therefore decide exposure in a backup environment: which identities can read the repository, whether backup data is protected by backup encryption with keys kept somewhere other than next to the data, and whether anyone would notice an unusual bulk read. Encrypted backups turn a stolen copy into unusable ciphertext, as long as the key was not taken too. Audit logs held outside the storage system make a large read visible afterwards, which matters when the organization has to establish exactly what was taken for regulators, insurers or customers.

How data exfiltration relates to ARTESCA

S3 Object Lock on ARTESCA controls deletion and overwrite, not reads, so exfiltration is a separate question from immutability. ARTESCA's IAM-style access model lets a backup application's keys be limited to specific buckets and actions, and its audit logs can be forwarded to Splunk, Graylog, Elasticsearch or syslog, where bulk reads by one identity show up alongside other security events.

The ARTESCA Cyber Guarantee draws the same line. It is a one-time $100,000 payment if an external cyberattack encrypts or deletes data held on ARTESCA, subject to conditions that include S3 Object Lock in compliance mode, and data theft without encryption or deletion is excluded.

Related terms