risk
Data exfiltration and theft of information by attackers
Adversary (outsider, insider, nation-state, or competitor) installs malware or sniffers to locate and exfiltrate sensitive/proprietary information, or steals data by external actors — including systems-security losses from hacking.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Data Protection & Privacy
- Network & Communications Security
- Logging, Monitoring & Detection
- taxonomy
- nist-800-30-threat-event
- nist-800-30-threat-source
- basel-operational-risk
- coso-erm-risk
- inherent_rating
- critical
Details
- risk_id
- data-exfiltration-espionage
- category
- cyber_security
- likelihood
- medium
- impact
- critical
- inherent_rating
- critical
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-event
- nist-800-30-threat-source
- basel-operational-risk
- coso-erm-risk
Source
No record-specific source URL is provided.
Connections
- UC-NET-12 — Restrict communication-capable devices, ports, and sensors mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Disabling unneeded I/O ports/devices blocks removable-media exfiltration, and prohibiting remote camera/mic activation prevents espionage collection.
- UC-LOG-09 — Monitor providers and exchange audit data across organizations mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Reviewing provider logs and monitoring their activity detects data theft routed through third-party channels.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Data-leakage-prevention on systems/channels plus technical flow-control directly block exfiltration of sensitive data.
- UC-LOG-03 — Protect audit logs and retain them for required periods mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Protecting and retaining logs preserves the forensic evidence attackers would erase after locating and stealing data.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Monitoring for unauthorized connections and anomalous behavior (SI-4) detects exfiltration such as anomalous outbound transfers.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Correlating events (e.g., beaconing plus large transfers) against threat-intel indicators detects exfiltration patterns.
- UC-LOG-01 — Log security-relevant events across all systems mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Logging access to sensitive/regulated (e.g., cardholder) data provides a targeted detection input for locating and investigating exfiltration.
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Session and personnel-usage monitoring detects insiders locating or moving sensitive data for theft.
- UC-LOG-02 — Record complete audit content with synchronized clocks mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Complete, accurately time-synced records enable reliable reconstruction of an exfiltration timeline during investigation.
- UC-NET-14 — Enforce policy on cross-domain information exchange mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Enforcing mandatory cross-domain policy that permits only authorized data types and flow directions blocks unauthorized data egress between domains.
- UC-BCDR-13 — Operate continuous security protection services mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Malware and network defenses directly counter the malware and sniffers adversaries install to locate and exfiltrate data.
- UC-LOG-06 — Evaluate events and declare incidents against defined criteria mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Declaring data-breach incidents against defined thresholds and notifying regulators/individuals reduces the impact of data theft.