Duplicate » admin by request

Data Exfiltration Techniques: The Ways Attackers Move Stolen Data Out

Dark data center with rows of server racks and glowing orange lights; a burst of orange particles streams from a rack toward the floor.

Breaking into a network is only half the job. The part that pays is getting your data back out, and that final step (moving files from inside your environment to somewhere the attacker controls) is what turns a break-in into a breach notification, a regulatory fine, or a ransom demand.

Stealing data is the goal of most attacks, not a bonus on top of one. In the incidents Microsoft’s response teams investigated for its 2025 Digital Defense Report, attackers went after data in 80% of cases, with financial gain driving far more of that activity than espionage.

Knowing how attackers pull data out helps you spot it happening and cut it off before it finishes. The methods run from crude (copying files to a USB stick) to nearly invisible (hiding data inside traffic that looks completely ordinary).

Backups Won’t Save You From Exfiltration

Modern ransomware rarely stops at encryption. Attackers steal a copy of your data first, then encrypt what’s left, so paying for a decryption key doesn’t get you off the hook. They can still leak customer records, financials, or intellectual property. This is double extortion, and it’s been standard for years: the Maze group initiated it in November 2019, and today a ransomware hit with no data theft is the exception.

That’s what makes the stolen copy so valuable to an attacker. Backups can get your systems running again, but they can’t un-steal information that’s already sitting on someone else’s server. Encrypting your files is often just the loud finish to a theft that already happened out of sight.

The stolen data keeps earning after the fact, too. It can be sold, used to extort a second time, or mined for credentials that open the door to the next target. Once it’s gone, you’ve lost control of it for good, which is why the exfiltration step deserves as much attention as keeping attackers out to begin with.

Usb flash drive plugged into a dark computer port with red sparks and glow. » admin by request

How Attackers Move Data Out

The MITRE ATT&CK framework, a widely referenced catalog of real-world attacker behavior, treats exfiltration as its own tactic and documents the specific techniques adversaries use to get data across the boundary. Most incidents come down to a handful of recurring approaches:

  • Over the command-and-control channel: Attackers tuck stolen data into the same connection their malware already uses to receive instructions. To your network, it reads as ordinary beacon traffic rather than a theft in progress.
  • DNS tunneling: Data gets broken up and smuggled out inside DNS queries, traffic almost nobody blocks and few teams inspect closely.
  • Through web services: Files are uploaded to legitimate cloud storage or file-sharing platforms, blending in with the SaaS traffic your users generate all day.
  • In small chunks: Instead of one large transfer that trips an alarm, attackers split data into pieces small enough to slip under volume thresholds, moving it out slowly.
  • Over physical media: The low-tech route. Someone with hands-on access copies data to a USB drive and walks out with it.

The common thread is camouflage. Attackers want your data leaving to look like something you’d never question, whether that’s a routine cloud upload, a normal DNS lookup, or an encrypted session that resembles every other one.

That camouflage is exactly why exfiltration is so hard to catch in the moment. By the time an odd transfer stands out, the data is often already gone. Useful detection focuses on the behavior surrounding the theft: unusual access patterns, files being staged in places they don’t belong, and connections to destinations your systems have no reason to reach.

What Actually Stops It

Since exfiltration hides inside legitimate-looking traffic, the strongest defenses sit at the points where data leaves. Data loss prevention (DLP) tools inspect outbound content and can block sensitive files from going where they shouldn’t. Egress filtering controls which destinations your network is allowed to reach at all, closing off the channels attackers depend on. Cloud security controls do the same work for the SaaS and storage platforms that hold so much data now.

Those controls handle the movement of data, but it’s also worth limiting how much an attacker can collect before they even get to that stage, and that’s where privilege comes in. A compromised account or process running with permanent admin rights can reach far more files, install its own collection and transfer tools, and stage large volumes for a single pull.

Take those standing privileges away and the same compromise is boxed in: fewer files within reach, fewer tools it can install, less it can assemble before anyone notices. Just-in-time elevation, the model behind Admin By Request’s EPM solution, keeps admin access from sitting idle on endpoints waiting to be abused, which shrinks what any one compromise can accomplish.

Monitoring ties the two together. Logging outbound connections, watching for unusual staging, and alerting on transfers to unfamiliar destinations gives you a window to step in while an attack is still unfolding instead of learning about it later.

Glowing orange file folder on a dark computer monitor with floating cubes around it, suggesting data transfer. » admin by request

Guard the Exits, Shrink the Haul

No single control stops exfiltration, since the whole point of it is to look like traffic you already allow. What works is narrowing the ways data can leave and limiting how much any one compromised account can pull together before it tries.

If you’re rethinking how much standing privilege lives on your endpoints, our lifetime free plan covers up to 25 endpoints with the full feature set. It’s a simple way to see how just-in-time access limits what an attacker can do with a foothold.

About the Author:

Picture of Pocholo Legaspi

Pocholo Legaspi

Pocholo Legaspi is a content writer at Admin By Request, where he covers privileged access management, endpoint security, threat analysis, and the wider cybersecurity issues facing IT teams. With over a decade in content marketing and SEO and a master's in business informatics, he writes about complex security topics in a way that's clear and useful for the IT teams putting them into practice.

Share this blog to your channels:

Lifetime Free Plan for 25 Endpoints,
No Strings Attached.

Fill out the form to create your account and get started.

Book a Demo