Data Security

Insider Data Exfiltration

Malicious or negligent insiders bypass perimeter controls because they already have access.

What it is

Insider threats range from malicious employees deliberately exfiltrating data before departure to negligent users who unknowingly send sensitive data to personal email or cloud storage. Departing employees are a particularly high-risk window — significant data exfiltration occurs in the weeks before resignation. DLP controls for email, USB, and cloud upload are the primary technical countermeasures, supplemented by user activity monitoring and access review.

Attack techniques

  • Email data exfiltration to personal account (T1048)
  • USB transfer (T1052.001)
  • Personal cloud sync (Dropbox, Google Drive) (T1567)
  • Bulk data download before departure
  • Credential sharing with external parties

Business impact

Insider data exfiltration is consistently harder to detect than external intrusion because access is legitimate. The signal is data volume and destination anomalies, not authentication failures.