Most breach prevention advice, including our own guide to preventing data breaches, is focused on keeping attackers out of your business network. Using stronger credentials, phishing resistance, patched systems, vetted suppliers are all key components of this practice. They’re all essential practices, but they can’t be your only data breach protection tactics: they won’t support you if an attacker manages to breach your network.
Gaining access and data theft are different. An attacker who compromises one inbox, one laptop, or one supplier connection has not yet stolen anything. They’ve gained a foothold, and what happens between that foothold and the moment data leaves the building is a phase most SMB security guidance skips entirely, because it isn’t just about securing your network; it’s also about noticing that data is being moved outside of it.
This phase is called exfiltration, and it typically lasts for days or even stretches across months undetected. It’s possible because of tools and channels that look completely ordinary to anyone not specifically watching for them. Breach notifications frequently arrive late not because organizations were careless about the initial compromise, but because the attacker wasn’t detected inside the business network.
The exfiltration phase: what happens between access and theft
What data exfiltration looks like
Why is exfiltration difficult to spot?
What businesses should monitor for
How early detection can change your legal position
What happens to exfiltrated business data?
Contain what an attacker can reach
The exfiltration phase: what happens between access and theft
Once an attacker gains initial access, whether through a phishing email, a stolen credential, or a compromised supplier connection, they rarely move straight to stealing data. Acting immediately risks triggering an alert before they’ve found anything worth taking, so the more common pattern is patience.
The attacker spends time mapping the environment, including:
- Where financial records are stored
- Assessing which SaaS tools contain customer data
- Locating accounts with the broadest access
- Detecting whether activity monitoring, if any, is in place.
This reconnaissance stage can be slow. Some attackers move within hours, particularly in opportunistic ransomware cases where speed matters more than stealth. Others, especially in cases built around long-term data theft or espionage, stay embedded for weeks or months, learning normal patterns of activity well enough to blend into them.
Either way, by the time the attacker starts moving data out, they usually already know exactly what they want and which account or system will let them take it without tripping an alarm.
What data exfiltration looks like
Malicious exfiltration is difficult to spot because it looks like everyday activity. IT admins aren’t looking for slightly larger file transfers than usual or folders synced somewhere they shouldn’t be.
Large or unusual data transfers
This is the most direct form of exfiltration. For example, an account may suddenly pull gigabytes from a file server or database it normally touches only occasionally, or bulk export from a CRM or HR platform.
In SaaS-heavy environments, exfiltration often happens through the platform’s own export features: bulk CSV downloads, PDF exports of customer records, or a sequence of screenshots taken of a dashboard that doesn’t have an export button at all.
A typical case might look like this: a compromised HR account is used, over several weeks, to run small, staggered exports of employee records rather than one obvious bulk download. Each individual export looks unremarkable on its own, well within what an HR platform expects someone in that role to do.
It’s only the pattern across weeks, the same account exporting similar data at odd intervals, that would reveal what’s happening, and that pattern only becomes visible to a business that’s looking for it.
Inbox compromise
An attacker who compromises a business email mailbox can set up a rule that silently copies every message, or every message matching certain keywords, to an external address, giving them an ongoing feed of sensitive correspondence long after the original phishing email is forgotten.
Cloud storage compromise
Personal cloud storage is another common route. An employee’s compromised laptop, or a compromised account with access to company files, can be used to copy documents into a personal Dropbox, Google Drive, or similar service, a transfer that often looks identical to a legitimate file backup unless someone is checking where the data ended up.
Why is exfiltration difficult to spot?
The uncomfortable truth about exfiltration is that it usually doesn’t require any malware(새 창) at all. An attacker using a compromised account to export a report, forward some emails, or upload files to a cloud drive is using the same tools and permissions a legitimate employee uses every day.
There’s no suspicious executable for antivirus software to flag, or any unusual processes for endpoint detection to catch, because nothing about the activity is technically abnormal. It only looks wrong in context, and context is exactly what most SMB security tooling isn’t built to evaluate.
This is why perimeter-focused defenses, however well implemented, aren’t enough on their own. A business can do everything right at the point of entry, enforce strong credentials, train employees against phishing, patch every system, and still have no way of knowing that a compromised account is steadily moving files to an external destination, because that activity was never designed to look suspicious in the first place.
Security researchers sometimes call this “living off the land”: using the target’s own legitimate software, cloud integrations, and administrative tools rather than using any tools that an antivirus product would recognize as illegitimate.
A file sync client, a built-in export feature, or a standard email rule aren’t malicious tools in themselves. This is why an attacker who relies on them can operate for so long without setting off anything designed to catch malware.
What businesses should monitor for
Catching exfiltration early comes down to watching for a small number of specific signals, rather than scanning broadly for suspicious activity.
Traffic and exports
Unusual data transfer volumes or destinations deserve the closest attention. Your organization should be watching for a spike in outbound traffic, a bulk export from a system that doesn’t normally see them, or any transfer heading to a destination you don’t recognize.
The NCSC’s guidance on data security(새 창) specifically recommends logging access to sensitive data and monitoring for unusual queries or attempted bulk exports, precisely because that pattern is a sign that something has moved beyond normal use.
Email forwarding rules
Email forwarding rules are worth auditing directly, especially for any account that has been involved in a suspected phishing incident. A rule quietly forwarding messages to an unfamiliar address can sit unnoticed for months, and it’s one of the simplest things to check once you know to look.
Unusual logins
Login activity from unexpected locations or times is a signal worth taking seriously. A login at 3 AM from a country the business has no presence in isn’t proof of anything on its own, but when cross-referenced with a data transfer around the same time, it’s a detail that can confirm an incident.
Admin account activity outside business hours deserves particular scrutiny, since admin accounts typically have the broadest reach into a system and are a preferred target precisely because of that reach.
Activity on these accounts late at night, on weekends, or during a period when the actual administrator is known to be out of office is one of the more reliable indicators that an account, not just a device, has been compromised.
How early detection can change your legal position
Under both EU GDPR and UK GDPR, Article 33(새 창) gives organizations 72 hours to notify the relevant supervisory authority once they become aware that a breach affecting personal data has occurred; the ICO in the UK(새 창) or the national data protection authority in each EU member state.
The requirement is materially the same for all jurisdictions: the clock starts for your organization at the moment of awareness, not from the moment the breach actually happened. This is why thorough exfiltration monitoring matters so much for compliance, not just security.
A business that detects exfiltration early, through forwarding-rule audits, transfer monitoring, or unusual login alerts, can notify proactively, on its own timeline, with a reasonably clear picture of what was taken.
A business that only discovers a breach weeks or months later, often because a customer complained or stolen data surfaced on a criminal forum, is notifying reactively, under pressure, often with an incomplete picture of scope and a regulator asking why it took so long to notice.
The difference goes beyond how your reputation is affected. It shapes how the entire incident is assessed, and how much latitude a regulator is inclined to extend.
What happens to exfiltrated business data?
Proton’s Data Breach Observatory tracks what surfaces on the dark web once a breach has occurred, and the pattern is a useful reality check on what exfiltration is really after.
According to the 2026 Data Breach Observatory update, names and email addresses appear in nearly nine out of ten tracked breaches, contact details such as phone numbers and physical addresses show up in roughly three-quarters of them, and passwords are exposed in close to half.
More sensitive categories, government-issued IDs, health records, and other personally identifiable information, appear in just over a third of breaches, while direct financial information shows up in a smaller share, around one in twenty.
SMBs make up the majority of breaches the Observatory tracks, and they are disproportionately represented among the incidents involving the most sensitive data categories.
This combination, frequent targeting and a high rate of sensitive-data exposure, is consistent with the type of exfiltration this article describes: attacks that occur over a long period of time within a smaller organization’s systems tend to pay more dividends, because nobody knew that data was being leaked and attackers could take everything.
Contain what an attacker can reach
Exfiltration monitoring catches data on its way out, but the size of the problem is decided earlier, by what a compromised account can reach in the first place. An attacker who gains access to an account with broad, unrestricted permissions can pull from far more systems than one who compromises an account scoped tightly to what that specific role needs.
Unique credentials on every account, combined with access limited to what a role genuinely requires, directly shrinks the exfiltration surface. If a compromised marketing account can only reach marketing systems, the worst-case scenario is bounded by design, rather than depending on an attacker’s restraint or a monitoring system catching them in time.
This is the same containment logic that limits blast radius in a credential-based breach generally: the account that gets compromised should only ever be able to leak what it was legitimately allowed to touch.
A business password manager like Proton Pass for Business makes this scoping realistic to maintain, since it removes the temptation to reuse a convenient set of broad credentials across tools simply because managing unique ones by hand doesn’t scale.
When every account has its own credential and access is reviewed against what a role actually needs, a single compromised account stops being a route to the entire organization’s data and becomes, at worst, a contained incident.
Proton Pass for Business can support your business with:
- Customizable team policies that help you enforce your password policy with password requirements, mandatory two-factor authentication (2FA) and revoked data sharing rules
- Usage logs that allow you to see activity within your network, with additional support from our advanced high security program Proton Sentinel
- Groups organized by role, project or access level, simplifying access management and ensuring that every team member only has access to what they need.
Stop credential-based data exfiltration with a business password manager.






