Security & governance · Glossary term

What is Data Exfiltration?

Unauthorized transfer of protected data from a system or trust zone to a person, tool, service, or storage location that is not permitted to receive it.

Why does Data Exfiltration matter?

An agent can expose secrets through generated text, tool arguments, URLs, logs, or side effects even when the original data store remains intact.

Data Exfiltration in practice

Minimize readable data, allowlist destinations, inspect outbound tool calls, redact sensitive fields, and alert on unusual transfers across trust boundaries.

What is the common confusion about Data Exfiltration?

Exfiltration is about unauthorized movement or disclosure. Ordinary retrieval of data by an authorized component is not exfiltration, although later use can become one.

Learn Data Exfiltration in the course

Start with

  • EchoLeak and the Emergence of CVEs for AI

    CVE-2025-32711 "EchoLeak" (CVSS 9.3) was the first publicly documented zero-click prompt injection in a production LLM system (Microsoft 365 Copilot).

    Phase 18: Ethics, Safety & Alignment

Taught in Phase 18: Ethics, Safety & Alignment.

  • Trust BoundaryAn interface where data, instructions, identity, or authority crosses between components or principals that operate under different trust…
  • Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
  • Indirect Prompt InjectionA prompt-injection attack delivered through content the system retrieves or observes, such as a webpage, document, email, image text, or…
  • Audit LogA durable, access-controlled record of security- or accountability-relevant events, including who or what acted, what changed, when it…

Sources

More terms in Security & governance

Open the Security & governance list in the glossary

This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.