# Data exfiltration

> Getting data out of a system that was not supposed to let it leave.

It is the step that turns access into a breach, and it is often the easiest part for an attacker, because systems are usually built to watch what comes in rather than what goes out. The channel can be anything that leaves: an API call, a DNS lookup, an image URL rendered in an email, a support ticket reply.

In AI systems the channel is frequently the answer itself. A model that can read internal documents and is asked, indirectly, to include something from them in a reply to a customer has exfiltrated data without anything that looks like an attack appearing in a log. This is the reason output filtering and egress control matter as much as input validation in agent architectures.

## Related terms

- https://dfieldsolutions.com/en/glossary/prompt-injection.md
- https://dfieldsolutions.com/en/glossary/owasp-llm-top-10.md
- https://dfieldsolutions.com/en/glossary/llm-agent.md

---

Source: https://dfieldsolutions.com/en/glossary/data-exfiltration
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
