TACTIC: EXFILTRATION

Exfiltration Over Web Service (T1567): real cases

MITRE Definition ↗
Adversaries exfiltrate sensitive files to legitimate cloud storage providers like Mega or Google Drive.

Key Facts

Technique ID
T1567
Exfiltration
Mapped Cases
7
Primary sources
Related Laws
4
Criminal statutes
  • ATT&CK Technique Identifier: T1567.
  • Tactical Phase: Exfiltration.
  • Substantiated in 7 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 18, Page 9
"Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts."
U.S. District Court for the District of New Jersey View full case dossier →
Primary Source Evidence Excerpt: SEC Form 8-K Disclosure
"Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom."
U.S. District Court for the District of Minnesota View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 26, Page 13
"Operatives packaged stolen records containing names, Social Security numbers, and birth dates into compressed archives and exfiltrated them to overseas staging servers."
U.S. District Court for the Northern District of Georgia View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 11, Page 5
"Using multithreaded cloud CLI commands, the defendant downloaded over 700 S3 buckets containing approximately 100 million credit card applications, Social Security numbers, and bank account details."
U.S. District Court for the Western District of Pennsylvania and Western District of Washington View full case dossier →
Primary Source Evidence Excerpt: UnitedHealth Group 8-K Regulatory Filing
"Adversaries exfiltrated approximately 6 terabytes of highly confidential medical claims, patient clinical history, and billing records to cloud storage repositories prior to encryption."
U.S. House Energy and Commerce Committee Oversight & HHS OCR View full case dossier →
Primary Source Evidence Excerpt: CISA Advisory AA24-165A
"Attackers generated time-limited pre-signed Amazon S3 storage URLs using tenant privileges, transferring hundreds of terabytes of relational data directly to adversary-controlled cloud infrastructure."
U.S. Securities and Exchange Commission & FBI Cyber Division View full case dossier →
Primary Source Evidence Excerpt: FCC Formal Notice of Inquiry into AT&T Cloud Breach
"The threat actor exfiltrated phone numbers, call durations, and cell tower interaction identifiers covering May 1 to October 31, 2022."
U.S. Securities and Exchange Commission & DOJ National Security Division View full case dossier →

Commonly Charged Criminal Statutes

18 U.S.C. § 1030(a)(2)

Unauthorized Access to Obtain Protected Information

Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.

18 U.S.C. § 1030(a)(5)(A)

Intentional Damage to a Protected Computer

Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.

18 U.S.C. § 1030(a)(7)

Extortion in Connection with Computers

Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.

18 U.S.C. § 1030(b)

Conspiracy to Commit Computer Fraud

Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.