Spotting Data Exfiltration: Unusual Traffic and Cloud Logins

When people think of a cyberattack, they picture encryption and ransom notes. But in many incidents, attackers quietly copy data first, sometimes days or weeks before anything else visibly goes wrong. That copying is called data exfiltration. For healthcare and senior-living organizations, it can mean resident records, employee information and financial data leaving the building.

The encouraging part is that exfiltration usually leaves evidence. You do not need a large security team to learn the signs. You need to know what to look for and make sure the right logs are switched on and reviewed.

What Exfiltration Looks Like

Attackers move data out through several routes:

Direct transfers to external servers over the internet

Cloud storage uploads to file-sharing services

Email, including forwarding rules and large attachments

Removable media such as USB drives

Abused legitimate tools, such as remote access or backup software

Compromised cloud accounts that download or sync files from email and document libraries

Warning Signs

In Network Traffic

Unusually large outbound transfers, especially at odd hours

A workstation or server sending far more data than normal

Connections to unfamiliar countries or newly seen destinations

Repeated traffic at regular intervals that could indicate automated activity

Use of file transfer or sync tools that are not part of normal business

In Cloud and Email Accounts

Sign-ins from unusual locations, devices or impossible travel patterns

Many failed sign-ins followed by a success

New forwarding rules or mailbox permissions

Mass downloads or file access from document libraries

New sharing links, especially anonymous links, created in bulk

New apps connected to an account with permission to read mail or files

On Devices and Servers

Unexpected compression of many files into archives

Security tools being turned off

Unfamiliar remote access software installed

Large numbers of files accessed in a short time by one account

Which Logs Reveal It

Firewall and Network Logs

Firewalls record connections, destinations and volumes. Reviewing top outbound destinations and data volumes by device reveals outliers. Make sure logs are retained long enough to investigate, since incidents are often discovered weeks later.

Cloud Audit Logs

Microsoft 365 and Google Workspace record sign-ins, file access, sharing events, mailbox rule changes and administrative actions. Confirm audit logging is enabled and check how long records are kept, since the default may be shorter than you need.

Identity and Sign-In Logs

These show where and how accounts authenticate, including failed attempts, new devices and changes to multi-factor authentication methods.

Endpoint Security Logs

Endpoint detection tools record process activity, file movement, removable media use and tool tampering. They often provide the clearest picture of what happened on a specific device.

DNS and Web Filter Logs

These show which sites devices contact, including newly registered or suspicious domains and uploads to file-sharing services.

Application Logs

Record systems and other applications log who accessed which resident records. Unusual volume or off-hours access can indicate misuse.

Build Simple Detection Habits

Turn on logging first. You cannot investigate what was never recorded.

Set alerts for the highest-value signals: new forwarding rules, impossible travel sign-ins, mass downloads, disabled security tools and large outbound transfers.

Know your normal. Baselines make unusual activity stand out. Note typical traffic volumes and working hours.

Review regularly. A weekly look at key reports is better than nothing, and alerts catch what reviews miss.

Centralize if possible. Collecting logs in one place makes correlation easier.

Reduce What Can Leave

Detection works best with prevention:

Restrict USB storage on sensitive systems

Limit outbound traffic to what is needed

Use data loss prevention features for sensitive information

Require multi-factor authentication everywhere

Limit who can share files externally

Apply least privilege so accounts can reach only what they need

If You Suspect Data Is Leaving

Do not power off systems unless advised, since volatile evidence may be lost; isolate affected devices from the network instead.

Disable compromised accounts and revoke active sessions.

Preserve logs.

Contact your incident response resources, legal counsel and cyber insurer.

Determine what data was involved and evaluate obligations under the HIPAA Breach Notification Rule.

How UnityCare IT Helps

UnityCare IT helps healthcare organizations enable the right logging, set alerts for signs of data theft and review activity, so suspicious movement gets noticed while there is still time to act.

Related service

Microsoft 365, cloud storage and tested backups with access controls built in.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172