TL;DR: A customer-support account on a managed device downloaded 63 confidential financial archives from Google Workspace and uploaded them to Discord, while per-file DLP allowed every transfer because it could not interpret the sequence, according to Artemis Security. The case proves exfiltration detection must rank user-baselined behaviour and destination changes, not isolated file verdicts.
At a glance
What this is: This is a sequence-based exfiltration analysis showing that legitimate-looking file transfers can still constitute theft when the download-to-upload pattern is measured against user baseline.
Why it matters: It matters because IAM, DLP, and insider-risk teams need to detect data movement patterns, not just file-by-file policy verdicts, across human identities and managed endpoints.
By the numbers:
- The account downloaded 63 confidential financial archives before uploading them to a personal Discord account.
- The detection point fired on 41 files in a 12-minute window from a sensitive SaaS.
👉 Read Artemis Security's analysis of sequence-based exfiltration from Google Workspace to Discord
Context
The core governance problem is that file-by-file allow decisions can miss the meaning of a sequence. A legitimate user on a managed device can still move a coherent, high-value set of confidential records out of a corporate environment in a way that only becomes obvious when the transfer pattern is compared with that account's own history.
This is a human identity and data-loss problem, not a malware story. The account had access, the endpoint controls saw each file, and the movement still represented exfiltration because the destination changed, the volume spiked, and the data formed a deliberate three-year financial set. That starting position is common in enterprise environments.
Key questions
Q: How should security teams detect exfiltration when every file transfer is individually allowed?
A: Correlate the full sequence, not the per-file verdict. A burst of downloads from a sensitive SaaS followed by uploads to a new personal destination is the exfiltration signal, especially when the destination is first-time for that account and the transfer volume exceeds its normal baseline.
Q: Why do authorised users still create serious data-loss risk in managed environments?
A: Because authorisation to access data is not the same as authorisation to remove it in bulk. When a legitimate account can gather a coherent record set and send it to an external destination, the organisation has an identity and sequence problem, not just a malware problem.
Q: What breaks when security teams rely only on DLP alerts?
A: Alert-only DLP creates a reactive model that identifies exposure after data has already spread. By the time teams investigate, sensitive information may exist in multiple tools, making containment slower and more complex. Effective programmes need immediate enforcement, not just notifications, so risky copying, sharing, or pasting can be stopped at the point of movement.
Q: Who should own response when a support account moves confidential archives to a personal channel?
A: Identity, endpoint, and insider-risk teams should share ownership because the event spans access, device trust, and data movement. The response should focus on containment of the account, review of the destination channel, and validation of whether the session was deliberate or compromised.
Technical breakdown
Why per-file DLP verdicts miss sequence-level exfiltration
Per-file DLP makes a decision on each object in isolation. That model works for simple policy enforcement, but it fails when the abuse lies in the relationship between events: a burst of downloads from a SaaS, followed by uploads to a personal or messaging destination minutes later. The security meaning only appears when telemetry from browser, endpoint, and SaaS logs is correlated into one chain. In this case, the user was authorised, the device was managed, and every transfer looked individually permissible. The control gap was not lack of visibility into files. It was lack of sequence interpretation.
Practical implication: move from per-file allow or block logic to sequence correlation across download, upload, and destination change events.
Why account baselines matter more than static thresholds
Static thresholds tell you when activity is large. Baselines tell you when activity is unusual for a specific identity. Artemis reconstructed the event against the account's own history and found first-ever Discord activity, a jump far beyond prior single-day transfer behaviour, and a coherent set of three years of financial records. That combination is stronger than raw volume alone because it distinguishes routine business handling from a one-off export of sensitive material. Identity-aware detection becomes essential when the user is legitimate but the behaviour is not.
Practical implication: baseline external destinations and transfer volume per user so first-time exfiltration channels stand out immediately.
How coherent data sets signal deliberate collection, not routine work
A coherent archive set often matters more than the fact that files are labelled confidential. Three consecutive years of monthly invoice records is a curated business collection, not random access. When many related files leave in a short window and then appear in a personal destination, the pattern indicates intentional assembly and removal of a business record set. DLP products that do not understand collection shape cannot tell the difference between operational access and exfiltration. The architecture problem is context loss across SaaS, endpoint, and destination telemetry.
Practical implication: score not just count and sensitivity, but whether the transferred files form a coherent business record set.
Threat narrative
Attacker objective: The objective was to remove confidential financial records from corporate control without triggering a traditional block event.
- Entry occurred through a legitimate customer-support account accessing confidential files in corporate Google Workspace from a managed device.
- Escalation took the form of bulk access and sequence abuse, where 63 archives were collected and then moved to a personal Discord account within minutes.
- Impact was exfiltration of a coherent three-year financial record set while every per-file control verdict still read as allowed.
Breaches seen in the wild
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
- DeepSeek breach — DeepSeek breach exposed 1M+ log lines and sensitive secret keys.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Per-file allow decisions are not exfiltration controls. This case worked because the control plane judged each file independently and never evaluated the sequence as a theft event. That is a governance failure, not a tuning issue. Organisations that rely on file verdicts without behavioural correlation are assuming that malicious intent will appear in a single object rather than across an access pattern, which is rarely true in insider-style theft. The implication is that exfiltration detection has to be sequence-aware, not verdict-aware.
Identity baseline, not file sensitivity, is the decisive signal. The account had legitimate access to confidential data, so sensitivity labels alone could not separate normal work from misuse. What changed was destination, cadence, and volume against the account's own history. That is the right unit of analysis for human identity abuse: the same permission set can support ordinary support work or deliberate removal of records. Practitioners should treat identity behaviour as the control boundary.
First-time destination use is a high-value governance signal. A managed device and authorised session do not eliminate risk when a user reaches a destination the account has never used before. This is the point where DLP, browser control, and insider-risk telemetry should converge. The specific concept here is identity blast radius: the amount of data that can leave before the organisation realises the destination change matters. Teams need to model that blast radius explicitly.
Coherent record sets expose intent faster than raw file counts. Three years of consecutive monthly financial archives is a business record set with shape and purpose. When that kind of collection leaves in one sitting, the question is no longer whether each file was confidential, but whether the transfer pattern matches an authorised business process. That shifts governance from content inspection to contextual loss detection, which is the right posture for human identity-driven data theft.
From our research:
- From our research: Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities. according to The State of Non-Human Identity Security.
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which shows how identity boundaries fail when access is delegated across systems.
- Use Ultimate Guide to NHIs , Key Challenges and Risks to connect visibility gaps with the same lifecycle and governance weaknesses that make sequence-based exfiltration hard to spot.
What this signals
Identity programmes should expect more abuse that looks legitimate at the point of transfer and malicious only in sequence. The practical shift is from file verdict management to behavioural correlation across endpoint, SaaS, and browser telemetry, with destination novelty treated as a first-class risk signal.
Identity blast radius: the real control question is how much sensitive data a single account can remove before the organisation recognises the pattern. That means DLP, insider-risk, and IAM teams need shared baselines for external destinations, transfer shape, and account-specific volume drift, not separate dashboards that never reconcile.
For broader identity governance context, the same blind spot appears in delegated access models where legitimate authority outlives practical oversight. When access is allowed to look normal while the outcome is abnormal, the programme needs context-rich detection rather than more permissive exceptions.
For practitioners
- Correlate download-to-upload sequences Link SaaS audit logs, endpoint telemetry, and browser events so bulk downloads followed by personal or messaging uploads are scored as one exfiltration chain.
- Baseline external destination behaviour per account Track first-ever use of destinations such as Discord, personal cloud, and webmail, then alert when an identity reaches a new external channel with sensitive data.
- Detect coherent record-set movement Flag transfers where related archives, invoices, or source trees leave together in a short window because collection shape often indicates deliberate exfiltration.
- Treat DLP allow verdicts as telemetry only Use allow outcomes to inform triage, but do not treat them as clearance when the same account shows unusual volume, new destinations, and a sensitive data cluster.
- Check for account-takeover signals around the transfer window Separate deliberate insider behaviour from compromised-session behaviour by reviewing concurrent authentication anomalies, impossible travel, and session integrity around the same timeframe.
Key takeaways
- This case shows that a legitimate account can still exfiltrate sensitive records when defenders look at file transfers one at a time instead of as a sequence.
- The evidence was not just volume, but a first-time personal destination, a coherent three-year record set, and behaviour far outside the account's own baseline.
- Teams that want to catch this pattern need behavioural correlation, destination novelty detection, and shared ownership across IAM, DLP, and insider-risk operations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-1 | Continuous monitoring fits the need to correlate download and upload behaviour. |
| NIST SP 800-53 Rev 5 | AU-6 | Audit review is central when per-file logs must be interpreted as one sequence. |
| NIST Zero Trust (SP 800-207) | Zero trust helps frame the need to verify destination and context, not just access. | |
| NIST SP 800-63 | SP 800-63B | Authentication context helps distinguish legitimate use from suspicious account behaviour. |
Apply zero-trust verification to sensitive SaaS and external destinations instead of trusting authorised sessions.
Key terms
- Sequence-Based Exfiltration: A theft pattern where the security meaning appears only across a chain of ordinary actions, such as downloading from one system and uploading to another. The individual events may be allowed, but the combined sequence shows data leaving organisational control.
- Identity baseline: A current inventory of identities, roles, entitlements, and effective permissions across environments. In Zero Trust, it is the starting point for deciding what should be trusted, reduced, or continuously verified, because controls cannot govern access that has not been discovered.
- Destination Novelty: A risk signal that appears when an identity uses an external channel, app, or storage location it has not used before. In practice, novelty matters because a first-time destination often reveals exfiltration sooner than a static file policy can.
What's in the full article
Artemis Security's full analysis covers the operational detail this post intentionally leaves for the source:
- The exact detection logic used to score the 41-file download burst and tie it to exfiltration
- The step-by-step reconstruction of the download-to-Discord chain across endpoint, browser, and SaaS telemetry
- The account-baseline comparisons that made first-ever Discord activity visible as a risk signal
- The triage sequence for separating allowed DLP verdicts from genuine theft indicators
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org