TL;DR: Coinbase’s $400 million breach underscores that insider-driven data loss often bypasses pattern-based DLP because the activity looks authorised until behavior is correlated across accounts, devices, and tools, according to Nightfall. The lesson for security teams is that data governance now depends on identity context and behavioral telemetry, not content matching alone.
NHIMG editorial — based on content published by Nightfall covering Coinbase’s insider breach and behavioral DLP gaps: State of Agentic Data Security 2026 Report
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: What fails when DLP only checks for sensitive content patterns?
A: Content-only DLP misses the most common insider-risk pattern, where authorised users move data through legitimate workflows that become suspicious only when viewed in sequence.
Q: Why do personal accounts and AI tools increase insider exfiltration risk?
A: Personal accounts and AI tools create exit paths that often look like normal work activity.
Q: How do security teams tell legitimate access from suspicious behavior?
A: They compare the user’s current actions with role-based baselines and account history.
Practitioner guidance
- Map authorised data paths by role Document which records, files, and systems each role can legitimately access, then define the account types and tools that should be in scope for monitoring, including personal email, cloud storage, and AI assistants.
- Correlate identity with destination behavior Join DLP events to identity attributes such as role, device, browser, and account boundary so that access from a personal account or unmanaged tool generates a higher-fidelity review case.
- Include physical exfiltration channels in policy Add USB use, printing, and screen-based transfer paths to the same monitoring and escalation process used for digital exports, because insiders often switch channels when content-based controls are weak.
What's in the full article
Nightfall's full report covers the operational detail this post intentionally leaves for the source:
- Monitoring logic for personal Gmail, Dropbox, OneDrive, and AI tools across employee workflows
- Correlation examples showing how browser switching, printing, and cloud uploads are combined into one investigation
- Nyx workflow detail for triaging noisy behavior events and surfacing high-confidence insider-risk cases
- Practical demos of identity-aware visibility across corporate and personal sessions
👉 Read Nightfall’s analysis of Coinbase’s $400 million insider breach and DLP blind spots →
Behavioral DLP for insider risk: what IAM teams need to see?
Explore further
Behavioral DLP is now an identity problem as much as a data problem. Pattern matching alone cannot distinguish normal access from misuse when the same person can move between corporate accounts, personal cloud services, and AI tools. The control gap is contextual trust, not content classification. For security programmes, the lesson is that DLP must be tied to identity, session, and destination awareness.
A question worth separating out:
Q: Who is accountable when insider data movement bypasses policy?
A: Accountability usually sits across security, identity, and data governance teams because the failure is cross-domain. IAM owns access scope, PAM owns elevated privilege, and data security owns classification and enforcement. If any one of those is missing, the organisation leaves a gap that insiders can exploit.
👉 Read our full editorial: Coinbase shows why DLP must detect behavior, not just content