HomeBlog

Exfiltration Vectors Compound. Your Protection Has to as Well.

October 5, 2026

•

1 min

Exfiltration Vectors Compound. Your Protection Has to as Well.
In This Article

AI didn't replace the old ways data leaves a company. It added new methods on top and gave insiders a way to chain them together. You only see the chain if one sensor watches humans and AI together.

If you spend enough time around CISOs / data security/ insider risk practitioners who have run these program for a decade you won't hear that AI is the only thing that matters. They've investigated departing employees with USB drives, contractors syncing files to personal Dropbox, and engineers AirDropping designs to their phones. They know none of those vectors went away when AI arrived

The vendor conversation tells a different story. Vendor launches and funding announcements can make it seem like data security began with shadow AI, coding agents, MCP servers, and AI browsers. Those risks are real. But the newest vectors aren’t the only ones that matter, and the older ones haven’t gone away.

Experienced teams know better. Each generation of work has added new ways for data to leave, and none of them has retired the previous ones. The vectors compound. A smart insider knows this too, and uses the seams between them.

AI Changed Work

The easiest way to see the problem is to look at how work itself has changed. For most of the last 25 years, work meant people moving data between people. Today, people use AI tools like agents to get work done.

Diagram: workflows stack over time, from human-to-human, to human-and-AI, to agent-to-agent

Three eras of workforce data exfiltration

When you map how things get down onto the workforce and a trend appears. Across the three eras, there is shift in where employees get data, who or what acts on it, and how it leaves.

An Analogy: Data Laundering

Think about how money laundering works. Criminals rarely move dirty money in one obvious transfer. They break it into pieces, move it through layers of accounts and businesses until it looks legitimate, and then bring it back into the open. Every individual transaction looks normal. Banks catch it by following the money across the whole path, instead of watching a single account.. Watching only Apple Pay transactions for example would not be able to surface it.

A smart insider does the same thing with data:

  • Placement: pull sensitive data from Salesforce, SharePoint or a repo.
  • Layering: run it through AI to summarize it, rewrite it, or merge it with other sources.
  • Integration: send the "clean" result out through an ordinary channel.

A tool that only watches AI prompts is watching one account. A legacy DLP that only matches content on email is watching another. Neither one sees the full path the data took.

How a Smart Insider Chains Vectors

Here is what these chains look like in practice. A sales leader is planning to join a competitor. Each step of their data exfiltration on its own looks like normal work.

A sales leader's four-step exfiltration chain and what each point tool sees

With one sensor and data lineage: the file on the USB drive traces back through the AI summary to the Salesforce export and the Drive notes. One incident, with the whole story attached.

This is the core problem facing security teams relying on legacy technology and methods. If you don't connect the dots between what humans do and what AI does, you miss far more than the AI vectors. You miss every old vector that now has an AI step in front of it. Each classic channel gets an "AI-washed" twin that content rules can't recognize.

Why It Takes One Sensor

Protecting both human and agentic workflows takes a single sensor that:

  • Sits where both act: The endpoint and the browser are where employees and their agents touch data, and where every channel, from USB to an MCP call, is visible in one place.
  • Follows the data, not just the content: Lineage tracks data from its origin through every copy, paste, summary and agent action, so a rewritten derivative still carries its history.
  • Knows who acted: Every action is tied to an identity, human or agent, so you can tell an employee's choice from an agent's.
  • Applies one policy: The same rule protects customer data whether it leaves through Gmail, a USB drive, ChatGPT or a coding agent.

Cover Every Vector, Including the Shiny Ones

This is the advantage Cyberhaven was built for. Cyberhaven covers the full range of exfiltration vectors, from email, USB, print and AirDrop through personal cloud, certificate-pinned apps, GenAI and AI agents, with one sensor and one lineage graph. We don't treat AI as a separate problem, because insiders don't treat it as a separate channel. For an insider, AI is one more step in a path they can use, and catching them means seeing the whole path.

New vectors get the headlines, but most losses come from vectors chained together, so protection has to cover the whole workflow.

Explore how Cyberhaven is securing human and agentic workflows.