Lumetrace / Data theft detection
Data theft

How would you know if someone was stealing your information?

It is an uncomfortable question because for most organisations the honest answer is that they would not, until somebody outside told them. Theft has to travel, and travelling is something you can watch.

Stealing data is a network event

Customer records, contracts, drawings, process recipes, source code, pricing, board papers. None of it is useful to an attacker while it sits on your file server. To have value it has to be moved somewhere they control, and that movement is observable.

This is why the absence of network detection is so expensive after the fact. Without a record of what left, an investigation cannot answer the only questions anybody will ask you: what was taken, how much, and where did it go.

What we look for

  • Destinations with no history. A host that has never spoken to a given service suddenly sending it a lot.
  • Volume asymmetry. An internal machine that normally downloads starting to upload, which is a shape change rather than a threshold breach.
  • Encoded and tunnelled transfers. Data smuggled inside DNS or ICMP to bypass web filtering entirely.
  • Unsanctioned cloud storage. Uploads to consumer file-sharing and sync services that were never approved for company data.
  • Source code and documents sent to AI assistants. Increasingly the single largest unmanaged outbound flow in an enterprise, and almost never malicious in intent, which is exactly why nobody is watching it.
  • Staging behaviour. Large internal collection into one host before anything leaves, which is often the earliest visible moment.

Shadow AI is the new exfiltration path, and it is not an attack

The uncomfortable modern case is not an intruder. It is a capable employee, under deadline, pasting a customer list or a repository into whatever assistant works best. No malware, no intrusion, nothing for an endpoint tool to flag, and your data is now outside your control.

We report which hosts reach which AI services, what volume went, and whether it looks like documents or code. The output is a governance conversation, not an accusation, and we deliberately frame it that way.

What a finding tells you

A verdict with no substance behind it wastes your time. Every finding is built to answer the practical questions: which host and which user context, how many bytes in each direction, what the destination actually is, what else that host touched around the same time, and what to do next. If we cannot say what left, we say that instead of implying we can.

Questions

Data theft detection: straight answers

Can you tell us exactly which files were taken?

Sometimes, and we are careful about the difference. Where the transfer is observable in the clear or identifiable by protocol, we can be specific. Where it is encrypted, we report the destination, the volume, the direction and the timing, and we say plainly that the contents were not visible rather than guessing.

Is this data loss prevention?

No, and it is worth being precise. DLP works on content, usually with agents and policies about what may leave. We work on the network view: where data went, how much, and whether that is new behaviour. The two are complementary, and we are the one that still works on a device that cannot run an agent.

Would you catch an employee uploading to a personal cloud account?

Yes, as a network flow to an unsanctioned service, with the host and the volume. Whether that is a policy matter or an incident is your call, and the report is written to support that judgement rather than pre-empt it.

Find your blind spots before an attacker does.

Tell us whether you suspect something is already inside, or whether you want to measure what your current tools would catch. Either way you get a concrete next step.

Contact us
Related

More on what we detect