October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Cyberhaven Report: 9.4% of Tracked Employees Exfiltrated Sensitive Data in Six Months

Cyberhaven’s 2022 tracking, as reported by CSO, found a six-month exfiltration rate of 9.4% among about 1.4 million people handling sensitive information. The study describes unapproved transfers, not necessarily intentional theft.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In Cyberhaven’s 2022 tracked population, 9.4% of people handling sensitive organizational information transferred it outside their organization in unapproved ways during a six-month period, according to CSO Online’s September 14, 2022 report. The study tracked about 1.4 million people globally from January through June 2022. That is a result from a particular population and period—not a current estimate for all employees, and not proof that every transfer was deliberate theft.

What the “one in 10” figure measures

CSO Online reported that Cyberhaven found an average of 2.5% of employees exfiltrated sensitive information in a month and 9.4% did so over the six-month observation window. The monthly and six-month rates describe different time periods; they should not be treated as interchangeable or extrapolated into an annual rate. The figures are specific to Cyberhaven’s tracked population of about 1.4 million people handling sensitive organizational information worldwide from January through June 2022. CSO Online’s summary of Cyberhaven’s report is the source for these numbers.

CSO defines an exfiltration incident as data being transferred outside an organization in an unapproved way. That definition establishes that a transfer was unauthorized under the organization’s rules; on its own, it does not establish whether the person acted maliciously, knowingly, accidentally, or caused harm. “Leak” can suggest intentional disclosure, so it is more precise to read the headline as a report about unapproved transfers.

How sensitive company data was transferred

CSO’s account breaks out the share of incidents associated with reported routes. These percentages are incident shares, not shares of employees, and the source does not say they sum to all incidents.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reported route Share of incidents
Personal cloud storage 27.5%
Personal webmail 18.7%
Corporate email sent to an inappropriate recipient 14.4%
Messaging apps, including WhatsApp and Signal 6.4%

Among cloud services reported, Dropbox appeared in 44.8% of incidents and Google Drive in 25.5%. These are reported service figures, not evidence that either service is inherently unsafe or that the percentages account for every incident. The practical issue for an employer is whether the destination and transfer are approved for the data involved—not simply whether a familiar app is being used.

What kinds of data were involved

Client or customer data made up 44.6% of the exfiltrated data reported by Cyberhaven, while source code accounted for 13.8%. Regulated data—personally identifiable information, payment-card information, and protected health information collectively—accounted for 17.9%. These figures describe the reported composition of exfiltrated data, not the proportion of employees or incidents in each category. CSO’s summary also quotes Cyberhaven suggesting that employees may not recognize customer information as sensitive in the same way they recognize a product formula or medical record.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

The mix is a reminder that data protection cannot focus only on records subject to regulation. Customer files, internal code, and other commercially sensitive information may also need clear labels, limited access, and rules for approved destinations.

Does data transfer rise around an employee’s departure?

CSO reported that incidents increased 83.1% during the two weeks before employees gave notice and 37.7% between notice and the final workday, relative to a baseline. For employees who were fired, reported incidents rose 23.1% on the day before termination and 109.3% on the day of termination, also relative to baseline. These are changes in incident activity, not percentages of departing workers who took data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The timing is an association in the study, not proof that a particular employee intends to take information or that departure caused a transfer. It can inform general offboarding planning: review access and sensitive-data handling when employment status changes, apply policy consistently, and revoke access at the appropriate time. A statistical pattern should not be used as an accusation against an individual.

What organizations can take from the findings

The study does not compare security products or prove that one intervention works better than another. Its reported routes and data categories point to practical questions for a company designing controls:

  • Define what is sensitive. Classify customer data, source code, regulated records, and other business-sensitive information so employees and systems can apply the right rules.
  • Make approved destinations clear. Set rules for personal cloud accounts, webmail, corporate email recipients, messaging apps, and other transfer routes. Distinguish legitimate work from unapproved movement rather than treating every use of a tool as equivalent.
  • Match access to need. Limit access to sensitive data and review it when roles or employment status change.
  • Pair technical controls with clear policy and training. Employees cannot reliably follow rules they have not been told or cannot understand. Explain the permitted handling of data in the tools they use.
  • Plan offboarding consistently. Establish who reviews access, what happens to accounts and devices, and when access is removed. Use the study’s timing pattern as a reason to plan, not as a prediction about a named employee.

In a 2008 Cisco release, the company recommended identifying the information to protect, not assuming employees know what is sensitive, and combining education, policy, and technology. That is historical guidance, not a test of effectiveness or a current benchmark. Cisco’s November 12, 2008 release describes a commissioned survey of more than 2,000 employees and IT professionals across 10 countries.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

AI tools add a separate data-handling concern

A later, separate survey provides context for a newer transfer route, but it is not a replication of Cyberhaven’s tracking. KnowBe4 reported in 2025 that 60.2% of surveyed workers used AI at work, 18.5% knew of their company’s AI policy, and 10% admitted entering client data into an AI tool for a work task. Censuswide conducted the fieldwork July 17–25, 2024, among 12,037 employed computer users in Germany, South Africa, the Netherlands, France, the UK, and the US. These are survey responses from those countries, not measurements of the same population or period as Cyberhaven’s 2022 data. KnowBe4’s release reports the findings and survey details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

For employers, the actionable point is to specify which AI tools may be used for work and what information may be entered into them. Guidance should be understandable at the moment employees choose a tool, rather than existing only as a policy document they may not know about.

How to read the headline responsibly

The figure is evidence that unapproved data transfers occurred in a large tracked population and that activity was concentrated in particular routes and periods. It does not show that one in ten employees everywhere steals data every six months. Nor does it tell readers that each transfer was intentional, harmful, or caused by a particular tool. The value of the report is in identifying handling risks organizations can address through data classification, clear rules, access controls, training, and consistent offboarding.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.