logo

Possible Data Exfiltration via Cloud Storage Sync Abuse

ID: e0ac67c9-9959-4395-af52-86439b7c8f44

STIX ID: report--e0ac67c9-9959-4395-af52-86439b7c8f44

Threat Score

65/100

Uploaded: 2026-04-13

Created by: Report Uploader

TLP:GREEN
...
...
On 13 April 2026, telemetry showed user m.thornton executing SyncDrivePortable.exe on device RSCH-WS-19, compressing multiple internal project folders into large archives (review_01.zip, review_02.zip, review_03.zip) and synchronizing them to an unsanctioned cloud service (api.syncdrive-files.com, cdn.syncdrive-files.com). The account accessed directories outside the user’s normal role (legal, finance), suggesting possible insider-driven data staging or exfiltration via legitimate tools or after account compromise; additional investigation is required to determine intent and credential misuse.