MITRE ATLAS 2026.09 / technique reference
AML.T0025
Exfiltration via Cyber Means
MITRE source definition
Adversaries may exfiltrate AI artifacts or other information relevant to their goals via traditional cyber means.
See the ATT&CK Exfiltration tactic for more information.
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
No explicit relationship in this pinned source.
Source-backed defensive context
MITRE mitigations
MITRE case studies
- AML.CS0010 Microsoft Azure Service Disruption · Exercise
- AML.CS0015 Compromised PyTorch Dependency Chain · Incident
- AML.CS0018 Arbitrary Code Execution with Google Colab · Exercise
- AML.CS0023 ShadowRay: Hijacking Exposed Ray Clusters · Incident
- AML.CS0027 Organization Confusion on Hugging Face · Exercise
- AML.CS0043 Malware Prototype with Embedded Prompt Injection · Incident
- AML.CS0044 LAMEHUG: Malware Leveraging Dynamic AI-Generated Commands · Incident
- AML.CS0048 Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution · Exercise
- AML.CS0058 Google Photos AI Model Extraction · Exercise
- AML.CS0059 EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration · Exercise
- AML.CS0063 Prompt-Based Attacks Against Gemini via Calendar Invitations · Exercise
- AML.CS0068 Autonomous OpenAI Evaluation Agents Compromise Hugging Face Infrastructure · Incident
- AML.CS0069 GTG-1002 Claude Code Espionage Campaign · Incident
- AML.CS0071 Multi-Agent Framework Compromises Taiwanese Government Systems · Incident
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.