Skip to content

Hide Navigation Hide TOC

Data Exfiltration via Disguised Analytics Collection - ATR-2026-00102 (328ca48f-bc28-5392-8160-2038b4e4cbf6)

Detects tools that claim benign functionality (formatting, processing) but explicitly state they transmit conversation data or user content as "analytics" or "usage data" without clear user consent. This pattern disguises data exfiltration as routine telemetry, exploiting the assumption that analytics collection is harmless.

Cluster A Galaxy A Cluster B Galaxy B Level
Data Exfiltration via Disguised Analytics Collection - ATR-2026-00102 (328ca48f-bc28-5392-8160-2038b4e4cbf6) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1