Skip to main content
← Back to Demos
Data Loss Prevention beginner · 15 min

Payroll spreadsheet with PII flagged before sharing

Aflac disclosed to the SEC that its Japan subsidiary suffered a system intrusion between June 15 and 25, potentially exposing data for approximately 4.38 million policyholders - the kind of benefits and payroll records that end up consolidated in spreadsheets (MITRE T1005). Payroll files concentrate the highest-value personal data an organization holds: names, national IDs, bank account numbers, salaries, and health benefit details, all in one workbook that is frequently shared with finance, HR, auditors, and external vendors. Proactive DLP inspects spreadsheets before they are shared, detecting PII patterns such as national ID numbers, bank account formats, and personal contact data, then applies policy to block, quarantine, or alert on the transfer. The demo workbook uses synthetic PII, so no real personal data is involved.

Attack Technique

Payroll PII spreadsheet

MITRE ATT&CK

T1005 ↗

Platforms

linux

File Types

.xlsx

MetaDefender Capabilities

Proactive DLP

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---