Earlier quoted context omitted.
Take this wildly simplified example. You are the attacker. You already have access to internal systems at Microsoft. Now you need to send the large amounts of data back to yourself, preferably without giving away your own location in the process. That’s the exfiltration phase of the cyber kill chain. In order to do that, you’ve already established a set of listening posts and command/control sites across the internet…
What happens after the first node is hit? You more or less need to control the network stack around it to know were it in turn sends data. If the NSA or whatever do control virtually every network stack they can access politically, every lead will end in countries which does not comply, right? If there is any world-wide N-to-N statistical analysis of eavesdropped nodes for reentry of the data, it should trivially be…
“Buffering” absolutely happens for a variety of reasons.
Tracking down the money or owning the operations infrastructure of the hosting companies along the way can help. Try to expand past bits on the wire- people set this stuff up at the end of the day.