Rate limiting is not effective. Having copied many terabytes of data do/from usb devices, I can tell you that it is not a consistent throughput. The speed of transfer depends on an inverse square of the file size of sorts. ( sensitive to the block size on both devices I'm sure )
Try copying 100gb of 2k-200k files ( all randomly sized ) It's a huge pain in the butt and works terribly on every system I've tried to do this on.
It would be way more awesome to have a utility that can after the fact forge a scenario directly into an existing tarball. Then, you can simply pick a "model to emulate" and click go, and wham you have a forged tarball.
Even if you did use a VM, it would be slower imo than a real transfer due to both the emulated system and the usb passthrough ( which is typically limited to USB 2.0 ) Show me a VM that is capable of USB 3.0 passthrough with reasonable speeds.
Unless you truly forge the dates in a carefully modeled way, it would be possible to tell that it isn't a real transfer.
Speaking of which; who steals data using USB 2.0? That's dumb. Use a modern USB 3.0 external 2.5" SSD. If you must use something small, use a cheapo 256gb USB 3.0 drive. The throughput on those is not bad. If no USB 3.0 ports are available, bring your own PCI Ex USB 3.0 card and open the system and install it. The BIOS may have intrusion detection... so be aware...
It is much more likely than direct system transfer that data is leaked slowly through an un-monitored network channel ( DNS tunneling... email... etc ) Hence the need to make things appear to be local; to distract from looking for the real method of transfer.