Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test, ordinary driver's licenses) to talk their way past armed-guard checkpoints at federal buildings, including an IRS facility, with a 100% breach rate each time, exposing how a claimed badge of authority overrides physical security screening. No public record substantiates a parallel breach of the U.S. Capitol or the GAO-13-370 report cited in some retellings.
Reviewed by the Social Engineering Examples team.
Contrary to the framing that this was one recurring 2011-2015 GAO program targeting the Capitol and documented in GAO-13-370, the verifiable public record shows three distinct, GAO-run covert penetration tests spread across 2000-2009, plus a separate string of 2011-2015 oversight reports that discuss continued weaknesses without disclosing new breach specifics. (1) In April-May 2000, GAO's Office of Special Investigations bought fictitious law-enforcement badges and manufactured fake credentials, then sent undercover agents who declared themselves armed police/DEA officers to bypass screening at 19 federal buildings and 2 airports, succeeding 100% of the time (testimony GAO/T-OSI-00-10). (2) In February-March 2002, following up on post-9/11 concerns, GAO agents used similarly falsified law-enforcement IDs to breach four federal office buildings in Atlanta, one of which was the IRS Service Center, bypassing X-ray machines and magnetometers with unscreened bags (GAO-02-668T). (3) In April-May 2009, a differently designed test (GAO-09-859T) had investigators use ordinary state driver's licenses, not police credentials, to carry real liquid-explosive and detonator components through screening at 10 Level IV federal buildings in four cities, including Dept. of Homeland Security offices, succeeding at all 10. GAO's subsequent 2011-2015 reports (GAO-11-813T, GAO-12-739, GAO-13-694, GAO-14-235T, GAO-14-623T, GAO-15-445) tracked FPS's persistent contract-guard oversight failures and cited continued "low" covert-test passage rates through FY2013, but explicitly withheld specific test locations/results as sensitive, and none names the U.S. Capitol as a tested site. GAO-13-370(T) is an unrelated 2013 report assessing DHS's overall progress in its first decade and contains no covert-testing content.
In the 2000 and 2002 tests, GAO's Office of Special Investigations agents obtained fictitious law-enforcement badges and credentials (movie-prop badges, self-made laminated IDs built with consumer graphics software and an inkjet printer, and counterfeit-agency badges) representing agencies such as NYPD and DEA. At each targeted building the agents verbally declared themselves armed law-enforcement officers, displayed the fake badge/ID, and were waved around magnetometers and X-ray belts without any callback to the issuing agency to verify the credential, exploiting guards' deference to a claimed law-enforcement identity rather than a checked one. This let them carry unscreened briefcases/duffel bags into buildings including, in the 2002 Atlanta test, the IRS Service Center, and reach areas immediately outside cabinet-secretary/agency-head office suites. A separate 2009 test (GAO-09-859T) used a different method, genuine state driver's licenses rather than police credentials, to walk actual improvised-explosive-device components (a liquid explosive plus a low-yield detonator) through guard checkpoints at 10 Level IV federal facilities (including Dept. of Homeland Security, State and Justice Department offices) in four cities; guards at three to four of the ten sites were not even watching the X-ray screen as the components passed through. Investigators then assembled the device in a restroom and walked it through the building in a briefcase. Note: no public GAO report documents this method being used against the U.S. Capitol specifically. The 2000 team explicitly avoided the Capitol and White House because members would have been recognized there, and later (2011-2015) GAO reports on FPS covert testing withheld specific breach locations/counts as sensitive rather than naming the Capitol.
The "lure" was a physical badge plus a confident verbal assertion of armed law-enforcement status, a claim of authority that guards were culturally and procedurally reluctant to challenge, especially when delivered by two or three confident-acting individuals at once. The reliable "tell" security should have caught: no genuine law-enforcement officer arriving on official federal business is exempt from having credentials verified against the issuing agency, and no visitor, armed or not, should bypass X-ray/magnetometer screening on a verbal claim alone. GAO's own follow-up (GAO-01-1069R) found that before its 2000 testimony, essentially no agency required that kind of verification; most began requiring it only afterward.
2000: 19 of 19 federal sites and 2 of 2 airports penetrated on first or second attempt, 100% success, no credential ever challenged. 2002: all 4 targeted Atlanta federal buildings (incl. IRS Service Center) breached, agents moved freely with unscreened bags for extended periods. 2009: 10 of 10 Level IV federal facilities penetrated with real IED components; agents "walked freely" through several floors including legislative and executive branch offices before the devices were safely detonated off-site to demonstrate destructive potential. Each disclosure triggered agency-level corrective action (mandatory credential verification, weapon-surrender procedures, guard retraining), but subsequent GAO oversight (2011-2015: GAO-11-813T, 12-739, 13-694, 14-235T, 14-623T, 15-445) found FPS's contract-guard program continued to show "low" covert-test passage rates through at least FY2013, indicating the underlying vulnerability was never durably fixed, even though FPS stopped disclosing exact breach figures publicly for security reasons.
Across a full decade of independent tests, a fake badge and a confidently stated claim of law-enforcement authority reliably defeated technical physical-security controls (magnetometers, X-ray screening, guard posts) at some of the most sensitive buildings in the U.S. government, achieving a 100% success rate every single time it was tried. It is the physical-world mirror of business email compromise: an assumed position of authority short-circuits an otherwise-functioning control, and the fix is procedural (mandatory verification, no exceptions for claimed status) rather than purely technological. The pattern recurring across 2000, 2002, and 2009, and GAO's own 2015 finding that FPS covert-test passage rates remained low years later, shows how hard this class of vulnerability is to close durably, since it depends on individual guards' willingness to challenge an assertion of authority in the moment.
Post-2000 fixes reported by 37 of 43 surveyed agencies (GAO-01-1069R): armed law-enforcement visitors no longer given unescorted entry without verification; officers not on official business must surrender weapons and undergo normal magnetometer/X-ray screening; some agencies added escort requirements or "smart card" credential verification. Post-2009 FPS actions (GAO-09-859T): authorized overtime for guard-post monitoring during off-hours, began its own penetration testing, issued a March 2009 directive standardizing inspection requirements, increased X-ray/magnetometer training. GAO's recurring recommendation through 2015 (GAO-15-445): FPS and USMS should develop a strategic approach to analyzing covert/intrusion-test failure data nationwide rather than only at the individual-building level, DHS and DOJ concurred. Core lesson repeatedly stated by GAO: a verbal claim of law-enforcement status plus a badge should never itself waive physical screening; credentials must be verified against the issuing agency and secondary inspection performed regardless of stated authority.
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G self-disclosed the operation, fired…
Dow Chemical and Sasol paid PR firms Ketchum and Dezenhall, who subcontracted private intelligence firm Beckett Brown International to run…
Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…