Case Library / Physical Social Engineering (Tailgating & Baiting) / GAO Covert Testers Use Fake Law-Enforcement Badges and Driver's Licenses to Breach Federal Buildings, Including an IRS Facility (2000-2009)

GAO Covert Testers Use Fake Law-Enforcement Badges and Driver's Licenses to Breach Federal Buildings, Including an IRS Facility (2000-2009)

Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test, ordinary driver's licenses) to talk their way past armed-guard checkpoints at federal buildings, including an IRS facility, with a 100% breach rate each time, exposing how a claimed badge of authority overrides physical security screening. No public record substantiates a parallel breach of the U.S. Capitol or the GAO-13-370 report cited in some retellings.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Contrary to the framing that this was one recurring 2011-2015 GAO program targeting the Capitol and documented in GAO-13-370, the verifiable public record shows three distinct, GAO-run covert penetration tests spread across 2000-2009, plus a separate string of 2011-2015 oversight reports that discuss continued weaknesses without disclosing new breach specifics. (1) In April-May 2000, GAO's Office of Special Investigations bought fictitious law-enforcement badges and manufactured fake credentials, then sent undercover agents who declared themselves armed police/DEA officers to bypass screening at 19 federal buildings and 2 airports, succeeding 100% of the time (testimony GAO/T-OSI-00-10). (2) In February-March 2002, following up on post-9/11 concerns, GAO agents used similarly falsified law-enforcement IDs to breach four federal office buildings in Atlanta, one of which was the IRS Service Center, bypassing X-ray machines and magnetometers with unscreened bags (GAO-02-668T). (3) In April-May 2009, a differently designed test (GAO-09-859T) had investigators use ordinary state driver's licenses, not police credentials, to carry real liquid-explosive and detonator components through screening at 10 Level IV federal buildings in four cities, including Dept. of Homeland Security offices, succeeding at all 10. GAO's subsequent 2011-2015 reports (GAO-11-813T, GAO-12-739, GAO-13-694, GAO-14-235T, GAO-14-623T, GAO-15-445) tracked FPS's persistent contract-guard oversight failures and cited continued "low" covert-test passage rates through FY2013, but explicitly withheld specific test locations/results as sensitive, and none names the U.S. Capitol as a tested site. GAO-13-370(T) is an unrelated 2013 report assessing DHS's overall progress in its first decade and contains no covert-testing content.

How the Attack Worked

In the 2000 and 2002 tests, GAO's Office of Special Investigations agents obtained fictitious law-enforcement badges and credentials (movie-prop badges, self-made laminated IDs built with consumer graphics software and an inkjet printer, and counterfeit-agency badges) representing agencies such as NYPD and DEA. At each targeted building the agents verbally declared themselves armed law-enforcement officers, displayed the fake badge/ID, and were waved around magnetometers and X-ray belts without any callback to the issuing agency to verify the credential, exploiting guards' deference to a claimed law-enforcement identity rather than a checked one. This let them carry unscreened briefcases/duffel bags into buildings including, in the 2002 Atlanta test, the IRS Service Center, and reach areas immediately outside cabinet-secretary/agency-head office suites. A separate 2009 test (GAO-09-859T) used a different method, genuine state driver's licenses rather than police credentials, to walk actual improvised-explosive-device components (a liquid explosive plus a low-yield detonator) through guard checkpoints at 10 Level IV federal facilities (including Dept. of Homeland Security, State and Justice Department offices) in four cities; guards at three to four of the ten sites were not even watching the X-ray screen as the components passed through. Investigators then assembled the device in a restroom and walked it through the building in a briefcase. Note: no public GAO report documents this method being used against the U.S. Capitol specifically. The 2000 team explicitly avoided the Capitol and White House because members would have been recognized there, and later (2011-2015) GAO reports on FPS covert testing withheld specific breach locations/counts as sensitive rather than naming the Capitol.

The Lure & the Tell

The "lure" was a physical badge plus a confident verbal assertion of armed law-enforcement status, a claim of authority that guards were culturally and procedurally reluctant to challenge, especially when delivered by two or three confident-acting individuals at once. The reliable "tell" security should have caught: no genuine law-enforcement officer arriving on official federal business is exempt from having credentials verified against the issuing agency, and no visitor, armed or not, should bypass X-ray/magnetometer screening on a verbal claim alone. GAO's own follow-up (GAO-01-1069R) found that before its 2000 testimony, essentially no agency required that kind of verification; most began requiring it only afterward.

Outcome

2000: 19 of 19 federal sites and 2 of 2 airports penetrated on first or second attempt, 100% success, no credential ever challenged. 2002: all 4 targeted Atlanta federal buildings (incl. IRS Service Center) breached, agents moved freely with unscreened bags for extended periods. 2009: 10 of 10 Level IV federal facilities penetrated with real IED components; agents "walked freely" through several floors including legislative and executive branch offices before the devices were safely detonated off-site to demonstrate destructive potential. Each disclosure triggered agency-level corrective action (mandatory credential verification, weapon-surrender procedures, guard retraining), but subsequent GAO oversight (2011-2015: GAO-11-813T, 12-739, 13-694, 14-235T, 14-623T, 15-445) found FPS's contract-guard program continued to show "low" covert-test passage rates through at least FY2013, indicating the underlying vulnerability was never durably fixed, even though FPS stopped disclosing exact breach figures publicly for security reasons.

Why It Matters

Across a full decade of independent tests, a fake badge and a confidently stated claim of law-enforcement authority reliably defeated technical physical-security controls (magnetometers, X-ray screening, guard posts) at some of the most sensitive buildings in the U.S. government, achieving a 100% success rate every single time it was tried. It is the physical-world mirror of business email compromise: an assumed position of authority short-circuits an otherwise-functioning control, and the fix is procedural (mandatory verification, no exceptions for claimed status) rather than purely technological. The pattern recurring across 2000, 2002, and 2009, and GAO's own 2015 finding that FPS covert-test passage rates remained low years later, shows how hard this class of vulnerability is to close durably, since it depends on individual guards' willingness to challenge an assertion of authority in the moment.

Defenses

Post-2000 fixes reported by 37 of 43 surveyed agencies (GAO-01-1069R): armed law-enforcement visitors no longer given unescorted entry without verification; officers not on official business must surrender weapons and undergo normal magnetometer/X-ray screening; some agencies added escort requirements or "smart card" credential verification. Post-2009 FPS actions (GAO-09-859T): authorized overtime for guard-post monitoring during off-hours, began its own penetration testing, issued a March 2009 directive standardizing inspection requirements, increased X-ray/magnetometer training. GAO's recurring recommendation through 2015 (GAO-15-445): FPS and USMS should develop a strategic approach to analyzing covert/intrusion-test failure data nationwide rather than only at the individual-building level, DHS and DOJ concurred. Core lesson repeatedly stated by GAO: a verbal claim of law-enforcement status plus a badge should never itself waive physical screening; credentials must be verified against the issuing agency and secondary inspection performed regardless of stated authority.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target selection and OSINT: GAO's Office of Special Investigations is documented (GAO/T-OSI-00-10) as first collecting background information from public sources on federal sites, choosing targets based on their national-security, intelligence, or symbolic significance, and conducting overt surveillance of each site's checkpoint layout as a private citizen before the operation began.
Countering Stage 1: Public-facing information about a building's security posture (guard presence, entrances, hours) is hard to fully suppress; the realistic control is limiting how much operational detail (post orders, screening schedules, staffing levels) is discoverable and treating any pre-visit inquiry calls as a signal worth logging rather than trying to eliminate visibility of the building itself.
2
Credential acquisition: Investigators bought fictitious law-enforcement badges available on the open market and, per the testimony, built matching fake photo identification using consumer means, then further refined the pretext with pretext telephone calls to the target agencies to gather additional site-specific detail.
Countering Stage 2: Restricting the retail and online availability of law-enforcement-style badges and credential stock, and requiring agencies to use tamper-evident, hard-to-replicate credential formats, raises the cost of building a convincing fake, though GAO's own testimony noted such badges were already 'readily available for purchase.'
3
Pretext rehearsal and team composition: Agents prepared a consistent cover story (representing agencies such as NYPD or DEA) and typically approached checkpoints in pairs or small groups, since the report notes that a confident multi-person assertion of shared law-enforcement status made individual guards less likely to challenge any one member.
Countering Stage 2/3 (rehearsal has no direct technical control): There is no practical way to detect rehearsal or team-composition choices before an attempt; the nearest real control is Stage 4/5, training every guard, individually, to treat multi-person confidence displays as a reason for more scrutiny, not less.
4
In-person authority claim: At each checkpoint the agents displayed the counterfeit badge and verbally declared themselves armed law-enforcement officers on business, a claim GAO's own testimony states was never challenged or verified against the issuing agency at any of the 21 sites tested in 2000.
Countering Stage 4: GAO's post-2000 survey (GAO-01-1069R) found 37 of 43 agencies subsequently mandated that any claimed law-enforcement credential be verified by phone callback to the issuing agency before being accepted, removing the guard's individual judgment call from the decision.
5
Screening bypass: Guards waved the agents and their unscreened bags around the magnetometers and X-ray belts based solely on the claimed status, letting them carry duffel bags, briefcases, and (in the related 2009 driver's-license variant) real liquid-explosive and detonator components straight past the checkpoint.
Countering Stage 5: Agencies adopted a no-exceptions screening policy after 2000 and 2009: officers not on official business must surrender weapons and pass through magnetometers/X-ray like any visitor, and FPS's post-2009 directive standardized inspection requirements and added guard training specifically on watching the X-ray screen rather than waving items through.
6
Objective completion and evidence capture: Agents moved through the buildings, in several cases reaching hallways immediately outside cabinet-secretary or agency-head office suites, and in the 2009 test assembled the device components in a restroom and carried the finished item through the facility, at which point GAO documented the breach on video and detonated the device safely off-site to demonstrate the risk to Congress.
Countering Stage 6: Escort requirements for any credentialed visitor moving beyond the lobby, plus GAO's recommended strategic, nationwide analysis of covert-test failure data (GAO-15-445, concurred with by DHS and DOJ) rather than one-off building-level fixes, are the controls aimed at catching or deterring an intruder who has already cleared the checkpoint.
Quick Facts
Victim
Federal Protective Service-guarded facilities: in 2000, CIA HQ, FBI HQ, DOJ HQ, State Dept, Pentagon, Dept. of Energy, INS, Library of Congress, National Archives, USDA, HHS, HUD, Labor, DOT, FEMA, NASA HQ, a U.S. courthouse, plus Reagan National and Orlando International airports; in 2002, four Atlanta federal office buildings including the IRS Service Center; in 2009, 10 Level IV federal facilities in four cities including Dept. of Homeland Security, State and Justice Dept offices and congressional district offices. (No public GAO report documents a U.S. Capitol breach via this method.)
Location
Washington, D.C. area and Orlando, FL (2000 test); Atlanta, GA (2002 test, incl. IRS Service Center); four unnamed U.S. metropolitan areas (2009 test, locations withheld by GAO as sensitive)
Date
April-May 2000 (GAO/T-OSI-00-10); February-March 2002 (GAO-02-668T, Atlanta incl. IRS Service Center); April-May 2009 (GAO-09-859T, driver's-license method); recurring low-disclosure FPS covert testing FY2010-FY2013 per GAO-15-445 (March 2015)
Impact
No theft/fraud loss. These were GAO-authorized security audits, not criminal attacks. Contextual figures from the reports: FPS's contract-guard program was budgeted at roughly $613 million (cited in 2009) rising to about $1 billion with ~13,000 guards; the IED components used in the 2009 test were bought at retail/online for under $150; FY2011 FPS basic security fees totaled $236 million (GAO-12-739).
Status
Confirmed
Case Type
Research / Advisory
Sector
Government & Public Sector, Transportation & Logistics
Threat Actor
Authorized Tester or Researcher
Related

Related Cases

P&G's 'Bad Hair Day': Dumpster-Diving Corporate Espionage on Unilever's Hair-Care Business

P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G self-disclosed the operation, fired…

Incident 2000Read →

Greenpeace v. Dow Chemical / Sasol Corporate Espionage ("D-Lines")

Dow Chemical and Sasol paid PR firms Ketchum and Dezenhall, who subcontracted private intelligence firm Beckett Brown International to run…

Incident 1998Read →

Air Canada v. WestJet: Curbside Garbage Collection From Co-Founder Mark Hill's Home

Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…

Incident 2003Read →