Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test.
Social Engineering Examples·9 sources
Contrary to the framing that this was one recurring 2011-2015 GAO program targeting the Capitol and documented in GAO-13-370, the verifiable public record shows three distinct, GAO-run covert penetration tests spread across 2000-2009, plus a separate string of 2011-2015 oversight reports that discuss continued weaknesses without disclosing new breach specifics. (1) In April-May 2000, GAO's Office of Special Investigations bought fictitious law-enforcement badges and manufactured fake credentials, then sent undercover agents who declared themselves armed police/DEA officers to bypass screening at 19 federal buildings and 2 airports, succeeding 100% of the time (testimony GAO/T-OSI-00-10). (2) In February-March 2002, following up on post-9/11 concerns, GAO agents used similarly falsified law-enforcement IDs to breach four federal office buildings in Atlanta, one of which was the IRS Service Center, bypassing X-ray machines and magnetometers with unscreened bags (GAO-02-668T). (3) In April-May 2009, a differently designed test (GAO-09-859T) had investigators use ordinary state driver's licenses, not police credentials, to carry real liquid-explosive and detonator components through screening at 10 Level IV federal buildings in four cities, including Dept. of Homeland Security offices, succeeding at all 10. GAO's subsequent 2011-2015 reports (GAO-11-813T, GAO-12-739, GAO-13-694, GAO-14-235T, GAO-14-623T, GAO-15-445) tracked FPS's persistent contract-guard oversight failures and cited continued "low" covert-test passage rates through FY2013, but explicitly withheld specific test locations/results as sensitive, and none names the U.S. Capitol as a tested site.
GAO-13-370(T) is an unrelated 2013 report assessing DHS's overall progress in its first decade and contains no covert-testing content.
In the 2000 and 2002 tests, GAO's Office of Special Investigations agents obtained fictitious law-enforcement badges and credentials (movie-prop badges, self-made laminated IDs built with consumer graphics software and an inkjet printer, and counterfeit-agency badges) representing agencies such as NYPD and DEA. At each targeted building the agents verbally declared themselves armed law-enforcement officers, displayed the fake badge/ID, and were waved around magnetometers and X-ray belts without any callback to the issuing agency to verify the credential, exploiting guards' deference to a claimed law-enforcement identity rather than a checked one.
This let them carry unscreened briefcases/duffel bags into buildings including, in the 2002 Atlanta test, the IRS Service Center, and reach areas immediately outside cabinet-secretary/agency-head office suites. A separate 2009 test (GAO-09-859T) used a different method, genuine state driver's licenses rather than police credentials, to walk actual improvised-explosive-device components (a liquid explosive plus a low-yield detonator) through guard checkpoints at 10 Level IV federal facilities (including Dept. of Homeland Security, State and Justice Department offices) in four cities; guards at three to four of the ten sites were not even watching the X-ray screen as the components passed through.
Investigators then assembled the device in a restroom and walked it through the building in a briefcase. Note: no public GAO report documents this method being used against the U.S. Capitol specifically. The 2000 team explicitly avoided the Capitol and White House because members would have been recognized there, and later (2011-2015) GAO reports on FPS covert testing withheld specific breach locations/counts as sensitive rather than naming the Capitol.
The "lure" was a physical badge plus a confident verbal assertion of armed law-enforcement status, a claim of authority that guards were culturally and procedurally reluctant to challenge, especially when delivered by two or three confident-acting individuals at once. The reliable "tell" security should have caught: no genuine law-enforcement officer arriving on official federal business is exempt from having credentials verified against the issuing agency, and no visitor, armed or not, should bypass X-ray/magnetometer screening on a verbal claim alone.
GAO's own follow-up (GAO-01-1069R) found that before its 2000 testimony, essentially no agency required that kind of verification; most began requiring it only afterward.
2000: 19 of 19 federal sites and 2 of 2 airports penetrated on first or second attempt, 100% success, no credential ever challenged. 2002: all 4 targeted Atlanta federal buildings (incl. IRS Service Center) breached, agents moved freely with unscreened bags for extended periods. 2009: 10 of 10 Level IV federal facilities penetrated with real IED components; agents "walked freely" through several floors including legislative and executive branch offices before the devices were safely detonated off-site to demonstrate destructive potential.
Each disclosure triggered agency-level corrective action (mandatory credential verification, weapon-surrender procedures, guard retraining), but subsequent GAO oversight (2011-2015: GAO-11-813T, 12-739, 13-694, 14-235T, 14-623T, 15-445) found FPS's contract-guard program continued to show "low" covert-test passage rates through at least FY2013, indicating the underlying vulnerability was never durably fixed, even though FPS stopped disclosing exact breach figures publicly for security reasons.
Across a full decade of independent tests, a fake badge and a confidently stated claim of law-enforcement authority reliably defeated technical physical-security controls (magnetometers, X-ray screening, guard posts) at some of the most sensitive buildings in the U.S. government, achieving a 100% success rate every single time it was tried. It is the physical-world mirror of business email compromise: an assumed position of authority short-circuits an otherwise-functioning control, and the fix is procedural (mandatory verification, no exceptions for claimed status) rather than purely technological.
The pattern recurring across 2000, 2002, and 2009, and GAO's own 2015 finding that FPS covert-test passage rates remained low years later, shows how hard this class of vulnerability is to close durably, since it depends on individual guards' willingness to challenge an assertion of authority in the moment.
Post-2000 fixes reported by 37 of 43 surveyed agencies (GAO-01-1069R): armed law-enforcement visitors no longer given unescorted entry without verification; officers not on official business must surrender weapons and undergo normal magnetometer/X-ray screening; some agencies added escort requirements or "smart card" credential verification. Post-2009 FPS actions (GAO-09-859T): authorized overtime for guard-post monitoring during off-hours, began its own penetration testing, issued a March 2009 directive standardizing inspection requirements, increased X-ray/magnetometer training.
GAO's recurring recommendation through 2015 (GAO-15-445): FPS and USMS should develop a strategic approach to analyzing covert/intrusion-test failure data nationwide rather than only at the individual-building level, DHS and DOJ concurred. Core lesson repeatedly stated by GAO: a verbal claim of law-enforcement status plus a badge should never itself waive physical screening; credentials must be verified against the issuing agency and secondary inspection performed regardless of stated authority.
Social Engineering Examples. “GAO Covert Testers Use Fake Law-Enforcement Badges and Driver's Licenses to Breach Federal Buildings, Including an IRS Facility (2000-2009)”. Accessed 19 September 2026. https://socialengineeringexamples.com/gao-fake-law-enforcement-badge-federal-building-breaches-2000-2009
GAO's Office of Special Investigations is documented (GAO/T-OSI-00-10) as first collecting background information from public sources on federal sites, choosing targets based on their national-security, intelligence, or symbolic significance, and conducting overt surveillance of each site's checkpoint layout as a private citizen before the operation began.
Public-facing information about a building's security posture (guard presence, entrances, hours) is hard to fully suppress; the realistic control is limiting how much operational detail (post orders, screening schedules, staffing levels) is discoverable and treating any pre-visit inquiry calls as a signal worth logging rather than trying to eliminate visibility of the building itself.
Investigators bought fictitious law-enforcement badges available on the open market and, per the testimony, built matching fake photo identification using consumer means, then further refined the pretext with pretext telephone calls to the target agencies to gather additional site-specific detail.
Restricting the retail and online availability of law-enforcement-style badges and credential stock, and requiring agencies to use tamper-evident, hard-to-replicate credential formats, raises the cost of building a convincing fake, though GAO's own testimony noted such badges were already 'readily available for purchase.'
Agents prepared a consistent cover story (representing agencies such as NYPD or DEA) and typically approached checkpoints in pairs or small groups, since the report notes that a confident multi-person assertion of shared law-enforcement status made individual guards less likely to challenge any one member.
Countering Stage 2/3 (rehearsal has no direct technical control): There is no practical way to detect rehearsal or team-composition choices before an attempt; the nearest real control is Stage 4/5, training every guard, individually, to treat multi-person confidence displays as a reason for more scrutiny, not less.
At each checkpoint the agents displayed the counterfeit badge and verbally declared themselves armed law-enforcement officers on business, a claim GAO's own testimony states was never challenged or verified against the issuing agency at any of the 21 sites tested in 2000.
GAO's post-2000 survey (GAO-01-1069R) found 37 of 43 agencies subsequently mandated that any claimed law-enforcement credential be verified by phone callback to the issuing agency before being accepted, removing the guard's individual judgment call from the decision.
Guards waved the agents and their unscreened bags around the magnetometers and X-ray belts based solely on the claimed status, letting them carry duffel bags, briefcases, and (in the related 2009 driver's-license variant) real liquid-explosive and detonator components straight past the checkpoint.
Agencies adopted a no-exceptions screening policy after 2000 and 2009: officers not on official business must surrender weapons and pass through magnetometers/X-ray like any visitor, and FPS's post-2009 directive standardized inspection requirements and added guard training specifically on watching the X-ray screen rather than waving items through.
Agents moved through the buildings, in several cases reaching hallways immediately outside cabinet-secretary or agency-head office suites, and in the 2009 test assembled the device components in a restroom and carried the finished item through the facility, at which point GAO documented the breach on video and detonated the device safely off-site to demonstrate the risk to Congress.
Escort requirements for any credentialed visitor moving beyond the lobby, plus GAO's recommended strategic, nationwide analysis of covert-test failure data (GAO-15-445, concurred with by DHS and DOJ) rather than one-off building-level fixes, are the controls aimed at catching or deterring an intruder who has already cleared the checkpoint.
Browse by what this case has in common with others in the library.
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.
Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
Operation Buckshot Yankee: a malware-laden USB drive plugged into a U.S. military laptop in 2008 spread the agent.btz worm onto…
Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.
Imperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that…
A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge.
ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model.