Physical social engineering skips the screen entirely: tailgating into a building, dropping an infected USB drive where someone will plug it in, or posing as a contractor or guest to get past a front desk. These 22 cases show that a lot of the most damaging intrusions in history, including Stuxnet, started with a person walking through a door rather than a phishing email.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool visit and an unverified family-tie claim, then was found carrying a USB drive initially flagged as containing malware, a determination prosecutors later said may have been a false positive, along with four phones, over $7,600 cash, and a hidden-camera detector.
PSResearchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that up to 98% were picked up and 45% were plugged in and opened, with the first connection occurring in under six minutes, the first rigorous, quantified real-world proof that USB-baiting works.
PSA nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors, then physically destroyed roughly 1,000 uranium centrifuges.
PSTwo unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a roughly seven-month notification delay led to a $850,000 multistate AG settlement and a separate $825,000 Massachusetts settlement mandating encryption of all backup media going forward.
PSAdvance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads, and Advance's mishandling of the discovery led a Minnesota jury (and, on appeal, the Minnesota Court of Appeals) to impose $500,000 in combined compensatory and reinstated punitive damages, a landmark early US ruling that trash retains a protectable privacy/property interest against competitor theft.
PSA Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec micro-cut document shredding while using equipment that could not physically produce that particle size, settling in July 2013 for $1.1 million combined ($800K Iron Mountain, $300K Shred-It), with Cintas continuing to contest the claims.
PSTV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading to a joint FTC/HHS settlement including a $1 million HIPAA payment and a 20-year FTC security-audit order.
PSA widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy failure to help trigger the 2012 Saudi Aramco Shamoon wiper attack, but no primary source (Reuters, Symantec, Kaspersky, CISA, Panetta's Pentagon remarks) corroborates any physical-access role in the actual, well-documented malware intrusion that wiped ~30,000-35,000 Aramco workstations.
PSP&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G self-disclosed the operation, fired three employees, and settled with Unilever in September 2001.
PSA Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up on a bystander employee's badge scan, then posed as a new security-team hire at the help desk for 30 minutes to probe whether staff would challenge him. He was ultimately stopped, seven months later, by a guard who cited that very fake-badge incident as the reason for denying access.
PSA Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title company's open dumpster, and combined with a 2004 website hack, it triggered an FTC settlement over failed data-security safeguards.
PSCalifornia's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured, publicly accessible dumpsters at 16 Kaiser Permanente facilities statewide, resulting in a $49 million settlement.
PSDow Chemical and Sasol paid PR firms Ketchum and Dezenhall, who subcontracted private intelligence firm Beckett Brown International to run over 120 dumpster-diving raids on Greenpeace's DC offices between July 1998 and July 2000, including using a bribed/subcontracted DC police officer's badge to bypass a locked trash enclosure.
PSBetween 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test, ordinary driver's licenses) to talk their way past armed-guard checkpoints at federal buildings, including an IRS facility, with a 100% breach rate each time, exposing how a claimed badge of authority overrides physical security screening. No public record substantiates a parallel breach of the U.S. Capitol or the GAO-13-370 report cited in some retellings.
PSFIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.
PSDOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.
PSCVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters; media exposure across a dozen-plus cities led to a $2.25M HHS settlement and a separate FTC consent order in 2009.
PSAn MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home patients' hard-copy prescription and NHS records left rotting in unlocked crates, bin bags and a cardboard box in the open rear yard of a London pharmacy supplier, triggering the ICO's first-ever GDPR fine.
PSA malware-laden USB flash drive plugged into a laptop at a U.S. military base in the Middle East in 2008 let the agent.btz worm crawl onto classified SIPRNet systems, triggering the Pentagon's largest-ever cleanup and helping spur creation of U.S. Cyber Command.
PSAir Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from outside WestJet co-founder Mark Hill's home (a collection Hill's own affidavit says involved the investigators walking onto his driveway, a claim IPSA disputed) and had shredded documents digitally reconstructed by a Houston forensic firm, as part of its corporate-espionage suit against WestJet, a fight that ended in a CAD 15.5 million WestJet settlement and public apology.
PSThe FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports and financial records in an unsecured dumpster, kept doing it even after a written FTC warning, and paid a $50,000 penalty.
PSA Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street outside an unidentified Robertson, Smith & Kempson estate agent branch, and after the agency ignored an initial ICO warning and repeated the practice, the ICO secured a formal undertaking rather than a fine.