Social Engineering Examples

Physical Social Engineering (Tailgating & Baiting)

Physical social engineering skips the screen entirely: tailgating into a building, dropping an infected USB drive where someone will plug it in, or posing as a contractor or guest to get past a front desk. These 22 cases show that a lot of the most damaging intrusions in history, including Stuxnet, started with a person walking through a door rather than a phishing email.


22 Cases
PS
Confirmed

Yujing Zhang Mar-a-Lago Intrusion

A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool visit and an unverified family-tie claim, then was found carrying a USB drive initially flagged as containing malware, a determination prosecutors later said may have been a false positive, along with four phones, over $7,600 cash, and a hidden-camera detector.

Incident 2019Read →
PS
Confirmed

UIUC USB Drive Drop Field Experiment (2015)

Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that up to 98% were picked up and 45% were plugged in and opened, with the first connection occurring in under six minutes, the first rigorous, quantified real-world proof that USB-baiting works.

Incident 2015Read →
PS
Confirmed

Stuxnet: USB-borne sabotage of Iran's air-gapped Natanz enrichment plant

A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors, then physically destroyed roughly 1,000 uranium centrifuges.

Incident 2010Read →
PS
Confirmed $850K

TD Bank Lost Unencrypted Backup Tapes - Multistate and Massachusetts AG Settlements

Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a roughly seven-month notification delay led to a $850,000 multistate AG settlement and a separate $825,000 Massachusetts settlement mandating encryption of all backup media going forward.

Incident 2012Read →
PS
Confirmed $500K

Tennant Co. v. Advance Machine Co. - Dumpster Diving / Conversion Punitive Damages Verdict

Advance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads, and Advance's mishandling of the discovery led a Minnesota jury (and, on appeal, the Minnesota Court of Appeals) to impose $500,000 in combined compensatory and reinstated punitive damages, a landmark early US ruling that trash retains a protectable privacy/property interest against competitor theft.

Incident 1978Read →
PS
Confirmed $1.1M

Shred-It and Iron Mountain Pay $1.1 Million to Settle GSA Shredding False Claims Act Whistleblower Suit (2013)

A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec micro-cut document shredding while using equipment that could not physically produce that particle size, settling in July 2013 for $1.1 million combined ($800K Iron Mountain, $300K Shred-It), with Cintas continuing to contest the claims.

Incident 2013Read →
PS
Confirmed $1M

Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records

TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading to a joint FTC/HHS settlement including a $1 million HIPAA payment and a 20-year FTC security-audit order.

Incident 2006Read →
PS
Alleged

Saudi Aramco "Badge Surfer" Claim in the 2012 Shamoon Attack - A Security-Awareness Narrative Without Primary-Source Corroboration

A widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy failure to help trigger the 2012 Saudi Aramco Shamoon wiper attack, but no primary source (Reuters, Symantec, Kaspersky, CISA, Panetta's Pentagon remarks) corroborates any physical-access role in the actual, well-documented malware intrusion that wiped ~30,000-35,000 Aramco workstations.

Incident 2012Read →
PS
Confirmed

P&G's 'Bad Hair Day': Dumpster-Diving Corporate Espionage on Unilever's Hair-Care Business

P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G self-disclosed the operation, fired three employees, and settled with Unilever in September 2001.

Incident 2000Read →
PS
Confirmed

Rapid7 'Blank Badge' Physical Penetration Test: Tailgating, Door-Reciprocity, and a Fake New-Employee Help-Desk Pretext

A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up on a bystander employee's badge scan, then posed as a new security-team hire at the help desk for 30 minutes to probe whether staff would challenge him. He was ultimately stopped, seven months later, by a guard who cited that very fake-badge incident as the reason for denying access.

Incident 2018Read →
PS
Confirmed

Nations Title Agency / Nations Holding Company Dumpster Diving and Hack Exposure (FTC Settlement, 2006)

A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title company's open dumpster, and combined with a 2004 website hack, it triggered an FTC settlement over failed data-security safeguards.

Incident 2006Read →
PS
Confirmed $49M

Kaiser Permanente Medical Waste and Patient Records Dumpster-Disposal Settlement

California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured, publicly accessible dumpsters at 16 Kaiser Permanente facilities statewide, resulting in a $49 million settlement.

Incident 2023Read →
PS
Confirmed

Greenpeace v. Dow Chemical / Sasol Corporate Espionage ("D-Lines")

Dow Chemical and Sasol paid PR firms Ketchum and Dezenhall, who subcontracted private intelligence firm Beckett Brown International to run over 120 dumpster-diving raids on Greenpeace's DC offices between July 1998 and July 2000, including using a bribed/subcontracted DC police officer's badge to bypass a locked trash enclosure.

Incident 1998Read →
PS
Confirmed

GAO Covert Testers Use Fake Law-Enforcement Badges and Driver's Licenses to Breach Federal Buildings, Including an IRS Facility (2000-2009)

Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test, ordinary driver's licenses) to talk their way past armed-guard checkpoints at federal buildings, including an IRS facility, with a 100% breach rate each time, exposing how a claimed badge of authority overrides physical security screening. No public record substantiates a parallel breach of the U.S. Capitol or the GAO-13-370 report cited in some retellings.

Incident 2000Read →
PS
Confirmed

FIN7 BadUSB "Best Buy" Gift Card Mailings via USPS

FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.

Incident 2020Read →
PS
Confirmed

FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.

Incident 2015Read →
PS
Confirmed $2.3M

CVS Caremark Pharmacy Trash Disposal Case (FTC/HHS Settlement)

CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters; media exposure across a dozen-plus cities led to a $2.25M HHS settlement and a separate FTC consent order in 2009.

Incident 2006Read →
PS
Confirmed

Doorstep Dispensaree: Unsecured Patient Records Found in a Pharmacy's Back Yard Trigger the ICO's First GDPR Fine (2019)

An MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home patients' hard-copy prescription and NHS records left rotting in unlocked crates, bin bags and a cardboard box in the open rear yard of a London pharmacy supplier, triggering the ICO's first-ever GDPR fine.

Incident 2018Read →
PS
Confirmed

Operation Buckshot Yankee: Infected USB Flash Drive Breaches U.S. Central Command Networks

A malware-laden USB flash drive plugged into a laptop at a U.S. military base in the Middle East in 2008 let the agent.btz worm crawl onto classified SIPRNet systems, triggering the Pentagon's largest-ever cleanup and helping spur creation of U.S. Cyber Command.

Incident 2008Read →
PS
Confirmed

Air Canada v. WestJet: Curbside Garbage Collection From Co-Founder Mark Hill's Home

Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from outside WestJet co-founder Mark Hill's home (a collection Hill's own affidavit says involved the investigators walking onto his driveway, a claim IPSA disputed) and had shredded documents digitally reconstructed by a Houston forensic firm, as part of its corporate-espionage suit against WestJet, a fight that ended in a CAD 15.5 million WestJet settlement and public apology.

Incident 2003Read →
PS
Confirmed $50K

American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports and financial records in an unsecured dumpster, kept doing it even after a written FTC warning, and paid a $50,000 penalty.

Incident 2006Read →
PS
Confirmed

Robertson, Smith & Kempson Estate Agent Refuse Sack Data Exposure (2013-2014)

A Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street outside an unidentified Robertson, Smith & Kempson estate agent branch, and after the agency ignored an initial ICO warning and repeated the practice, the ICO secured a formal undertaking rather than a fine.

Incident 2013Read →