Case Library / Physical Social Engineering (Tailgating & Baiting) / Rapid7 'Blank Badge' Physical Penetration Test: Tailgating, Door-Reciprocity, and a Fake New-Employee Help-Desk Pretext

Rapid7 'Blank Badge' Physical Penetration Test: Tailgating, Door-Reciprocity, and a Fake New-Employee Help-Desk Pretext

A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up on a bystander employee's badge scan, then posed as a new security-team hire at the help desk for 30 minutes to probe whether staff would challenge him. He was ultimately stopped, seven months later, by a guard who cited that very fake-badge incident as the reason for denying access.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

During an authorized physical social engineering penetration test, Rapid7 tester Steve Laura combined OSINT/on-site surveillance, a self-made badge visually mimicking employee badges, and social tailgating tactics (door-holding reciprocity, blending into a shift-change crowd) to gain unaccompanied access to a client's building and, via an employee's own badge scan, to a restricted elevator floor. After working undetected after hours, he approached the help desk posing as a newly hired security-team employee needing a phone charger and, later, server-room access, sustaining the ruse for about 30 minutes specifically to see if anyone would challenge him before voluntarily disclosing he was a pentester. A concurrent, unrelated internal network penetration test was running at the same site under rules that kept the two test teams from coordinating on-site. Seven months later, during a follow-up internal network pentest, the tester was denied elevator/lobby access by a security guard who explicitly cited the earlier fake-badge incident and required explicit point-of-contact confirmation, evidence the client had adopted new after-hours badge restrictions and staff training as a direct result of the first engagement. Rapid7 published the full account on its blog on 2018-10-02 as part of its "This One Time on a Pen Test" series.

How the Attack Worked

The Rapid7 tester (Steve Laura) began with OSINT and on-site surveillance: he watched the client's parking lot and entrances to note employee clothing norms and what badges looked like, then relocated to a Starbucks across the street to get a closer look at badge design so he could fabricate a convincing (visually similar but non-functional/"blank") replica. Around 4:30 p.m., during the shift-change crowd, he tailgated behind a departing/arriving mix of employees to blend in, and used the reciprocity principle (deliberately holding doors open for staff) to get people to reciprocate the courtesy. This chain culminated when, in an elevator, an employee scanned their own badge, unknowingly carrying him up to a restricted floor. He then lay low until most employees left, worked on assessment objectives after hours, and finally walked up to the help desk late in the evening claiming to be a new hire on the internal security team who was stuck late and needed a phone charger, testing whether staff would challenge an unfamiliar face. He sustained the pretext for about 30 minutes, including asking to be let into the server room, before voluntarily revealing he was a penetration tester. Separately, an unrelated internal network pentest was running concurrently under rules of engagement barring the two test teams from associating on-site, and the help desk staffer even joked to him about a real pentest happening that night, unaware he was the physical tester. Seven months later, during a follow-up internal network test at the same site, the tester (using his legitimate after-hours vendor badge, not a fake one this time) got stuck in an elevator because vendor badges no longer worked on upper floors after hours, a new policy, and when he approached the lobby guard for help, the guard refused without point-of-contact confirmation, explicitly citing "an incident where someone made a fake badge and was able to gain access to our building about seven months ago."

The Lure & the Tell

Lure: "I'm a new employee on the security team, stuck here late. Can I grab a phone charger? Also, could you let me into the server room?" The pretext leveraged assumed insider authority (security team) plus a mundane, low-suspicion request (charger) to open a longer conversation. Tell: after roughly 30 minutes of sustained small talk deliberately designed to give the help desk staffer every opportunity to challenge him, including a moment where the staffer joked "For all I know, you are a pen tester!" and the tester deflected with "Nah, man, not me," he voluntarily disclosed that he was in fact a penetration tester, since the goal was to test (not permanently deceive) the organization.

Outcome

On the initial engagement, the tailgating and reciprocity tactics succeeded completely: the tester gained building and elevator access, worked unchallenged after hours, and sustained a 30-minute impersonation with the help desk without being definitively caught (he self-disclosed rather than being detected). He was not granted server-room access, indicating a partial control success at the most sensitive layer. The lasting outcome was organizational: the client visibly changed policy and behavior. Seven months later, during a separate internal network pentest, the same tester (now using a legitimate but after-hours-restricted vendor badge) was denied elevator/lobby access by a security guard, who explicitly invoked the earlier fake-badge incident and required point-of-contact confirmation before allowing re-entry, demonstrating the training and policy changes had taken hold.

Why It Matters

This case is a clean, first-party-documented illustration of how badge-based physical access control collapses against basic social-engineering tactics, namely reciprocity (holding a door) and diffusion of responsibility (a bystander unknowingly badges the intruder into an elevator), regardless of how technically robust the badge system itself is. It also shows that even directly telling staff a penetration test is underway in real time doesn't guarantee a challenge: the help-desk employee joked about "you might be a pen tester" and still didn't act on it. Uniquely, it also documents genuine security-culture improvement: the same client, faced with the same tester seven months later, had staff and policy that correctly blocked an access attempt, showing that institutional memory of a physical security incident (a guard citing "about seven months ago") plus a concrete process (after-hours vendor badge restrictions, point-of-contact confirmation) measurably closes a previously exploited gap.

Defenses

Rapid7's own after-action framing recommends: (1) challenge-culture training so help desk/reception staff verify identity of unfamiliar people rather than assuming legitimacy from a badge or confident manner; (2) callback/point-of-contact verification before granting after-hours access, which the guard correctly executed seven months later; (3) restricting vendor/temporary badges from elevator and floor access outside business hours (the control that physically stopped the tester on the second visit); (4) treating physical security findings as institutional knowledge (the guard explicitly cited the prior fake-badge incident) so lessons persist across staff turnover; (5) not relying on visual badge inspection alone, since badges are trivially replicable from casual observation.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: The tester surveilled the client's parking lot and entrances to learn employee dress norms and badge appearance, then moved to a nearby coffee shop to study badge design closely enough to fabricate a visually similar but non-functional replica.
Countering Stage 1: Avoid making badge design easy to observe or photograph from public vantage points where practical, though this has limits; the more durable control is not depending on visual badge inspection as the actual security layer.
2
Tailgating entry: During the afternoon shift-change crowd, the tester blended in with departing and arriving staff and used door-holding reciprocity (holding doors for people so they would naturally hold the next one for him) to move through access-controlled entry points without his own badge ever being checked.
Countering Stage 2: Train staff explicitly that holding a door for an unbadged stranger is a security action, not just courtesy, and normalize politely asking anyone without a visible badge to badge in themselves.
3
Piggybacking to a restricted floor: In an elevator, a bystander employee scanned their own badge, which authorized the car to reach a restricted floor, unknowingly carrying the tester up with no credential check on him personally.
Countering Stage 3: Configure elevator/floor access so a single badge scan cannot authorize multiple riders to restricted floors, and consider turnstile or mantrap-style entry that ties one credential to one person for sensitive areas.
4
Dwell and cover: The tester waited until most employees left for the day, then worked on his after-hours assessment objectives while the office was quiet, reducing the chance of being casually noticed.
Countering Stage 4: After-hours motion/access monitoring and periodic security patrols increase the chance an unauthorized presence is noticed even if initial entry succeeded.
5
Help-desk impersonation: Late in the evening he approached the help desk claiming to be a newly hired member of the security team, opening with a small, low-suspicion request (a phone charger) to build rapport before making a bigger ask (server-room access).
Countering Stage 5: Require verified point-of-contact confirmation (a call to HR or the employee's manager) before granting any physical resource or access to someone claiming to be a new hire, no matter how minor the initial request seems.
6
Sustained pretext under direct suspicion: He kept the persona going for about 30 minutes, including through a moment where the help-desk staffer half-joked he might be a penetration tester, deliberately giving staff repeated openings to challenge him before he voluntarily disclosed the test.
Countering Stage 6: Empower and explicitly train staff to act on their own suspicion in the moment. The help-desk employee's joking suspicion was correct but wasn't followed up; a stated 'when in doubt, verify, even if it feels rude' policy closes that gap, which is exactly the gap the client closed by the second engagement seven months later.
Quick Facts
Victim
Unnamed enterprise client of Rapid7, referred to in the published account only as a "client partner"; company name, sector, and city are not disclosed
Location
United States (specific city and building not disclosed; Rapid7 is headquartered in Boston, Massachusetts, but the assessed client's office location is not named in the account)
Date
2018-10-02 (blog publication date); the physical assessment itself occurred at an unspecified earlier date in 2018, with a follow-up internal network penetration test roughly seven months later at the same client site
Impact
None disclosed / not applicable. This was a contracted, authorized penetration-testing engagement for a paying Rapid7 client; no financial loss, theft, or breach cost is reported. The value at stake was security-control validation, not money.
Status
Confirmed
Case Type
Research / Advisory
Threat Actor
Authorized Tester or Researcher
Related

Related Cases

Doorstep Dispensaree: Unsecured Patient Records Found in a Pharmacy's Back Yard Trigger the ICO's First GDPR Fine (2019)

An MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home…

Incident 2018Read →

Yujing Zhang Mar-a-Lago Intrusion

A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…

Incident 2019Read →

FIN7 BadUSB "Best Buy" Gift Card Mailings via USPS

FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive…

Incident 2020Read →