A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge.
Social Engineering Examples·3 sources
During an authorized physical social engineering penetration test, Rapid7 tester Steve Laura combined OSINT/on-site surveillance, a self-made badge visually mimicking employee badges, and social tailgating tactics (door-holding reciprocity, blending into a shift-change crowd) to gain unaccompanied access to a client's building and, via an employee's own badge scan, to a restricted elevator floor.
After working undetected after hours, he approached the help desk posing as a newly hired security-team employee needing a phone charger and, later, server-room access, sustaining the ruse for about 30 minutes specifically to see if anyone would challenge him before voluntarily disclosing he was a pentester. A concurrent, unrelated internal network penetration test was running at the same site under rules that kept the two test teams from coordinating on-site.
Seven months later, during a follow-up internal network pentest, the tester was denied elevator/lobby access by a security guard who explicitly cited the earlier fake-badge incident and required explicit point-of-contact confirmation, evidence the client had adopted new after-hours badge restrictions and staff training as a direct result of the first engagement.
Rapid7 published the full account on its blog on 2018-10-02 as part of its "This One Time on a Pen Test" series.
The Rapid7 tester (Steve Laura) began with OSINT and on-site surveillance: he watched the client's parking lot and entrances to note employee clothing norms and what badges looked like, then relocated to a Starbucks across the street to get a closer look at badge design so he could fabricate a convincing (visually similar but non-functional/"blank") replica.
Around 4:30 p.m., during the shift-change crowd, he tailgated behind a departing/arriving mix of employees to blend in, and used the reciprocity principle (deliberately holding doors open for staff) to get people to reciprocate the courtesy. This chain culminated when, in an elevator, an employee scanned their own badge, unknowingly carrying him up to a restricted floor.
He then lay low until most employees left, worked on assessment objectives after hours, and finally walked up to the help desk late in the evening claiming to be a new hire on the internal security team who was stuck late and needed a phone charger, testing whether staff would challenge an unfamiliar face. He sustained the pretext for about 30 minutes, including asking to be let into the server room, before voluntarily revealing he was a penetration tester.
Separately, an unrelated internal network pentest was running concurrently under rules of engagement barring the two test teams from associating on-site, and the help desk staffer even joked to him about a real pentest happening that night, unaware he was the physical tester. Seven months later, during a follow-up internal network test at the same site, the tester (using his legitimate after-hours vendor badge, not a fake one this time) got stuck in an elevator because vendor badges no longer worked on upper floors after hours, a new policy, and when he approached the lobby guard for help, the guard refused without point-of-contact confirmation, explicitly citing "an incident where someone made a fake badge and was able to gain access to our building about seven months ago."
Lure: "I'm a new employee on the security team, stuck here late. Can I grab a phone charger? Also, could you let me into the server room?" The pretext leveraged assumed insider authority (security team) plus a mundane, low-suspicion request (charger) to open a longer conversation. Tell: after roughly 30 minutes of sustained small talk deliberately designed to give the help desk staffer every opportunity to challenge him, including a moment where the staffer joked "For all I know, you are a pen tester!" and the tester deflected with "Nah, man, not me," he voluntarily disclosed that he was in fact a penetration tester, since the goal was to test (not permanently deceive) the organization.
On the initial engagement, the tailgating and reciprocity tactics succeeded completely: the tester gained building and elevator access, worked unchallenged after hours, and sustained a 30-minute impersonation with the help desk without being definitively caught (he self-disclosed rather than being detected). He was not granted server-room access, indicating a partial control success at the most sensitive layer.
The lasting outcome was organizational: the client visibly changed policy and behavior. Seven months later, during a separate internal network pentest, the same tester (now using a legitimate but after-hours-restricted vendor badge) was denied elevator/lobby access by a security guard, who explicitly invoked the earlier fake-badge incident and required point-of-contact confirmation before allowing re-entry, demonstrating the training and policy changes had taken hold.
This case is a clean, first-party-documented illustration of how badge-based physical access control collapses against basic social-engineering tactics, namely reciprocity (holding a door) and diffusion of responsibility (a bystander unknowingly badges the intruder into an elevator), regardless of how technically robust the badge system itself is. It also shows that even directly telling staff a penetration test is underway in real time doesn't guarantee a challenge: the help-desk employee joked about "you might be a pen tester" and still didn't act on it.
Uniquely, it also documents genuine security-culture improvement: the same client, faced with the same tester seven months later, had staff and policy that correctly blocked an access attempt, showing that institutional memory of a physical security incident (a guard citing "about seven months ago") plus a concrete process (after-hours vendor badge restrictions, point-of-contact confirmation) measurably closes a previously exploited gap.
Rapid7's own after-action framing recommends: (1) challenge-culture training so help desk/reception staff verify identity of unfamiliar people rather than assuming legitimacy from a badge or confident manner; (2) callback/point-of-contact verification before granting after-hours access, which the guard correctly executed seven months later; (3) restricting vendor/temporary badges from elevator and floor access outside business hours (the control that physically stopped the tester on the second visit); (4) treating physical security findings as institutional knowledge (the guard explicitly cited the prior fake-badge incident) so lessons persist across staff turnover; (5) not relying on visual badge inspection alone, since badges are trivially replicable from casual observation.
Social Engineering Examples. “Rapid7 'Blank Badge' Physical Penetration Test: Tailgating, Door-Reciprocity, and a Fake New-Employee Help-Desk Pretext”. Accessed 19 September 2026. https://socialengineeringexamples.com/rapid7-blank-badge-pentest-2018
The tester surveilled the client's parking lot and entrances to learn employee dress norms and badge appearance, then moved to a nearby coffee shop to study badge design closely enough to fabricate a visually similar but non-functional replica.
Avoid making badge design easy to observe or photograph from public vantage points where practical, though this has limits; the more durable control is not depending on visual badge inspection as the actual security layer.
During the afternoon shift-change crowd, the tester blended in with departing and arriving staff and used door-holding reciprocity (holding doors for people so they would naturally hold the next one for him) to move through access-controlled entry points without his own badge ever being checked.
Train staff explicitly that holding a door for an unbadged stranger is a security action, not just courtesy, and normalize politely asking anyone without a visible badge to badge in themselves.
In an elevator, a bystander employee scanned their own badge, which authorized the car to reach a restricted floor, unknowingly carrying the tester up with no credential check on him personally.
Configure elevator/floor access so a single badge scan cannot authorize multiple riders to restricted floors, and consider turnstile or mantrap-style entry that ties one credential to one person for sensitive areas.
The tester waited until most employees left for the day, then worked on his after-hours assessment objectives while the office was quiet, reducing the chance of being casually noticed.
After-hours motion/access monitoring and periodic security patrols increase the chance an unauthorized presence is noticed even if initial entry succeeded.
Late in the evening he approached the help desk claiming to be a newly hired member of the security team, opening with a small, low-suspicion request (a phone charger) to build rapport before making a bigger ask (server-room access).
Require verified point-of-contact confirmation (a call to HR or the employee's manager) before granting any physical resource or access to someone claiming to be a new hire, no matter how minor the initial request seems.
He kept the persona going for about 30 minutes, including through a moment where the help-desk staffer half-joked he might be a penetration tester, deliberately giving staff repeated openings to challenge him before he voluntarily disclosed the test.
Empower and explicitly train staff to act on their own suspicion in the moment. The help-desk employee's joking suspicion was correct but wasn't followed up; a stated 'when in doubt, verify, even if it feels rude' policy closes that gap, which is exactly the gap the client closed by the second engagement seven months later.
Browse by what this case has in common with others in the library.
An unrelated MHRA search warrant found care-home patient prescription and NHS records rotting in unlocked crates and bin bags at…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake…
SEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine…
A compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.
ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model.
Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test.
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that…
Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.
Imperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.