A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up on a bystander employee's badge scan, then posed as a new security-team hire at the help desk for 30 minutes to probe whether staff would challenge him. He was ultimately stopped, seven months later, by a guard who cited that very fake-badge incident as the reason for denying access.
Reviewed by the Social Engineering Examples team.
During an authorized physical social engineering penetration test, Rapid7 tester Steve Laura combined OSINT/on-site surveillance, a self-made badge visually mimicking employee badges, and social tailgating tactics (door-holding reciprocity, blending into a shift-change crowd) to gain unaccompanied access to a client's building and, via an employee's own badge scan, to a restricted elevator floor. After working undetected after hours, he approached the help desk posing as a newly hired security-team employee needing a phone charger and, later, server-room access, sustaining the ruse for about 30 minutes specifically to see if anyone would challenge him before voluntarily disclosing he was a pentester. A concurrent, unrelated internal network penetration test was running at the same site under rules that kept the two test teams from coordinating on-site. Seven months later, during a follow-up internal network pentest, the tester was denied elevator/lobby access by a security guard who explicitly cited the earlier fake-badge incident and required explicit point-of-contact confirmation, evidence the client had adopted new after-hours badge restrictions and staff training as a direct result of the first engagement. Rapid7 published the full account on its blog on 2018-10-02 as part of its "This One Time on a Pen Test" series.
The Rapid7 tester (Steve Laura) began with OSINT and on-site surveillance: he watched the client's parking lot and entrances to note employee clothing norms and what badges looked like, then relocated to a Starbucks across the street to get a closer look at badge design so he could fabricate a convincing (visually similar but non-functional/"blank") replica. Around 4:30 p.m., during the shift-change crowd, he tailgated behind a departing/arriving mix of employees to blend in, and used the reciprocity principle (deliberately holding doors open for staff) to get people to reciprocate the courtesy. This chain culminated when, in an elevator, an employee scanned their own badge, unknowingly carrying him up to a restricted floor. He then lay low until most employees left, worked on assessment objectives after hours, and finally walked up to the help desk late in the evening claiming to be a new hire on the internal security team who was stuck late and needed a phone charger, testing whether staff would challenge an unfamiliar face. He sustained the pretext for about 30 minutes, including asking to be let into the server room, before voluntarily revealing he was a penetration tester. Separately, an unrelated internal network pentest was running concurrently under rules of engagement barring the two test teams from associating on-site, and the help desk staffer even joked to him about a real pentest happening that night, unaware he was the physical tester. Seven months later, during a follow-up internal network test at the same site, the tester (using his legitimate after-hours vendor badge, not a fake one this time) got stuck in an elevator because vendor badges no longer worked on upper floors after hours, a new policy, and when he approached the lobby guard for help, the guard refused without point-of-contact confirmation, explicitly citing "an incident where someone made a fake badge and was able to gain access to our building about seven months ago."
Lure: "I'm a new employee on the security team, stuck here late. Can I grab a phone charger? Also, could you let me into the server room?" The pretext leveraged assumed insider authority (security team) plus a mundane, low-suspicion request (charger) to open a longer conversation. Tell: after roughly 30 minutes of sustained small talk deliberately designed to give the help desk staffer every opportunity to challenge him, including a moment where the staffer joked "For all I know, you are a pen tester!" and the tester deflected with "Nah, man, not me," he voluntarily disclosed that he was in fact a penetration tester, since the goal was to test (not permanently deceive) the organization.
On the initial engagement, the tailgating and reciprocity tactics succeeded completely: the tester gained building and elevator access, worked unchallenged after hours, and sustained a 30-minute impersonation with the help desk without being definitively caught (he self-disclosed rather than being detected). He was not granted server-room access, indicating a partial control success at the most sensitive layer. The lasting outcome was organizational: the client visibly changed policy and behavior. Seven months later, during a separate internal network pentest, the same tester (now using a legitimate but after-hours-restricted vendor badge) was denied elevator/lobby access by a security guard, who explicitly invoked the earlier fake-badge incident and required point-of-contact confirmation before allowing re-entry, demonstrating the training and policy changes had taken hold.
This case is a clean, first-party-documented illustration of how badge-based physical access control collapses against basic social-engineering tactics, namely reciprocity (holding a door) and diffusion of responsibility (a bystander unknowingly badges the intruder into an elevator), regardless of how technically robust the badge system itself is. It also shows that even directly telling staff a penetration test is underway in real time doesn't guarantee a challenge: the help-desk employee joked about "you might be a pen tester" and still didn't act on it. Uniquely, it also documents genuine security-culture improvement: the same client, faced with the same tester seven months later, had staff and policy that correctly blocked an access attempt, showing that institutional memory of a physical security incident (a guard citing "about seven months ago") plus a concrete process (after-hours vendor badge restrictions, point-of-contact confirmation) measurably closes a previously exploited gap.
Rapid7's own after-action framing recommends: (1) challenge-culture training so help desk/reception staff verify identity of unfamiliar people rather than assuming legitimacy from a badge or confident manner; (2) callback/point-of-contact verification before granting after-hours access, which the guard correctly executed seven months later; (3) restricting vendor/temporary badges from elevator and floor access outside business hours (the control that physically stopped the tester on the second visit); (4) treating physical security findings as institutional knowledge (the guard explicitly cited the prior fake-badge incident) so lessons persist across staff turnover; (5) not relying on visual badge inspection alone, since badges are trivially replicable from casual observation.
An MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive…