A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool visit and an unverified.
Social Engineering Examples·12 sources
On March 30, 2019, during a period when President Trump was in residence, Yujing Zhang approached the Secret Service's outer checkpoint at the Mar-a-Lago Club and gained entry by telling the first agent she was going "to the pool." Club staff let her continue after noting she shared a surname with an actual member and speculating she might be a relative; she gave no definite answer when asked if that member was her father.
Escorted by golf cart toward the main building, she told the driver she did not know where she wanted to go. Once inside, she gave shifting justifications for her presence, first a "United Nations Chinese American Association" event, then a "United Nations Friendship Event" between China and the U.S., and produced a purported event invitation; no such event existed at the property that day.
She was detained and searched. On her person, agents found four cellphones, a laptop, an external hard drive, and a USB thumb drive. A search of her room at the nearby Colony Hotel turned up a fifth cellphone, a radio-frequency/hidden-camera detector, nine additional USB drives, five SIM cards, several credit/debit cards, $7,620.11 in U.S. currency (mostly $100 bills), and about $663 in Chinese currency.
A preliminary Secret Service forensic examination of the thumb drive found that a file began installing onto the examining agent's computer immediately upon insertion; the agent halted the process because it appeared abnormal, and the complaint described the drive as containing malicious malware. That finding did not hold up: at an April 15, 2019 bail hearing, Assistant U.S. Attorney Rolando Garcia disclosed that a follow-up FBI analysis of the same thumb drive could not reproduce the file-installation behavior the Secret Service agent had observed, and that the original malware determination may have been a "false positive." No conclusive malware finding was ever entered into the record, and the magistrate judge nonetheless denied bail based on the totality of Zhang's conduct and statements.
Zhang approached the Secret Service's outer checkpoint at the Mar-a-Lago perimeter and told the first agent she was there "to go to the pool." Mar-a-Lago staff, noting she shared a surname ("Zhang") with an actual club member, let her proceed on the assumption she might be a relative; when asked directly whether that member was her father she gave no definite answer.
She was then escorted by golf cart toward the main reception area, where she told the driver she did not know where she wanted to go, a second point where the story should have collapsed. Once past that layer and inside, she shifted her cover story again, first claiming to be attending a "United Nations Chinese American Association" event that evening, then a "United Nations Friendship Event" between China and the U.S., and produced a purported invitation as a physical prop; investigators later confirmed no such event was scheduled at the property.
The repeated, shifting justifications and the prop invitation are what ultimately triggered detention and search, at which point the USB drive and other items were discovered. Note that the drive's malware finding was itself provisional: at an April 15, 2019 bail hearing, prosecutors disclosed that a follow-up FBI analysis could not reproduce the file-installation behavior the initial Secret Service examiner had observed, and that the original malware determination may have been a false positive.
The lure was a layered set of low-friction claims calibrated to whatever the current gatekeeper would accept: "I'm here for the pool" to the first Secret Service agent, an implied family tie to an actual dues-paying member sharing her surname to the club staff, and, once inside, two different fabricated "United Nations" cultural/friendship event names complete with a prop invitation.
The tell was internal inconsistency: she could not answer whether the member was her father, could not tell the golf-cart driver where she was going, and named two different, non-existent events in succession, normally enough to end an interaction, but each checkpoint here passed her forward rather than resolving the contradiction, letting the story survive three separate handoffs before detention.
Zhang was detained on site March 30, 2019, indicted April 12, 2019 on two counts (18 U.S.C. § 1752(a)(1), unlawful entry of restricted buildings/grounds; and 18 U.S.C. § 1001(a)(2), false statements to federal officers). At an April 15, 2019 arraignment/detention hearing, Assistant U.S. Attorney Rolando Garcia disclosed that a follow-up FBI analysis of the thumb drive could not reproduce the file-installation behavior the Secret Service examiner had originally observed, and that the initial malware determination may have been a "false positive"; the presiding magistrate nonetheless denied bail, calling Zhang an "extreme risk of flight." At an April 8, 2019 detention hearing, prosecutors had also stated "there is no allegation that she is involved in any espionage"; no espionage charge was ever brought.
She went to trial (choosing to represent herself for part of the proceedings after dismissing counsel), was convicted by jury verdict on September 11, 2019, and was sentenced on November 25, 2019 by U.S. District Judge Roy Altman to 8 months' imprisonment (time served) on each count concurrently, 2 years' supervised release, and a $125 special assessment.
On completing her sentence in December 2019 she was transferred to ICE custody; deportation was delayed roughly two years by COVID-19-era logistics (including a failed 2020 habeas petition to speed her removal), and she was deported to China on November 14, 2021.
The case is a canonical illustration of physical social engineering defeating a professionally staffed, high-security perimeter (Secret Service protecting a sitting president) through nothing more sophisticated than an ambiguous claim of kinship and a willingness to keep talking through multiple checkpoints rather than any technical exploit. It also illustrates the potential convergence of physical intrusion and cyber risk, even though that risk was never conclusively realized here: the actor did not need network access, she needed only unsupervised proximity to a computer to attempt introduction of a USB device that field examiners initially flagged as malware-laden, a vector that would bypass perimeter/network cyber defenses if confirmed.
Prosecutors themselves later walked that determination back as a possible false positive after FBI analysis could not reproduce the behavior, which is itself an instructive lesson about the fragility of ad hoc field malware triage. Separately from the device question, the case underscores that "she's probably a relative of a member" and "she has an invitation" are exactly the kind of unverified social credentials that determined, low-cost human intrusions rely on, and that anti-surveillance tooling (hidden-camera detectors) carried alongside bulk cash and multiple phones/SIMs is itself a meaningful red flag independent of the cover story.
Best practices this case argues for: (1) verify claimed member/family relationships against a checked membership roster before granting any access, rather than accepting a shared surname as corroboration; (2) treat inconsistent or evolving justifications for entry (pool access -> UN association event -> UN friendship event) as an escalation trigger, not a reason to keep waving the person to the next layer; (3) never plug an unknown/unvetted USB device into any checkpoint, security, or club computer; use an air-gapped burner device or a dedicated malware-analysis station (the agent here stopped an installing file only because it "looked unusual," which is not a reliable control, and the government's own follow-up FBI analysis could not reproduce the behavior, underscoring how unreliable ad hoc field triage of removable media can be); (4) screen for counter-surveillance tools (hidden-camera/RF detectors) and bulk cash/multiple phones/SIM cards as independent red flags warranting secondary screening at high-value physical sites; (5) apply consistent perimeter logic regardless of visitor presentation or claimed social ties, since the failure mode here was staff and initial checkpoint agents relaxing scrutiny based on an unverified kinship claim.
Social Engineering Examples. “Yujing Zhang Mar-a-Lago Intrusion”. Accessed 19 September 2026. https://socialengineeringexamples.com/yujing-zhang-mar-a-lago-intrusion-2019
per Palm Beach Post reporting on the case, Zhang paid roughly $20,000 to a Chinese contact for a travel package built around a purported Mar-a-Lago event tied to Trump family associates, giving her a plausible cover story and destination before she ever approached the property.
An event invitation or travel package sourced through an informal third-party broker is outside a target venue's visibility; the realistic control sits at the checkpoints downstream that actually gate physical access, not at disrupting how the cover story was manufactured.
she traveled from Shanghai with two valid PRC passports, booked a nearby hotel (the Colony Hotel), and carried multiple phones, SIM cards, a laptop, an external hard drive, and USB drives, consistent with preparation for extended, self-directed on-site activity beyond a simple event visit.
Ordinary travel and ID acquisition is not something a private venue can interdict in advance; the realistic control is the access-verification step at the perimeter, described in Stage 3, rather than anything upstream of arrival.
per the criminal complaint and affidavit, she presented a low-scrutiny, ordinary-sounding cover ("going to the pool") to the first Secret Service screening agent, a story calibrated to plausible member activity.
Require verification of any claimed purpose against an actual, checked visitor or member list at the first point of contact, instead of allowing a plausible-sounding stated purpose to substitute for a documentary access check.
she leveraged a coincidental shared surname with an actual club member to get club staff to assume a family relationship, without any documentary verification, per the affidavit.
Treat a shared surname or claimed family tie as requiring the real member's real-time confirmation before granting entry, not staff speculation based on a name match.
she moved through successive layers (golf-cart valet escort, magnetometer checkpoint, reception), each of which treated the prior checkpoint's clearance as sufficient, letting an unresolved inconsistency (not knowing her own destination) pass forward unchallenged.
Adopt a re-verify-at-every-layer rule between security checkpoints so each one independently confirms authorization rather than trusting that a person passed by a prior layer is already cleared.
when reception directly questioned her, she shifted to a fabricated "United Nations" event name and produced a prop invitation document in Chinese that agents could not read on the spot, manufacturing legitimacy under real-time pressure.
Treat any change or inconsistency in a stated reason for access, especially one appearing only once directly challenged, as an automatic escalation and detention trigger rather than a reason to keep the interaction moving.
she carried a USB thumb drive onto the grounds and it was examined on a Secret Service computer, where a file reportedly began installing, the intrusion's closest approach to a device-based objective, though prosecutors later said the malware finding may have been a false positive.
Never connect an unvetted removable-media device to any operational or security computer; use an air-gapped inspection device or a dedicated malware-analysis station for anything recovered from an unauthorized visitor.
inconsistencies (contradictory event names, no swimsuit for a stated pool visit, inability to name her destination) triggered escalation to the on-site agent, verification against the access list confirmed she was not authorized, and she was detained before any further activity could occur.
Maintain and enforce a real-time, checked master access list at reception and interior checkpoints so unauthorized presence is caught by list verification rather than relying on staff noticing behavioral oddities.
Browse by what this case has in common with others in the library.
A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge.
FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT.
An unrelated MHRA search warrant found care-home patient prescription and NHS records rotting in unlocked crates and bin bags at…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF.
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge.
Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.
A small Columbus, Ohio manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an imposter scam…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…
Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network.
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal.
Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project.
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…