Blog Image with lanyard badge

How A Fake Badge Got Us Past Two Reception Desks

Key Takeaways

  • Physical access controls only work if every step is consistently enforced, even after a visitor is signed in.
  • Replica ID badges, made from photos found on social media, passed inspection at two reception desks.
  • A plausible cover story overcame every barrier meant to stop it.
  • An existing escort policy went unenforced once the consultant was signed in.
  • Publicly shared photos can hand an attacker exactly what they need to replicate physical security assets.

How A Fake Badge Got Us Past Two Reception Desks

Would your staff let a stranger into your building if he seemed confident enough?

Most organisations assume the answer is no. On paper, this client’s building looked well protected:

  • Gated lift access requiring a key fob
  • Pass-controlled doors on every office entry point
  • Staffed reception desks on two separate floors
  • A sign-in process for all visitors

In practice, physical security controls only work if the people enforcing them follow every step, including the ones that happen after a visitor has already been signed in.

This was my first physical assessment, working alongside a senior colleague. Here’s what we found.

What We Found

Before attempting entry, my colleague and I spent time in a café near the client’s building, watching who came and went. Footfall was quiet through the morning, and we needed a moment when people would be moving in and out often enough that an unfamiliar face wouldn’t draw attention. We decided the best opportunity would come as staff returned from lunch.

 

We already had what we needed to support the approach: replica ID badges and branded lanyards, created in advance from employee photos found publicly on social media during preparation. As lunchtime traffic picked up, my colleague spotted a genuine employee heading back into the building, wearing their real badge. He pointed them out to me, and I saw my moment. I followed, timing my entry to blend in with a real employee returning from lunch.

 

Using the replica badge, I approached the building’s gated lift entrance and tapped it against the reader.

Physical penetration test case study: replica security badge used to bypass office reception

It didn’t work, which I expected. But it did prompt a member of staff at reception to intervene. I was questioned directly: did I usually work on site, when had I last visited, how had I got in before. I explained that I normally worked remotely and had been let in on a previous visit.

 

Asked to confirm my company email address, I gave the standard first-name-dot-surname format, correctly guessed rather than known. That was enough. I was signed in and directed to the correct floor.

A second reception desk was waiting upstairs, along with several pass-controlled doors. Stopped again, I was asked who I was visiting. I gave the name of a real employee, gathered in advance during preparation. That answer was enough to earn a visitor pass and directions to the right part of the office.

 

Being signed in as a visitor should have meant being collected and escorted from reception. Instead, I was simply pointed in the right direction and left to find my own way.

 

Once inside, the office was quiet enough that no one questioned me finding a desk at the back. The network ports at that desk turned out to be isolated from the internal network, a control working exactly as intended, so I moved to a different point in the office to plant the device instead.

The Risk 

  • Replica identification, built entirely from publicly available photos, was convincing enough to pass visual inspection twice
  • A plausible cover story consistently overrode the friction that access controls are meant to create
  • Sign-in processes and visitor passes recorded the visit, but did nothing to verify the story behind it
  • The organisation’s own visitor escort policy existed but wasn’t followed once I was signed in
  • Photos shared publicly, of staff, events, or offices, had inadvertently supplied the exact badge design needed to replicate it

The Implication 

Nobody broke a lock, cloned a fob, or exploited a technical flaw. Most of the controls in that building worked exactly as designed, including the network segmentation that forced a change of plan. What failed was further back in the chain: a confident story overriding two reception checks, and an escort policy that existed on paper but wasn’t enforced in practice.

What We Recommend

  • Staff awareness and challenging policy. Every employee, not just security personnel, should be trained and empowered to challenge anyone unrecognised or without valid ID, and this should be covered explicitly in onboarding and refresher training.
  • Visitor escort enforcement. Being signed in should never substitute for being collected and accompanied. Visitors should be escorted at all times, particularly in any area with access to network infrastructure.
  • Badge verification, not observation. A badge should be verified against a pre-booked visitor management system, not simply glanced at. Unbooked visitors should require sign-off from a senior staff member before entry.
  • A photography and social media policy. The badge design that made this possible came directly from publicly shared photos. Staff and event imagery that shows badge designs, lanyards, or access control infrastructure should be reviewed or obscured before publication.

What Does This Mean For Your Organisation?

Access control systems are usually judged on whether they’re in place, not on whether every step, including the ones after someone’s already been let in, is consistently followed. Fobs, passes, and sign-in sheets are the easy part to audit. Whether your staff would challenge a confident stranger, and whether your own processes hold up once someone’s inside, is much harder to know without testing it.

If you’ve never tested how your organisation would respond to a real attempt at physical intrusion, it’s worth finding out before someone else does.

Find out how our physical and social engineering assessments could test your organisation. Visit our Penetration Testing page or get in touch to discuss your requirements.

Picture of Arlyn Miles

Arlyn Miles

Arlyn is a penetration tester who enjoys tackling complex customer challenges across a wide range of engagements. He is motivated by understanding real-world risks and helping organisations address them through practical, hands-on testing. Arlyn values continuous learning to keep his skills sharp.

Contact us..

Related Articles