
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
A hired security tester socially engineered a hospital nurse to unlock a restricted medical records room, despite having a non-working fake badge. He used a believable story, referenced a real doctor’s name, and built rapport by complaining about that doctor to convince the gatekeeper to let him in. The story highlights how friendly, “I belong here” behavior can bypass physical controls and lead to exposure of sensitive medical files.
A hired security tester posed as a brand-new hospital employee. He wore scrubs and carried a fake security badge that could not possibly swipe in at the door. When the badge failed, he did not walk away. Instead, he leaned into a pretext: a named doctor on staff was allegedly failing to pull records needed for a trauma case, and he had been sent to retrieve them urgently.
The nurse gatekeeping the restricted records room responded to the story, and to the shared frustration about the doctor's behavior, by opening the door and letting him in. Once inside, he retrieved a targeted patient file. Rather than leaving immediately, he stayed and talked with the nurse for another ten minutes, complaining about security being incompetent, which further normalized his presence.
Several factors combined to make this pretext effective:
Defenders in healthcare settings should treat these signals as warning signs:
Organizations can reduce the risk of this kind of physical social engineering by reinforcing that appearance and confidence are not proof of authorization. Staff should be trained to treat a non-working badge as a trigger for a documented verification process, such as contacting security or a supervisor, rather than manually opening restricted doors. Even in situations framed as urgent or life-or-death, access to sensitive areas like medical records rooms should require verified identity. Building this habit reduces the chance that a friendly, confident pretext alone can bypass physical access controls.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
He wore scrubs, carried a fake badge that could not actually swipe in, and used a story about an urgent trauma patient's records to convince a nurse to open the door for him.
He built rapport by name-dropping a real doctor on staff and complaining about that doctor, which lowered the nurse's suspicion and made the request feel legitimate.
Treat a non-working badge as a red flag and follow a documented verification process, such as calling security or a manager, rather than manually opening a door.
This case is associated with MITRE ATT&CK technique T1656, impersonation, used to gain physical access to a restricted area.
A guy in scrubs, fake badge that doesn’t even swipe… still walks into a restricted records room. He swipes, it fails, he sighs and says, “Look, I’m gonna save you the details. Dr Johnson’s being an absolute asshole, didn’t pull the trauma records. I’m brand new, they sent me to grab the file.” She says, “I got you,” badges the door for him, and he walks straight to a patient file. Then he hangs out, chatting another ten minutes so it feels normal. That’s social engineering, not teamwork. Here’s the move: if someone’s badge doesn’t work, you do not be the hero, call security or your manager and let them handle the door.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

The “Pink” data extortion group is running a real-world voice phishing campaign targeting employees in Microsoft 365 / Entra ID environments. Callers…

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

Researchers reported a real malware campaign where attackers trick people searching for Flash Player into installing a fake “Flash” installer that delivers the…

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…