Fake Badges and Uniforms to Walk In

Pentest Partners · Low sophistication
Last updated July 30, 2026

The article describes how social engineers can use cheap, online-ordered lookalike lanyards, ID badges, uniforms, and PPE to appear legitimate and gain physical access to facilities. It’s based on real physical security engagements where testers used convincing “visual tokens of trust” (badges, branded clothing, key fobs, letterhead) to reduce suspicion. The main lesson is that appearance is not identity, staff must consistently verify unfamiliar people even when they look the part.

How the attack worked

This breakdown is based on real physical security engagements where testers used branded lanyards, ID badges, uniforms, hard hats, key fobs, and corporate materials to appear legitimate. None of these items alone guaranteed entry. Instead, the combination of a credible badge, matching clothing, and a plausible reason for being onsite was often enough to avoid scrutiny at reception, doors, and turnstiles.

The items themselves were not sophisticated. Online suppliers make it easy to order or produce convincing copies of badges, lanyards, and branded apparel using nothing more than logos and photos found publicly. This keeps the attack sophistication low while the payoff, unchallenged physical access, remains high.

Why it succeeded

The core weakness is that appearance was treated as a substitute for verified identity. When someone looks the part, staff are less likely to ask questions, especially if the person offers a simple, believable reason for being there. Multiple small trust signals stacking together, badge plus clothing plus props, created enough social proof to bypass normal access procedures like badge scans, sign-in, or escort requirements.

What to watch for

  • An unfamiliar person is not challenged because they visually match expectations for staff or contractors.
  • Badge or uniform details are slightly off, such as print quality or missing security features like holograms.
  • The person relies on a plausible verbal explanation instead of completing standard access steps (scan, check, sign-in, escort).
  • Access procedures are skipped because someone appears rushed, busy, or clearly on the job.

How to build resistance

  • Treat badges, lanyards, and uniforms as visual cues only, never as proof of identity on their own.
  • Reinforce that reception, security, facilities, and general staff should challenge unfamiliar people and complete verification every time, even when someone looks like they belong.
  • Use ID badges with anti-counterfeit features such as holograms, unique colors, or controlled materials to raise the cost and effort required to fake them.
  • Build a genuine "trust, but verify" culture rather than one that relies on visual assumptions, since this is described as necessary even when the counterfeit items themselves look convincing.

This technique aligns with T1656, impersonation, and applies to any organization with physical offices or sites that use badges, uniforms, PPE, or branded access-control apparel.

Key findings

  • Online suppliers make it easy to buy or create convincing copies of lanyards, ID badges, branded clothing, and PPE using public logos/photos.
  • Multiple small “trust” signals together (badge + clothing + props) can make an intruder look like they belong, even if no single item works alone.
  • The author states these props have been used/faked during real physical security engagements to facilitate entry.
  • Anti-counterfeit features (e.g., holograms, unique colors/materials, controlled vendors) can raise attacker cost, but staff verification is still required.
  • A consistent challenge-and-verify culture is necessary; relying on appearance as proof of identity is a weakness.

Who’s being targeted

  • Commonly targeted roles: Reception, Security, Facilities, Office staff, Operations/site leads.
  • Affected industries: Any organization with physical offices or sites, Organizations using badges, uniforms, PPE, or branded access-control apparel.
  • Attack channels: physical.
  • Impersonated: Employee or onsite contractor (made credible by branded badge/PPE).

Red flags to watch for

  • Person is unfamiliar but is not challenged because they ‘look like they belong’
  • Badge/uniform details are slightly off (print quality, missing security features)
  • Relies on a plausible reason for being there instead of completing access procedures
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do attackers get convincing fake badges and uniforms?

According to the source, online suppliers make it easy to order or create convincing copies of lanyards, ID badges, branded clothing, and PPE using public logos and photos, often in small quantities.

Does one fake item like a badge get an attacker through the door?

No, the article notes that no single item gets someone through the door, but combined trust signals like a badge, matching clothing, and a plausible reason for being there can be enough to avoid scrutiny.

What can organizations do to reduce this risk?

Anti-counterfeit features such as holograms, unique colors or materials, and controlled vendors can raise attacker cost, but staff still need to challenge unfamiliar people and follow access procedures every time.

Who should be trained to spot this kind of physical social engineering?

The targeted audience includes reception, security, facilities, office staff, and operations or site leads, since any of these roles could be the point where an unverified person is let through.

Read the video transcript

That person in the perfect company hoodie and shiny badge? They might have ordered all of it online last night. On real security tests, teams have walked in using fake badges, uniforms, hard hats, even key fobs, no single item is perfect, but together they make you look like you belong. They walk up and say, “Hi, I’m here for work onsite today,” and people wave them through because the badge, clothing, and story feel right, even when the badge never gets scanned and the name isn’t checked. Here’s the rule: appearance is not identity. If you don’t personally know them, don’t wave them through, use the normal process every time: scan the badge, check the name, or call for an escort.

MITRE ATT&CK techniques

Similar attacks

Early Access Apps Hide Risks From Employees

Early Access Apps Hide Risks From Employees

Bitdefender reports that Google Play’s “Early Access” apps can’t be publicly rated or reviewed, reducing a key warning signal employees use to spot deceptive apps. The research found thousands of suspicious Early Access apps (including fake casino/reward apps and utilities) promoted on social…

September 11, 2026
Fraudsters Can Remotely “Brick” Phones for $3

Fraudsters Can Remotely “Brick” Phones for $3

Researchers showed that attackers can abuse mobile carriers’ “lost/stolen phone” reporting process to get devices blocked from the cellular network, even when the devices were never lost. With only a prepaid account and a target device’s IMEI number, blocking can cost just a few dollars and take…

September 11, 2026
One-Click Sogou Link Trick Dropped GRAYRABBIT

One-Click Sogou Link Trick Dropped GRAYRABBIT

Researchers reported a real intrusion where a China-linked group used a crafted link to exploit Sogou Input Method on Windows and install the GRAYRABBIT backdoor. Victims were lured into opening a special link (potentially via email or chat), which redirected Sogou’s built-in browser to an…

September 11, 2026
China-Linked Hackers Push “Gemini” Phish With Zero-Days

China-Linked Hackers Push “Gemini” Phish With Zero-Days

Proofpoint reports multiple China-aligned espionage groups used a chained set of browser/Windows zero-days (“BlueMoon”) and delivered it through phishing emails. Victims who clicked a phishing link could end up with a malicious browser extension disguised as Google Gemini, letting attackers watch…

September 11, 2026
BlueMoon Spearphish Turns One Click Into Admin

BlueMoon Spearphish Turns One Click Into Admin

Proofpoint reports that multiple espionage-focused groups are using a shared “BlueMoon” toolkit to run targeted spear‑phishing campaigns that trick people into clicking a link. A single click can trigger a Chrome/Windows exploit chain that gives attackers full Windows admin access and lets them…

September 11, 2026
Pig Butchering Scams Drive $12.7B Crypto Losses

Pig Butchering Scams Drive $12.7B Crypto Losses

FinCEN reports that overseas scam centers stole about $12.7B from U.S. victims since 2023, largely through “pig butchering” style cryptocurrency investment scams. Scammers build trust using fake personas (often romance or “financial adviser” roles), then pressure victims to buy crypto and send it…

September 10, 2026