Fake Badges and Uniforms to Walk In

Pentest Partners · Low sophistication
Last updated July 30, 2026

The article describes how social engineers can use cheap, online-ordered lookalike lanyards, ID badges, uniforms, and PPE to appear legitimate and gain physical access to facilities. It’s based on real physical security engagements where testers used convincing “visual tokens of trust” (badges, branded clothing, key fobs, letterhead) to reduce suspicion. The main lesson is that appearance is not identity, staff must consistently verify unfamiliar people even when they look the part.

How the attack worked

This breakdown is based on real physical security engagements where testers used branded lanyards, ID badges, uniforms, hard hats, key fobs, and corporate materials to appear legitimate. None of these items alone guaranteed entry. Instead, the combination of a credible badge, matching clothing, and a plausible reason for being onsite was often enough to avoid scrutiny at reception, doors, and turnstiles.

The items themselves were not sophisticated. Online suppliers make it easy to order or produce convincing copies of badges, lanyards, and branded apparel using nothing more than logos and photos found publicly. This keeps the attack sophistication low while the payoff, unchallenged physical access, remains high.

Why it succeeded

The core weakness is that appearance was treated as a substitute for verified identity. When someone looks the part, staff are less likely to ask questions, especially if the person offers a simple, believable reason for being there. Multiple small trust signals stacking together, badge plus clothing plus props, created enough social proof to bypass normal access procedures like badge scans, sign-in, or escort requirements.

What to watch for

  • An unfamiliar person is not challenged because they visually match expectations for staff or contractors.
  • Badge or uniform details are slightly off, such as print quality or missing security features like holograms.
  • The person relies on a plausible verbal explanation instead of completing standard access steps (scan, check, sign-in, escort).
  • Access procedures are skipped because someone appears rushed, busy, or clearly on the job.

How to build resistance

  • Treat badges, lanyards, and uniforms as visual cues only, never as proof of identity on their own.
  • Reinforce that reception, security, facilities, and general staff should challenge unfamiliar people and complete verification every time, even when someone looks like they belong.
  • Use ID badges with anti-counterfeit features such as holograms, unique colors, or controlled materials to raise the cost and effort required to fake them.
  • Build a genuine "trust, but verify" culture rather than one that relies on visual assumptions, since this is described as necessary even when the counterfeit items themselves look convincing.

This technique aligns with T1656, impersonation, and applies to any organization with physical offices or sites that use badges, uniforms, PPE, or branded access-control apparel.

Key findings

  • Online suppliers make it easy to buy or create convincing copies of lanyards, ID badges, branded clothing, and PPE using public logos/photos.
  • Multiple small “trust” signals together (badge + clothing + props) can make an intruder look like they belong, even if no single item works alone.
  • The author states these props have been used/faked during real physical security engagements to facilitate entry.
  • Anti-counterfeit features (e.g., holograms, unique colors/materials, controlled vendors) can raise attacker cost, but staff verification is still required.
  • A consistent challenge-and-verify culture is necessary; relying on appearance as proof of identity is a weakness.

Who’s being targeted

  • Commonly targeted roles: Reception, Security, Facilities, Office staff, Operations/site leads.
  • Affected industries: Any organization with physical offices or sites, Organizations using badges, uniforms, PPE, or branded access-control apparel.
  • Attack channels: physical.
  • Impersonated: Employee or onsite contractor (made credible by branded badge/PPE).

Red flags to watch for

  • Person is unfamiliar but is not challenged because they ‘look like they belong’
  • Badge/uniform details are slightly off (print quality, missing security features)
  • Relies on a plausible reason for being there instead of completing access procedures
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do attackers get convincing fake badges and uniforms?

According to the source, online suppliers make it easy to order or create convincing copies of lanyards, ID badges, branded clothing, and PPE using public logos and photos, often in small quantities.

Does one fake item like a badge get an attacker through the door?

No, the article notes that no single item gets someone through the door, but combined trust signals like a badge, matching clothing, and a plausible reason for being there can be enough to avoid scrutiny.

What can organizations do to reduce this risk?

Anti-counterfeit features such as holograms, unique colors or materials, and controlled vendors can raise attacker cost, but staff still need to challenge unfamiliar people and follow access procedures every time.

Who should be trained to spot this kind of physical social engineering?

The targeted audience includes reception, security, facilities, office staff, and operations or site leads, since any of these roles could be the point where an unverified person is let through.

Read the video transcript

That person in the perfect company hoodie and shiny badge? They might have ordered all of it online last night. On real security tests, teams have walked in using fake badges, uniforms, hard hats, even key fobs, no single item is perfect, but together they make you look like you belong. They walk up and say, “Hi, I’m here for work onsite today,” and people wave them through because the badge, clothing, and story feel right, even when the badge never gets scanned and the name isn’t checked. Here’s the rule: appearance is not identity. If you don’t personally know them, don’t wave them through, use the normal process every time: scan the badge, check the name, or call for an escort.

MITRE ATT&CK techniques

Similar attacks

Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

July 31, 2026
Fake Flash Installer Drops AtlasRAT

Fake Flash Installer Drops AtlasRAT

Researchers reported a real malware campaign where attackers trick people searching for Flash Player into installing a fake “Flash” installer that delivers the…

July 31, 2026
Invoice Phish Leads to Resilient ValleyRAT

Invoice Phish Leads to Resilient ValleyRAT

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

July 31, 2026