Tailgating (also called piggybacking) is a physical security breach where an unauthorized individual gains access to a restricted area by following an authorized person through an access-controlled entrance (badge reader, keypad, biometric scanner). The attacker exploits social courtesy—the authorized employee holds the door open for what they believe is a colleague, visitor, or delivery person without verifying identity. Tailgating bypasses electronic access controls (badge readers) and is one of the most common physical security failures, leading to data breaches, theft, sabotage, and corporate espionage.
Physical Security Impact: 70% of organizations experienced tailgating incidents in 2023. 35% of data breaches involve physical security failures (Verizon DBIR). Average cost of tailgating-related breach: $1.5 million.
Common targets of tailgating attacks:
Attacker observes employee entry patterns, security protocols, uniform/ID badge design, and peak entry times (morning rush, lunch hour).
Attacker approaches entrance carrying props (laptop bag, coffee, clipboard, pizza box). Blends in with employees.
Attacker asks employee to hold door: "I forgot my badge", "My badge is broken", "I'm with IT support".
Employee holds door open → attacker gains access to restricted area. Accesses server rooms, unlocked workstations, sensitive documents.
Attacker waits near entrance, follows employee through door. Excuse: "I forgot my badge", "My badge is in my other bag". Exploits social courtesy (85% of employees hold door for strangers).
Attacker carries props (pizza box, FedEx package, clipboard, ladder) to appear as delivery person or maintenance worker. Employee holds door without questioning authority.
Attacker impersonates executive, IT support, or security auditor. Uses confidence trick: "I'm here to fix the server", "CEO requested me". Employees afraid to challenge authority.
Multiple attackers follow single employee through door. Group enters during busy periods (shift change, lunch hour). Security guards cannot challenge everyone.
// Tailgating attack statistics (Physical Security Council, 2023)
- 85% of employees admit holding door for strangers (security policy violation)
- 60% of tailgating attacks occur during morning rush hours (8:00-9:30 AM)
- 40% of tailgating attacks occur during lunch hour (12:00-1:00 PM)
- 30% of organizations have no tailgating prevention policy
- 25% of employees never challenge unrecognized individuals
- 15% of data breaches start with physical security failure (tailgating, piggybacking)
- 10% of corporate espionage cases involve tailgating (insider threat)
// High-profile tailgating incidents
1. Morgan Stanley (2015): Attacker tailgated into data center, stole client data (10 million records)
2. Twitter (2020): Tailgating led to internal system access (social engineering + physical breach)
3. DEF CON (2019): Tailgating demonstration - 95% success rate (researchers tested 50 employees)
This demonstration simulates a tailgating attack where an attacker follows an employee through a secure entrance:
This is a simulated demonstration. Real tailgating attacks can bypass electronic access controls (badge readers), leading to data breaches, theft, and espionage. Protect your organization by enforcing "no tailgating" policy, requiring badge swipes for all entries, installing turnstiles/mantraps, and training employees to challenge unrecognized individuals.
Train employees: Never hold door for strangers. Challenge unrecognized individuals. Report tailgating attempts to security. Regular security awareness training (annual refreshers).
Install mantraps (airlock-style entry) requiring single person entry. Use turnstiles (prevents tailgating). Anti-tailgating alarms (detect multiple persons). Security guards at entrances.
Monitor entrances with CCTV. Use video analytics to detect tailgating (multiple persons with single badge swipe). Record tailgating incidents for security audit.
Enforce visible ID badge policy (above waist). Employees must challenge individuals without visible badges. Temporary badges for visitors (escorted access).
Best Practice - Never Hold Door for Strangers: Security starts with employees. Never hold door for unrecognized individuals. Politely ask "May I see your badge?" or direct them to security reception. Report tailgating attempts to security immediately. Organizations should install mantraps or turnstiles to prevent tailgating by design.
Tailgating (unauthorized physical access) is illegal and may constitute trespassing, burglary, corporate espionage, or data theft:
Tailgating (unauthorized physical access) is illegal. Penalties include:
Important: This guide is for educational and defensive purposes only. Tailgating is illegal and violates physical security protocols.
CISA physical security recommendations: mantraps, turnstiles, anti-tailgating alarms.
Security awareness training module on tailgating prevention.