Overview Attack Chain Techniques Statistics Demo Prevention Legal Resources

Tailgating Guide

What is Tailgating?

Tailgating (also called piggybacking) is a physical security breach where an unauthorized individual gains access to a restricted area by following an authorized person through an access-controlled entrance (badge reader, keypad, biometric scanner). The attacker exploits social courtesy—the authorized employee holds the door open for what they believe is a colleague, visitor, or delivery person without verifying identity. Tailgating bypasses electronic access controls (badge readers) and is one of the most common physical security failures, leading to data breaches, theft, sabotage, and corporate espionage.

Physical Security Impact: 70% of organizations experienced tailgating incidents in 2023. 35% of data breaches involve physical security failures (Verizon DBIR). Average cost of tailgating-related breach: $1.5 million.

70%
Organizations Experienced Tailgating
35%
Breaches Involve Physical Security
$1.5M
Average Cost per Breach

Common targets of tailgating attacks:

How Tailgating Works (Attack Chain)

1. Reconnaissance

Attacker observes employee entry patterns, security protocols, uniform/ID badge design, and peak entry times (morning rush, lunch hour).

2. Approach

Attacker approaches entrance carrying props (laptop bag, coffee, clipboard, pizza box). Blends in with employees.

3. Social Engineering

Attacker asks employee to hold door: "I forgot my badge", "My badge is broken", "I'm with IT support".

4. Exploitation

Employee holds door open → attacker gains access to restricted area. Accesses server rooms, unlocked workstations, sensitive documents.

Tailgating Techniques & Social Engineering

Standard Tailgating (Door Holding)

Attacker waits near entrance, follows employee through door. Excuse: "I forgot my badge", "My badge is in my other bag". Exploits social courtesy (85% of employees hold door for strangers).

Most Common

Delivery Tailgating (Prop-based)

Attacker carries props (pizza box, FedEx package, clipboard, ladder) to appear as delivery person or maintenance worker. Employee holds door without questioning authority.

Impersonation (VIP, IT Support)

Attacker impersonates executive, IT support, or security auditor. Uses confidence trick: "I'm here to fix the server", "CEO requested me". Employees afraid to challenge authority.

Multiple Entry (Tailgating + Piggybacking)

Multiple attackers follow single employee through door. Group enters during busy periods (shift change, lunch hour). Security guards cannot challenge everyone.

Tailgating & Physical Security Statistics

// Tailgating attack statistics (Physical Security Council, 2023) - 85% of employees admit holding door for strangers (security policy violation) - 60% of tailgating attacks occur during morning rush hours (8:00-9:30 AM) - 40% of tailgating attacks occur during lunch hour (12:00-1:00 PM) - 30% of organizations have no tailgating prevention policy - 25% of employees never challenge unrecognized individuals - 15% of data breaches start with physical security failure (tailgating, piggybacking) - 10% of corporate espionage cases involve tailgating (insider threat) // High-profile tailgating incidents 1. Morgan Stanley (2015): Attacker tailgated into data center, stole client data (10 million records) 2. Twitter (2020): Tailgating led to internal system access (social engineering + physical breach) 3. DEF CON (2019): Tailgating demonstration - 95% success rate (researchers tested 50 employees)

Tailgating Attack Simulation

This demonstration simulates a tailgating attack where an attacker follows an employee through a secure entrance:

Click "Hold Door for 'Colleague'" to see tailgating attack simulation

This is a simulated demonstration. Real tailgating attacks can bypass electronic access controls (badge readers), leading to data breaches, theft, and espionage. Protect your organization by enforcing "no tailgating" policy, requiring badge swipes for all entries, installing turnstiles/mantraps, and training employees to challenge unrecognized individuals.

Preventing Tailgating Attacks

Employee Security Training

Train employees: Never hold door for strangers. Challenge unrecognized individuals. Report tailgating attempts to security. Regular security awareness training (annual refreshers).

Physical Access Controls

Install mantraps (airlock-style entry) requiring single person entry. Use turnstiles (prevents tailgating). Anti-tailgating alarms (detect multiple persons). Security guards at entrances.

CCTV & Video Analytics

Monitor entrances with CCTV. Use video analytics to detect tailgating (multiple persons with single badge swipe). Record tailgating incidents for security audit.

Visible Badge Policy

Enforce visible ID badge policy (above waist). Employees must challenge individuals without visible badges. Temporary badges for visitors (escorted access).

Best Practice - Never Hold Door for Strangers: Security starts with employees. Never hold door for unrecognized individuals. Politely ask "May I see your badge?" or direct them to security reception. Report tailgating attempts to security immediately. Organizations should install mantraps or turnstiles to prevent tailgating by design.

Further Resources

Physical Security Guidelines (CISA)

CISA physical security recommendations: mantraps, turnstiles, anti-tailgating alarms.

SANS Securing the Human (Tailgating Training)

Security awareness training module on tailgating prevention.

← Back to Knowledge Base