Join Doppel at Black Hat USA 2026 to win The Bigger Carry-On suitcase from Away
General

What Is a Tailgating Attack and How Can You Prevent Them?

A tailgating attack lets an intruder follow an employee through a secured door with no credential. Learn how tailgating works and how to stop it.

Doppel TeamSecurity Experts
July 31, 2026
5 min read

A tailgating attack can begin when a convincing visitor reaches a secured gate during the morning rush. It is 8:50 on a Tuesday, and the lobby turnstiles are moving a steady line of employees onto the floor. A visitor in a branded polo and a visitor lanyard falls into step behind an analyst, a laptop bag on one shoulder and a tray of coffees in both hands. He nods at the badge reader as if he has swiped it a hundred times, and the analyst, seeing full hands and a familiar-looking face, holds the gate.

The visitor enters through an employee-held gate without cloning a badge or forcing a lock. The day before, the front desk had received an email confirming a vendor's on-site visit, sent from a domain that differed from the vendor's real one. Within minutes the visitor is on the floor, plugging a small device into an open conference-room network jack.

Attackers often use social engineering to get their first foothold, and the held door is one of its quietest physical forms. So how does a stranger walk in without a badge, a broken lock, or a single alarm? Tailgating turns courtesy and a plausible pretext into unauthorized entry behind an organization's own people. This guide explains what a tailgating attack is, how it unfolds, why standard entrance controls miss it, and how to prevent it.

Key takeaways

Tailgating prevention starts with a clear understanding of what the attacker exploits and where common controls fall short.

  • Tailgating turns an employee's legitimate access into unauthorized physical entry.
  • Piggybacking adds employee consent, which means the defenses must address both hardware and human decision-making.
  • Badge readers, cameras, guards, and cybersecurity tools each miss part of the problem when the process leaves the second person through the door unverified.
  • Prevention requires one-person entry controls, a challenge culture, digital pretext disruption, and realistic rehearsal.

Together, those controls turn a polite door decision into a verifiable security process.

What is a tailgating attack?

A tailgating attack is a physical social engineering breach in which an unauthorized person follows an authorized employee through a secured entry point. The attacker exploits human courtesy and a plausible appearance to get inside. In federal terms, it means unauthorized individuals following authorized individuals into facilities with controlled access. It is the rare attack that beats access control without defeating it, because the door does exactly what it was built to do while the person behind it goes unchecked.

The held door is the whole exploit

The attack works because access controls are working as designed. The door authenticates the credential presented to it, not the number of people who pass through on that single swipe. The mechanic exploits human psychology, using common courtesy and the brief window that prevents thorough identity verification. Attackers need only look like they belong and time their entry.

The attack rides an employee's legitimate access

A tailgater can enter without a credential of their own. They borrow one, silently, by walking through the opening a real employee created. A badge reader can log card use while missing the physical blind spot: card-in does not equal single-person passage.

The employee's badge is genuine, the badge system logs the swipe, and the security system records a clean, authorized entry. The stranger walking in behind them leaves no trace at the door, so investigators struggle to reconstruct the breach after the fact.

Tailgating and piggybacking describe the same outcome: an unauthorized person crossing a secured threshold behind someone who has access. The common working distinction is consent, whether the employee knowingly let the person in. Federal security guidance treats the two terms as interchangeable, so the labels are often used loosely in practice. What both share is the failure point: a person made the entry decision, and credential verification never happened.

Tailgating slips through without the employee's knowledge

Tailgating is the opportunistic version. The unauthorized person follows someone with clearance through a controlled-access point without being noticed or challenged. The employee badges in and moves on, unaware that someone slipped in behind them before the door closed. The attacker exploits inattention.

Piggybacking requires the employee to make a choice. The authorized person knowingly holds the door or waves the person through, often out of courtesy or because the visitor appears legitimate. The attacker asks, and the employee says yes, usually because a props-and-pretext performance gave them a reason to.

The two failures need different controls. Turnstiles stop the unnoticed tailgater. A workforce trained to challenge stops the door-holder.

How a tailgating attack unfolds

A tailgating attack follows the same social engineering attack chain as a digital campaign, moving from studying the site to acting on the access once inside. The five stages below trace that progression from the parking lot to the network jack.

Stage 1: Setup — attackers study the site, its people, and the entrances they trust

The work starts long before anyone approaches the door. Reconnaissance consumes time and attention: attackers examine physical security controls, dress code, lanyards, and the company culture around behavior such as tailgating. Operators note details like lanyard colors so they can blend into the background, and scrape open-source intelligence such as names, job titles, or badge images to personalize the approach.

Stage 2: Launch — attackers weaponize the pretext, props, and digital lure

Reconnaissance feeds the disguise. The pretext turns into a role, such as a new employee waiting on badge activation or a visitor whose escort is running late.

Attackers stack psychological levers deliberately, pairing a uniform or heavy equipment with a claimed deadline to trigger helpfulness and confrontation avoidance. They often back the physical props with a digital setup, such as an advance vishing call so the receptionist half-expects the visitor, or a spoofed appointment confirmation planted the day before.

Stage 3: Contact — the attacker steps into the flow of legitimate foot traffic

Morning rush gives attackers the easiest opening because volume suppresses scrutiny. They blend into employee traffic and disappear into the background of the office. Two operators can also split the work: one uses the pretext from a prior vishing call to walk past reception. The second simply tailgates behind an employee who holds the door with a friendly good morning.

Stage 4: Engagement — courtesy and urgency get the door held

When the attacker needs a door held rather than an open one, they lean on social norms. The coffee-tray move works because full hands make helping feel automatic, and few employees will interrogate someone who simply looks like they belong. Confrontation avoidance keeps many people quiet even when something feels off. The technician with full hands and the badge the attacker only appears to swipe both exploit the same reluctance to challenge.

Stage 5: Compromise — one held door becomes data theft or a foothold

Once inside, a held door can become network access or a path to higher privileges. Attackers plug rogue devices into open jacks and work for hours under the target's nose without being questioned. A remote-access device can support server exploitation and a route to domain administrator privileges.

An unattended conference room and an open network jack can lead to harvested password hashes. The held door is the first move in a chain that ends in the same place as any other breach.

Why standard defenses miss tailgating attacks

A tailgating attack falls into the gap between the four controls most organizations trust to keep strangers out. Each one governs part of the entrance, and the second person steps through on someone else's authority when the process never verifies them. Why do four separate layers still miss the person in the doorway?

Badge and card systems govern credential use, but physical passage still needs separate verification. Anti-passback rules stop one badge from being used twice, yet a tailgater never touches a credential, so those rules leave the second person through the door unaddressed. Even Personal Identity Verification (PIV) multi-factor authentication validates the badge, not the number of bodies that follow it. Organizations still need a physical control that enforces single-person passage at the entry point.

Cameras and guards add real-time presence, but both have limits. Cameras record entries after the fact, so intervention depends on a challenge that a recording cannot make. Guards work with limited attention, and a confident stranger with full hands rarely reads as a threat in the half-second a guard has to react. Sustained vigilance also degrades without regular drills.

The cybersecurity stack operates above the physical layer and cannot see the door at all. Security teams should treat the physical layer as a core control, because physical access protection is "essentially the last line of defense," and an attacker with facility and equipment access can compromise many software-based controls.

Generic awareness training closes the loop on paper but rarely at the door. Most programs define tailgating, then employees improvise when a stranger with full hands is jogging toward the door they just opened. Annual videos rarely build a door-level reflex; that takes continuous reinforcement through realistic attack scenarios.

How to prevent tailgating attacks

Prevent tailgating by hardening entrances, making challenges routine, cutting off digital pretexts, and rehearsing the contact that precedes the physical approach.

Harden the entrance so one credential admits one person

Security entrances enforce one-person entry and address the unnoticed tailgater directly. Revolving doors and mantrap portals provide a strong physical control because they can verify that a user is alone during the entry event. Access control vestibules use interlocking doors to limit each cycle to a single authorization event. Prioritize server rooms and data centers first.

Make challenging an unrecognized stranger the default

Hardware stops the tailgater; culture stops the door-holder. Build a culture of questioning, where checking an unfamiliar person signals mutual respect and shared safety rather than suspicion. Treat verification as a standard safety protocol so the awkwardness attackers count on disappears. Year-round practice makes that reflex stick.

Cut off the digital pretext before the attacker reaches the door

The campaign often runs for days in the digital domain before the stranger reaches the door. Attackers build the spoofed appointment email and the lookalike vendor domain there.

Verify any request for access through a separately confirmed contact, and treat contact details in the request itself as untrusted. Run the same reconnaissance tools attackers use against the organization's own domains. Domain monitoring and vendor verification protocols starve the physical approach of its cover story.

Rehearse the workforce against the contact that precedes the approach

Security teams can test both the vishing call that sets up the visit and the door decision itself. Blended threat actors call IT help desks while impersonating employees to escalate access quickly. Rehearsing the workforce against that pretext contact, across voice and messaging as well as email, builds the muscle memory that a generic annual video rarely touches.

How Doppel defends against tailgating attacks

Doppel is the AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) and Human Risk Management (HRM). It defends against the social engineering that gets the door held, while physical access control still owns the door itself. The platform closes the social engineering gap around the door.

  • Brand Protection detects and dismantles the impersonated vendor and IT identities behind a spoofed appointment or delivery confirmation, along with the lookalike domains and cloned profiles attackers stand up to make that pretext look real. The Doppel Threat Graph correlates those isolated signals into a single campaign view, so enforcement reaches the connected infrastructure. Agentic AI correlates and executes prioritized takedowns at scale, so analysts focus on the complex escalations that require human judgment.
  • Security Awareness Training turns simulation outcomes and live attacker activity into targeted employee training.
  • Dynamic Simulation runs the vishing, smishing, and phishing pretext that sets up "let me in," and converts a detected lure into a live simulation in one click. When the platform dismantles an impersonated vendor identity in the wild today, the same lure can train the workforce tomorrow.

The workflow turns a detected impersonation asset into campaign mapping and enforcement-ready training material without forcing analysts to rebuild the lure by hand.

Stop the stranger before they reach the door

Go back to the visitor with the coffee tray. The organizations that stop him harden the entrance and rehearse the reflex to verify an unrecognized face, so a held gate becomes a verification step rather than a courtesy. They also dismantle the online impersonation that gave him a credible reason to be there in the first place.

When security teams dismantle the pretext and employees rehearse the reflex, the held door stops being the one step no control watched. The cost of walking in behind an organization's people climbs high enough that attackers look elsewhere.

Request a demo to see how Doppel dismantles the impersonation that turns a stranger into an expected guest.

Frequently asked questions about tailgating attacks

What is a tailgating attack in cybersecurity?

A tailgating attack is a physical social engineering technique in which an unauthorized person follows an authorized employee through a secured door or turnstile to enter a restricted area. It exploits human courtesy and a convincing appearance, so it works even when access control systems function exactly as designed. Because the intruder never presents a credential, the entry often leaves no record at the door.

What is the difference between tailgating and piggybacking?

The usual distinction is consent. In tailgating, the unauthorized person slips through behind an employee without that employee's knowledge, often by timing entry before the door closes. In piggybacking, the authorized employee knowingly holds the door or waves the person through. The distinction matters for defense: physical barriers stop the unnoticed tailgater, while a workforce trained to challenge unfamiliar people stops the door-holder.

What is an example of a tailgating attack?

A classic example is the coffee trick. An attacker approaches a secured door carrying several cups of coffee, appears to have their hands full, and an employee opens the door out of politeness without asking for identification. In a similar scenario, an intruder carries food trays past biometric data-center doors and tailgates through badge-activated turnstiles. Once inside, the attacker can plug a laptop into an open network jack and operate for hours without being questioned.

Why are tailgating attacks so hard to stop?

Tailgating attacks are hard to stop because they exploit human behavior outside the security stack's normal field of view. Badge readers authenticate the credential presented but cannot count how many people pass through on one swipe, and cameras and guards record and deter without often challenging a confident stranger in the moment. Generic annual training defines the concept while leaving the door-level reflex underdeveloped. Stopping the attack requires physical barriers and a challenge culture working together.

How do you prevent tailgating attacks?

Preventing tailgating attacks takes a layered social engineering protection program. Harden the entrance with security revolving doors, mantrap portals, or access control vestibules that enforce one person per credential. Build a challenge culture where verifying an unfamiliar person is a normal safety protocol. Cut off the digital pretext by monitoring for lookalike domains and spoofed vendor emails, and rehearse employees against the vishing and phishing contact that often sets up a physical intrusion.

Last updated: July 31, 2026

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.