How to defend the full social engineering attack chain | Register for the webinar to learn more

General

What Is a Tailgating Attack?

Tailgating attacks let unauthorized individuals slip behind authorized employees to breach physical security, exposing organizations to data theft, device implants, and ransomware. Learn how they work, their types, and effective defenses.

Doppel TeamSecurity Experts
September 23, 2026
5 min read

What Is a Tailgating Attack?

A tailgating attack is a physical social engineering attack in which an unauthorized person enters a restricted area by following closely behind someone who holds valid access. The attacker presents no credential, so the badge reader, turnstile, or guard records one authorized entry while two people walk through.

The terms piggybacking and tailgating (opens in new tab) describe the same failure under federal control guidance, though the two differ on consent: a tailgater slips through unnoticed, while a piggybacker is knowingly waved in.

How a tailgating attack works

The attack turns on timing and plausibility; the lock itself stays intact. Attackers first study the building through open-source intelligence. They map entry points, shift-change times, smoking areas, delivery schedules, and the uniforms or lanyards legitimate vendors wear. They then build a pretext that explains their presence to a receptionist or guard: co-worker, police officer, bank official, delivery person, job applicant, technical support.

Those personas recur across on-site penetration tests (opens in new tab).

Entry itself exploits ordinary courtesy. Arriving with hands full of coffee or boxes, or hovering near a door and catching it as it swings shut, invites an employee to hold it open instead of confronting a stranger. Door-holding is a reflex the attacker triggers on purpose; the likelihood that the person walking through helps in return rises with the effort someone spends holding the door, according to reciprocity research (opens in new tab).

In one documented red team engagement (opens in new tab), operators bought coffee across the street and loitered by a parking-lot entrance just before the 5 pm rush. Several employees held the door, and inside, the team found passwords on notes under keyboards, a visitor badge in a desk drawer, open network ports, and data center keys in an unlocked cabinet, which they used to plant a second device on the network.

Why tailgating attacks matter

A tailgater who reaches a desk or server rack holds physical access that most security tooling treats as unavailable to an attacker. A planted device can passively tap network traffic, modify it through an adversary-in-the-middle attack, or inject keystrokes, all under the hardware additions (opens in new tab) catalog.

In one bank intrusion (opens in new tab), a cellular-enabled implant inside the network opened a data path that conventional security tools could not see, and no firewall rule fired because the attacker was already inside.

That physical foothold can also be the on-site stage of campaigns that start remotely. The Silent Ransom Group (opens in new tab) has combined both stages against U.S. law firms. During calls, it impersonates legitimate IT services and then sends an operator to the site who poses as an employee of that IT provider.

Once on the network, the group deploys minimal software for persistence and exfiltration, then issues extortion demands.

Hybrid work has eroded the informal defense of knowing who belongs in the building: employees rotating through the office on irregular schedules make the on-site operator harder to spot, opening gaps in badge auditing (opens in new tab) and visitor monitoring. The same question also appears in access control testing.

ISO 27001:2022 certification auditors test the control in person by attempting to follow authorized personnel through access-controlled doors during site visits.

Types of tailgating attacks

Tailgating attacks can be sorted by how the attacker gets through the door and whether the authorized person knows it happened.

  • Unnoticed follow-through. The attacker slips through a turnstile or door in the seconds before the barrier closes. The badge holder walks on without realizing anyone followed. In the consent-based distinction, this is tailgating.
  • Courtesy piggybacking. An employee knowingly holds the door, out of politeness or because the stranger claims a forgotten badge. Security teams address this variant through policy enforcement and training (opens in new tab), which can include disciplinary action against the employee who let the stranger in; sensors address unnoticed follow-through instead.
  • Impersonation entry. A jumpsuit and a plumbing story, or a pizza box the attacker says has to go to another floor, persuades someone who believes the role to open the door, which applies physical pretexting (opens in new tab) at the door. Physical penetration testers search social media and company websites for photos of employee badges (opens in new tab) before the attempt.
  • Badge cloning. Attackers can clone a proximity card with a handheld reader that captures its credential without contact; a packed elevator (opens in new tab) is a common place to get close enough. The access log then shows a valid entry.
  • Digital tailgating. The term can also extend to unauthorized system access, where stolen credentials or a hijacked user session substitutes for a held door.

How to defend against tailgating attacks

Defense combines controls that catch the second body at the door, procedures that limit what a successful tailgater can reach, and training that closes the courtesy gap.

  1. Barrier controls. An access control vestibule, "a space between two sets of interlocking doors," provides the control built for tailgating and piggybacking under the PE-3 vestibule control (opens in new tab). Optical turnstiles and speed gates detect a second body passing on a single badge, and AI video analytics does the same at open doors; Punta Gorda Airport (opens in new tab) counts unique individuals against every badge swipe. Anti-passback addresses credential sharing, and badge-to-body controls detect an uncredentialed second entrant who does not present a credential (opens in new tab).
  2. Access procedures. Organizations include verifying authorizations before granting access, escorting visitors, and keeping physical access audit logs under the NIST PE-3 control (opens in new tab). For cardholder data environments, visitors must be "escorted at all times (opens in new tab)" and issued expiring badges that visibly distinguish them from personnel under PCI DSS v4.0.1 Requirement 9.3.2.
  3. Workstation controls. Organizations applying ISO 27001:2022 Control 7.7 (clear desk control (opens in new tab)) lock assets away and screen-lock unattended workstations, which matters because a locked workstation blocks session-level keystroke injection: the attacker has no active session to type into.
  4. People and culture. Employees wearing badges above the waist (opens in new tab) make a missing badge visible, and staff need the vocabulary to politely challenge an unbadged stranger plus a discreet channel to report one.

Authorized physical penetration tests validate all of it, and rehearsing the pretext call that precedes a visit belongs in the same program.

How Doppel helps

Physical access control owns the door. Doppel is the Frontier AI Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) and Human Risk Management (HRM). It defends against the social engineering that gets the door held.

Simulation emulates the vishing call, SMS, and Microsoft Teams contact that establishes a pretext before an attacker arrives on site, and Security Awareness Training delivers content that uses live attacker tactics such as the IT helpdesk and vendor impersonation personas that open doors.

The Simulation product runs voice and SMS rehearsals, along with exercises in messaging channels. When Doppel's AI detects an impersonation campaign in the wild, it dismantles the digital infrastructure supporting the campaign and uses one-click threat-to-simulation conversion to turn its live tactics into an employee exercise.

Request a demo to walk through the pretext-to-simulation loop.

Frequently asked questions about tailgating attacks

What is a tailgating attack?

A tailgating attack is a physical security breach in which an attacker gains entry to a restricted area by closely following someone who holds legitimate access credentials, exploiting courtesy, distraction, or a believable cover story rather than any technical flaw. Security teams classify it as social engineering because it exploits human behavior and social norms, and it can bypass fingerprint scanners, badge readers, and guards, all of which authenticate the credentialed person without detecting the one who follows.

What is a tailgating attack in cybersecurity?

In cybersecurity, a tailgating attack is the physical entry point of a broader intrusion. Once inside, the attacker can plug a rogue device into an open network port, drop a malicious USB, harvest credentials from an unlocked workstation, or install hardware on a server rack that runs below the operating system and stays invisible to endpoint security. Ransomware operators have paired the technique with phone impersonation of IT services and sent an operator on site after the call. Treating tailgating as a facilities issue outside the security operations center leaves those follow-on techniques without a detection owner.

What is the difference between tailgating and piggybacking?

Both terms describe an unauthorized person entering behind an authorized one, with interchangeable usage in NIST control guidance (opens in new tab). The consent-based distinction is that a tailgater follows without the authorized person's knowledge, while a piggybacker gets waved through by an employee who saw them and let them in anyway, often after a plausible excuse. Sensors and vestibules address the first; policy enforcement and training address the second.

What is an example of a tailgating attack?

In one documented physical intrusion case study (opens in new tab), operators posed as fire equipment inspectors with uniforms, a company logo, and forged letterhead granting permission to inspect extinguishers. The team obtained unsupervised access to a meeting room, found a hidden network port behind a TV screen, and installed a 4G-enabled network implant. A simpler version needs no costume: an attacker approaches a secure door carrying two cups of coffee, an employee holds it open out of politeness, and the reader logs a single authorized entry.

Last updated: September 23, 2026