Tailgating, Shoulder Surfing and Dumpster Diving: The Physical Side of Social Engineering
Four physical social engineering techniques, what actually separates them, and why the controls that stop one are useless against the others.

Most security awareness programs are, in practice, phishing programs. The simulations go out by email, the metrics come back by email, and the picture that forms is of an organization attacked exclusively through its inbox. Meanwhile four of the oldest techniques in the social engineering repertoire keep working, because they operate in the physical world where almost nobody is measuring: tailgating, piggybacking, shoulder surfing and dumpster diving.
These four get grouped together in training decks and then treated as one topic. They are not one topic. They differ in what the attacker needs, what they walk away with, and — most importantly — which control stops them. A turnstile that ends tailgating does nothing about the recycling bin. A shredder that ends dumpster diving does nothing about the person reading a laptop screen on the 07:42 train. Grouping them hides that, and the result is a program that treats "physical security" as a single box to tick.
The four techniques, side by side
| Technique | What the attacker needs | What they get | The control that actually stops it |
|---|---|---|---|
| Tailgating | Timing, and a door that stays open | Physical presence inside a controlled area | Physical design: turnstiles, mantraps, door-ajar alarms |
| Piggybacking | A plausible pretext and a helpful employee | The same, with the employee's cooperation | A sanctioned challenge script and cover for using it |
| Shoulder surfing | Proximity in a public place | Credentials, PINs, whatever is on screen | Privacy filters, screen lock, workspace policy |
| Dumpster diving | An unlocked bin and an hour | Reconnaissance that makes the next attack credible | Classified disposal and destruction at source |
Read the last column and the shape of the problem becomes clear. Three of these four are solved by things you buy and install once. Only piggybacking is genuinely a human behavior problem — and it is the one that awareness training is most likely to get wrong.
Tailgating and piggybacking are not the same failure
Many glossaries treat the two words as synonyms, and our own tailgating entry notes that the defensive controls overlap. But the distinction is worth keeping, because it identifies which of two very different things went wrong.
In tailgating, the employee does not know. Someone badges in, walks through, and an intruder catches the door before the latch engages. The employee has not made a decision at all. No amount of training changes this, because there was no moment of judgment to train. This is an engineering failure, and it has engineering answers: a turnstile that admits one person per credential, an interlocking vestibule, a door contact that alarms when the leaf is held open past a threshold.
In piggybacking, the employee decides. Someone with full hands, a lanyard, a hard hat or a plausible story asks to be let in, and the employee — weighing a small chance of a security problem against a certain chance of appearing rude — holds the door. This is a pretexting success, and it is a decision made under social pressure with no organizational cover.
Telling staff to "be vigilant" does not change that calculation, because vigilance is not what is missing. What is missing is permission. An employee who challenges a stranger and turns out to be wrong pays a real social cost immediately; an employee who lets someone in pays nothing they will ever see. Until the organization makes challenging visibly safe — a sanctioned form of words, a reception desk that expects to be called, a manager who praises the person who made the awkward phone call — the incentive keeps pointing the wrong way.
The practical fix is a script, because scripts remove the improvisation that social pressure exploits. Something as plain as "I don't think we've met — reception can badge you through in a second, let me walk you over" gives the employee a way to refuse entry without refusing the person. That is a training objective you can write, rehearse and observe. "Be vigilant" is not.
Shoulder surfing became a remote work problem
Shoulder surfing used to be an ATM concern. Hybrid work moved the corporate screen into cafés, trains, airport lounges and co-working spaces, and it moved the corporate video call there with it. The exposure now includes things that were never on an ATM screen: customer records in a CRM, a candidate's file open in an HR system, an unreleased roadmap on a shared screen, a one-time passcode arriving as a notification banner.
It is also the technique most likely to be recorded rather than merely observed. A phone on a café table films a keyboard for the price of nothing, and the footage can be reviewed frame by frame afterward. Assume that anything typed in public has been captured, not glimpsed.
The controls here are unglamorous and effective: privacy filters issued by default rather than on request, short screen-lock timeouts enforced by policy, notification previews suppressed on the lock screen, and a clear-screen expectation that covers the co-working desk as well as the office one. ISO/IEC 27001:2022 puts this in Annex A control 7.7, "Clear desk and clear screen" — which is a useful thing to cite internally, because it turns a nagging request into a control with an owner.
The one behavior worth training is positional: sit with your back to a wall. It sounds trivial and it eliminates most of the opportunistic version of the attack.
Dumpster diving is the cheapest reconnaissance in the business
Of the four, dumpster diving is the one most often dismissed as dated, and it is the one that most reliably makes every other attack work. The value is rarely a password on a sticky note. The value is context.
An org chart tells an attacker who reports to whom, which is what makes a business email compromise pretext credible. An invoice reveals a vendor relationship and a billing cycle, which is what makes an invoice fraud attempt land in the right week. A printed email supplies the internal jargon, signature block and tone that separate a convincing pretext from an obvious one. Visitor logs, meeting agendas, travel itineraries, shipping labels, a decommissioned laptop in the e-waste pile — none of it is secret, all of it is useful, and together it is the difference between "Dear Sir/Madam" and a message that names the right project and the right approver.
There is also an asymmetry that defenders consistently misjudge. Dumpster diving carries almost no legal risk for the attacker in much of the world. In California v. Greenwood (1988) the US Supreme Court held that there is no reasonable expectation of privacy in trash left for collection, and most states follow that reasoning. The obligation runs the other way: the FTC Disposal Rule requires reasonable measures to destroy consumer report information, HIPAA's disposal guidance requires that protected health information be rendered unreadable, and NIST SP 800-88 sets out what sanitization means for media. The attacker's risk is low and yours is regulatory.
The control that works is destruction at the point of disposal, not at the point of collection. Cross-cut shredders at the desk and locked consoles in every print area beat a weekly collection from an open recycling bin, because the exposure window is what is being attacked. Extend the same rule to hardware: drives sanitized to a written standard before equipment leaves the building, and a disposal contractor whose chain of custody you have actually audited rather than assumed.
Why these stay invisible in a phishing-only program
A phishing simulation produces a number every month, so it gets attention every month. Physical exposure produces no number at all unless someone goes and creates one, so it gets attention after an incident. That is a measurement artifact, not a risk assessment — and it is the specific blind spot these four techniques live in.
Creating the number is not hard, and it does not require a red team retainer:
- A walk-through. Once a quarter, someone senior enough to be believed walks every controlled door at shift change and writes down which ones can be held, propped or followed through.
- A bin audit. With permission and a witness, sample the recycling from two or three floors and classify what you find: nothing sensitive, internal context, or genuinely confidential. The third category is a finding with a date on it.
- A clear-desk sweep. After hours, photograph what is visible on desks and screens. Report categories, not names.
- An announced-program, unannounced-test physical assessment. Tell the whole organization that physical testing happens and that challenging a stranger is expected and protected; run the individual test unannounced, with a written authorization letter in the tester's pocket and escalation contacts agreed in advance.
Report all four as process findings — this door, this floor, this bin, this hour — rather than as individual failures. A program that names the person who held a door teaches everyone that the safe move is to notice nothing.
Where this fits in a human risk program
The four techniques belong in a risk picture alongside email and voice, not in a separate annual slide. In human risk management terms, they are exposures with owners: facilities owns the door, IT owns the screen, procurement owns the disposal contractor, and the security team owns whether anyone is measuring. The behavior that spans all four is the same one that matters in vishing and help desk impersonation — an employee's willingness to verify an unexpected request, and their confidence that they will be backed up when they do.
That is the honest connection between the physical and digital sides. It is not that tailgating leads to ransomware, though occasionally it does. It is that the same organizational reflex — resolve the awkwardness, help the person in front of you, do not make a scene — is what every one of these attacks is actually exploiting.
Frequently asked questions
What is the difference between tailgating and piggybacking?
Both describe an unauthorized person entering a secured area behind someone who has legitimate access. The distinction practitioners draw is consent: in tailgating the employee does not know they are being followed — the intruder slips through the door as it closes — while in piggybacking the employee actively holds the door open, having been persuaded that the person belongs there. The difference matters for training, because the two failures need different fixes. Tailgating is defeated by physical design such as turnstiles, interlocking doors and door-ajar alarms. Piggybacking is defeated by giving employees an authorized script for challenging strangers. It is not defeated by telling people to be less polite. Many standards and vendors use the two words interchangeably, so it is worth defining which you mean before writing a policy around it.
Is dumpster diving illegal?
In the United States, generally no. In California v. Greenwood (1988) the Supreme Court held that there is no reasonable expectation of privacy in trash left for collection outside the curtilage of a home, and most states follow that rule. Local ordinances on trespass, scavenging and municipal recycling can still apply, and going through a bin inside a fenced or posted area is trespass regardless. The practical takeaway for a defender is that you cannot rely on the law to protect discarded material — legality is a question about the attacker's risk, not about your data. Sector regulation flips the obligation onto you: the FTC Disposal Rule, the HIPAA disposal requirements and PCI DSS all require that certain records be destroyed rather than merely thrown away.
Which of these attacks should we prioritize?
Prioritize by what the attacker gets, not by how sophisticated the technique looks. Dumpster diving is usually the cheapest and most under-defended, and it yields reconnaissance — org charts, vendor names, internal jargon — that makes every later pretext more convincing. Tailgating gives physical presence, which is the prerequisite for planting devices or stealing hardware. Shoulder surfing gives credentials but is opportunistic and hard to scale. A reasonable order for most organizations is: fix disposal first because it is cheap and permanent, then entry control, then screen and workspace hygiene.
How do you test physical social engineering without alarming staff?
Announce the program, not the test. Tell everyone that physical assessments happen and that challenging a stranger is expected and will never be held against them, then run the individual exercise unannounced. Give testers a written authorization letter to produce if they are stopped, agree escalation contacts in advance, and scope precisely which buildings, hours and actions are in bounds. Report results as process findings rather than named individuals: the useful output is that a specific door failed at a specific hour, not that a specific employee was too polite. An employee who challenges a tester and turns out to be right about the risk should be treated as the success case, publicly.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo