← All terms

Dumpster Diving

Dumpster diving is the practice of searching an organization's discarded trash for documents, media, or hardware that reveal sensitive information for attacks.

Dumpster diving is a social engineering reconnaissance technique in which an attacker searches through an organization's discarded materials — paper documents, storage media, decommissioned hardware — looking for information that enables a bigger attack. It is one of the oldest tricks in the intruder's playbook precisely because it works: what a company throws away is often a candid snapshot of how it operates.

How it works

Attackers target the bins, recycling containers, and e-waste piles outside offices, or the unsecured trash areas of shredding contractors. The haul rarely needs to include a password on a sticky note (though it sometimes does). Far more useful are the mundane items: org charts and phone lists that map who reports to whom, invoices that reveal vendor relationships and billing cycles, meeting agendas, travel itineraries, printed emails with signatures and internal jargon, and even shipping labels that tie names to departments.

This material is fuel for pretexting: an attacker who knows your vendor's name, your invoice format, and your CFO's travel dates can craft a phone call or email that sounds unmistakably internal. Discarded hardware raises the stakes further — old laptops, USB drives, printers, and copiers frequently leave the building with recoverable data still on their disks. In most jurisdictions, taking items from publicly accessible trash is legal or only weakly restricted, which means the only real barrier is how the organization handles its waste.

How to defend against it

Make destruction the default. Cross-cut shred all business documents — a "shred-everything" policy beats asking employees to judge sensitivity document by document — and use locked disposal consoles emptied by a vetted, certified destruction vendor. Physically secure dumpsters behind fencing or in access-controlled areas. For electronics, enforce certified media sanitization or destruction before anything leaves inventory, and keep an asset-disposal audit trail.

Then close the loop with people: teach staff that the recycling bin next to the printer is an attack surface, and fold clean-desk and disposal habits into your security awareness training. Physical-layer lapses like unshredded documents tend to travel with other risky behaviors, including tailgating and shoulder surfing.

Full guide
Read the deep dive on this attack →

Related terms

Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.Shoulder SurfingShoulder surfing is observing someone's screen or keyboard to steal passwords, PINs, or confidential data — in person or via cameras in public spaces.Tailgating (Piggybacking)Tailgating is a physical social engineering attack where an unauthorized person follows an employee through a secured door into a restricted area.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo