← All terms

Tailgating (Piggybacking)

Tailgating is a physical social engineering attack where an unauthorized person follows an employee through a secured door into a restricted area.

Tailgating — also called piggybacking — is a physical social engineering technique in which an unauthorized person enters a secured area by following closely behind someone with legitimate access. The attacker exploits courtesy and social norms rather than technology: most people hold the door for the person behind them, especially one carrying coffee cups, boxes, or wearing a convincing contractor's vest.

How it works

The attacker waits near a controlled entrance — an office lobby turnstile, a badge-locked side door, a loading dock — and times their approach to coincide with an employee badging in. Common pretexts include full hands ("could you grab the door?"), a fake or cloned badge held up too quickly to read, impersonating delivery or maintenance staff, or simply projecting confident familiarity. Once inside, the intruder can plant rogue devices on the network, photograph whiteboards and screens, steal unattended laptops, or drop malicious USB sticks in common areas. Strictly speaking, some practitioners distinguish tailgating (following without the employee's knowledge) from piggybacking (the employee knowingly, if naively, lets the person in), but the defensive controls are identical.

Physical intrusion is often the overlooked half of social engineering programs: organizations that rigorously test email phishing may never once test whether a stranger with a ladder can walk into the server room. The entry itself usually rides on a well-rehearsed pretext.

How to defend against it

Layer physical controls — mantraps or turnstiles at main entrances, badge readers on interior doors, and alarms on emergency exits — so a single held door doesn't grant full access. Establish a clear, blame-free norm that every person badges in individually and that challenging or reporting an unfamiliar face is expected behavior, not rudeness. Require visible badges and escorted visitors. Most importantly, test the human layer: physical social engineering assessments reveal whether policy survives contact with a friendly stranger. Results feed naturally into an employee-level view of exposure such as a Human Risk Score, alongside data from phishing and vishing simulations.

Full guide
Read the deep dive on this attack →

Related terms

Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.BaitingBaiting is a social engineering attack that lures victims with a tempting item — such as a USB drive, free download, or prize — to deliver malware or harvest credentials.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo