Tailgating (Piggybacking)
Tailgating is a physical social engineering attack where an unauthorized person follows an employee through a secured door into a restricted area.
Tailgating — also called piggybacking — is a physical social engineering technique in which an unauthorized person enters a secured area by following closely behind someone with legitimate access. The attacker exploits courtesy and social norms rather than technology: most people hold the door for the person behind them, especially one carrying coffee cups, boxes, or wearing a convincing contractor's vest.
How it works
The attacker waits near a controlled entrance — an office lobby turnstile, a badge-locked side door, a loading dock — and times their approach to coincide with an employee badging in. Common pretexts include full hands ("could you grab the door?"), a fake or cloned badge held up too quickly to read, impersonating delivery or maintenance staff, or simply projecting confident familiarity. Once inside, the intruder can plant rogue devices on the network, photograph whiteboards and screens, steal unattended laptops, or drop malicious USB sticks in common areas. Strictly speaking, some practitioners distinguish tailgating (following without the employee's knowledge) from piggybacking (the employee knowingly, if naively, lets the person in), but the defensive controls are identical.
Physical intrusion is often the overlooked half of social engineering programs: organizations that rigorously test email phishing may never once test whether a stranger with a ladder can walk into the server room. The entry itself usually rides on a well-rehearsed pretext.
How to defend against it
Layer physical controls — mantraps or turnstiles at main entrances, badge readers on interior doors, and alarms on emergency exits — so a single held door doesn't grant full access. Establish a clear, blame-free norm that every person badges in individually and that challenging or reporting an unfamiliar face is expected behavior, not rudeness. Require visible badges and escorted visitors. Most importantly, test the human layer: physical social engineering assessments reveal whether policy survives contact with a friendly stranger. Results feed naturally into an employee-level view of exposure such as a Human Risk Score, alongside data from phishing and vishing simulations.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo