APT-level red team operations for enterprises and organizations
CASE FILE RT-0203 Manufacturing site

The €40 badge that opened the production wing

Physical red teaming proves what access controls actually stop. At this production site, a cloned €40 badge and a shift change were enough to reach the corridor nobody wanted us in.

Objective
Enter the production wing of a manufacturing site through physical controls, without touching a single system
Path
OSINT gave us shift schedules and contractor routines. A €40 ProxMark-class reader cloned a low-frequency (125 kHz) badge from half a meter in the cafeteria — badges issued before the site’s expansion were legacy HID. The clone opened the outer door of the production wing; the inner doors relied on the same credential, and CCTV was reviewed only after incidents. We reached the target corridor during a shift change, escorted per ROE by the site manager, and touched nothing.
Detected
The badge system logged the clone’s first use as a normal door open — no anomaly rules, no tailgating detection at the outer door

After: High-frequency encrypted credentials rolled out site-wide, anti-passback on secure corridors, and a quarterly physical red-team drill added to the security calendar.

Names, sectors and infrastructure details are changed; timelines and tradecraft are not. More case files →

The pattern in one page

  • Badges older than five years are usually legacy low-frequency — clonable in seconds with €40 of hardware.
  • One credential that opens everything is a single point of failure. Zone physical access like you zone networks.
  • CCTV nobody watches in real time is a recording of the breach.
Recognize the pattern?
We can verifyTypical effort
The same path against your estate, under signed ROE2–4 wks
Detection validation: what your SOC would have seenincluded
Retest after fixes, within three monthsfree

Could this path exist in your estate?

Tell us your crown jewels — we will tell you how close this case file is to your reality.

Request assessment