0%
BACK TO OVERVIEW

The Legend: How Attackers Build Identities — and Why Your Team Won't Spot Them

The Legend: How Attackers Build Identities — and Why Your Team Won't Spot Them
Pretexting: How Attackers Build Identities – Access Granted

No exploit. No phishing link. Just a high-vis vest, a clipboard, and three days of preparation.

A mid-sized manufacturing company. Engineering sector. Security concept: RFID badge access control, cameras at all entrances, reception with visitor registration. The server room houses production control systems. No direct internet connection. No remote maintenance access from outside. The team was proud of it: "You don't just walk in here."

During a commissioned physical pentest engagement, we saw it differently. Three days before the actual operation: OSINT. The company website names the facility manager by name. LinkedIn shows which external HVAC company services the building — a comment under a post, publicly visible. The job listing for an in-house technician specifies the exact ticketing system used internally. The annual report mentions an ongoing renovation in Hall 3.

On the day: high-vis vest, clipboard with a printed "maintenance order", safety boots. The pretext: the air conditioning unit in the production hall is throwing fault codes, on-site diagnosis required, appointment confirmed with [name of the facility manager]. Reception calls internally — facility manager is in a meeting, unreachable. The receptionist decides to let us through. "He has an order with him."

We were unescorted on the premises for 23 minutes. Had we wanted to plant a rogue device: no problem. Had we wanted to photograph the production facility: done. With one additional pretext — "just need to check the server room cooling" — we could have accessed that too. We didn't, because it was outside our scope. An attacker would have had no reason to hold back.

Pretexting doesn't exploit a technical vulnerability. It exploits a person doing their job — who makes the wrong call in that moment. The receptionist wasn't inattentive. They were polite, helpful, and under social pressure. That's exactly the point.

3 days
OSINT preparation for 23 minutes of unescorted access
23 min.
Unescorted time on premises after successful pretext
0
Technical security measures that would have prevented access
74%
Of all data breaches involve a human element (Verizon DBIR 2024)

What pretexting actually is — and why most people underestimate it

Social engineering is the umbrella term for all attacks that exploit human behaviour rather than technical vulnerabilities. Pretexting is the methodology beneath it: the construction of a false identity, a role, a story — in short, a legend. What sounds abstract separates cleanly:

Social Engineering
The umbrella term. All techniques that exploit human trust, helpfulness, or authority to gain information or access.
Pretexting
The legend. A constructed identity, role, and story that carries the attack. Not a channel — a foundation. Pretexting can be deployed physically, by phone, or digitally.
Vishing
Pretexting by phone. The 2023 MGM hack: a caller poses as an employee, the IT helpdesk resets credentials. Legend + channel: voice.
Phishing / Spear Phishing
Pretexting by email. Spear phishing uses personalised legends — the sender "knows" the target, references real projects, real colleagues. Legend + channel: text.
Physical Pretexting
The legend is embodied physically. Uniform, ID badge, tools, demeanour. The attacker isn't anonymous — they're visibly present, but as someone else entirely. Legend + channel: body.
Tailgating / Piggybacking
Often the physical consequence of a successful pretext — or without any legend at all: simply following someone through a door. Less preparation, more opportunism.

The critical point: pretexting is not a trick — it's preparation. The actual attack — the moment at reception, the call to the helpdesk, the email to finance — takes minutes. What carries it is hours or days of research beforehand. An unprepared attacker gets challenged and falls apart. A well-prepared attacker gets waved through because their story has no gaps that anyone naturally reaches for.

The most dangerous property of a good legend: it doesn't need to be true. It only needs to seem unlikely to be false. People don't evaluate claims for truth — they evaluate them for plausibility. And plausibility is constructable.

Five layers: how a legend is built

A convincing legend is not a monologue the attacker memorises. It's a coherent system of five layers that together create a picture nobody spontaneously questions. If one layer is missing or contradicts another, friction points emerge — and friction points cost the attacker the initiative.

01
Who am I? — Role & affiliation
The identity. Not "a technician" — but specifically: employee of Company X, subcontractor for Client Y, responsible for Area Z. External service providers are particularly attractive: HVAC, cleaning, IT support, security systems, fire protection. Why? Because no internal directory exists to cross-reference. "Does he work for us?" — this question can't be answered with a quick HR lookup for an external contractor.
02
Why am I here? — Assignment & context
The assignment needs three properties: urgent enough to justify immediate action; plausible enough not to trigger questions; and vague enough that the target sees no clear way to verify it. "Routine maintenance of the air conditioning following a fault code" hits all three. "I need to check the server room" hits none. The assignment has to fit the situation — and after three days of OSINT, you know the situation.
03
What do I know? — Insider knowledge & OSINT
The strongest trust signal is specific knowledge. Names of internal contacts, the ticketing system in use, ongoing construction projects, internal abbreviations — much of this is publicly available: LinkedIn profiles, job postings, press releases, annual reports, Xing, company registries, supplier chain websites. Someone who knows the facility manager by first name and references the right ticketing system sounds like someone who's been there before.
04
What do I have with me? — Physical artefacts
People trust what they see more than what they hear. Uniforms, high-vis vests, a clipboard with a printed work order, a toolbox, an ID badge (even a barely convincing one), a smartphone showing a "maintenance assignment" — all of this dramatically reduces cognitive friction at the checkpoint. The psychology: someone who looks like they belong, and has paperwork, doesn't need verification.
05
Who do I know? — Social anchoring
Drop names. "Mr [facility manager] told me to head straight in." "The job's being coordinated through [name from LinkedIn]." Social anchoring serves one function: it transfers responsibility. The target no longer thinks "should I let them in?" — but "did [name] really say that?" That is a far less threatening question.

Why people let through what they should stop

Pretexting attacks don't work because people are stupid. They work because people operate within social systems where certain heuristics are sensible and functional in everyday life. An attacker exploits these heuristics deliberately — and overriding them costs social capital that most people are unwilling to spend in a professional context.

Authority

People follow authority signals automatically — not critically. A uniform, a title, a confident manner, an official-looking document: these are authority signals, not authority proof. A fire safety inspector in the right gear with a clipboard generates authority without ever having to demonstrate it. Anyone checking an ID typically looks at the photo and name — not the issuing body or the serial number.

Urgency

Time pressure disables evaluation reflexes. "The server room cooling is showing critical temperature readings, I need access immediately" creates a state in which weighing up the decision seems more costly than granting access. Urgency works especially well combined with authority: blocking an urgent request from an authority figure feels wrong.

Helpfulness

The most underestimated element. Politely asking someone to hold a door activates a social reflex that is almost impossible to override. The person asking casts themselves as the victim of a minor inconvenience — and the potential target becomes the helper. The uncomfortable truth: helpfulness is a virtue. Exploiting it doesn't exploit something bad in people — it exploits something good.

Social proof

"Your colleague Mr [name] was expecting me." Names the target knows or might know generate immediate plausibility. The implicit message: someone inside the organisation has already authorised this visit. Verifying it would mean distrusting that colleague — a far stronger social barrier than distrust of a stranger.

Fear of conflict

The strongest mechanism at the end. Most people want to avoid confrontation. Stopping someone who presents convincingly and carries paperwork means: saying no, demanding explanations, potentially being wrong if the visit turns out to be legitimate. The alternative — letting them through — costs nothing as long as nothing happens. This asymmetry is what carries pretexting in its final step.

Physical Pretexting
Bodily present
Uniform · Artefacts · Demeanour
Authority signal: uniform, tools, body language
Pressure: physical presence creates immediate decision demand
Helpfulness: hands full → hold the door
Fear of conflict especially strong: refusal is visible and direct
Goal: physical access, rogue device, documentation
Vishing / Phishing
Remote
Voice · Text · Context
Authority signal: tone of voice, technical vocabulary, caller ID (spoofable)
Pressure: urgency framing, artificial deadline
Helpfulness: "I need this by end of business today"
Fear of conflict lower: hanging up is easier than turning someone away in person
Goal: credentials, MFA codes, wire transfer, file access

The same five psychological levers. Two completely different channels. That's why awareness training that only covers phishing doesn't prevent physical pretexting — and vice versa. The mechanics are identical, but the contextual expression is different enough that people don't recognise them as the same pattern.

Five legends that work — and why

What makes a legend particularly convincing in a physical context? It fits a context that already exists. A maintenance technician in a factory is expected — not specifically, but categorically. The question "who are you?" disappears when the answer is already written into the environment.

Legend OSINT Sources Primary Psychological Lever Typical Goal
External Maintenance Technician
HVAC, lift, fire alarm, IT infrastructure
LinkedIn (service providers), supplier chain websites, job listings, planning applications Authority Server rooms, plant rooms, restricted areas
Fire Safety / Security Inspector
With regulatory framing, "legally required"
Regulatory websites for inspection cycles, local authority portals, press releases Authority Urgency Full building access, emergency exits, basement areas
Delivery Person with Large Package
Hands full, needs someone to hold the door
Barely needed — opportunistic legend with minimal preparation Helpfulness Bypass entry point, tailgate into secured areas
New Employee, First Day
"My badge isn't working yet, HR said..."
LinkedIn (recent job postings), Glassdoor reviews Helpfulness Social Proof Bypass access control, gain insider perspective
IT Support / Helpdesk Technician
"I just need to take a quick look at [name]'s machine"
LinkedIn, org charts, annual reports, ticketing system from job listing Authority Urgency Physical access to workstations, USB drop, network access

A vishing pretext in detail: the helpdesk call

To make the pattern concrete — what a pretexting attack sounds like over the phone when it's well prepared. The following example is fictional, but close to real techniques used in vishing engagements.

Example // Vishing Pretext Against IT Helpdesk Attacker "Good morning, this is James Webb, I'm in the London sales team. I've got a problem with my VPN access — I'm supposed to be in a client presentation in 20 minutes and I can't get in." → Name sounds internal. Location plausible. Urgency established. Target is immediately in helper mode. Helpdesk "No problem, let me take a look. Can you give me your employee ID?" Attacker "Yeah, it's... hang on, I don't have it to hand, I'm travelling to the client. Can you pull me up by email address? james.webb@[company].com." → Deflection without raising suspicion. The email address is available from the website footer or LinkedIn. Helpdesk "One moment... I can see you. What phone number do you have registered with us?" Attacker "That's part of the problem — I got a new number when I moved to the London office and I don't think it's been updated yet. My colleague Sarah from the team can confirm if you want to verify — but I genuinely have the client in 15 minutes." → Social anchoring (real name from LinkedIn). Verification offer nobody takes up. Urgency repeated. Helpdesk "Okay, I'll just reset the password quickly..." → Goal achieved. No technical exploit. No malware. Just a convincing context.

What carries this conversation: not lies nobody checks — but a story nobody wants to check. The helpdesk agent wanted to help. Urgency made verification feel expensive. Social anchoring made scepticism feel inappropriate. That is pretexting.

How to detect pretexting — and why checklists aren't enough

The honest answer first: you cannot detect a well-prepared pretext from its content. The story is plausible. The artefacts are convincing. The psychological levers are deliberately applied. What stops pretexting is not better instincts in individuals — it's processes that remove the decision from the individual in the first place.

  • Verification protocols that are actually followed: Every external service provider is pre-announced — in writing, in the system, not via a phone call the day before. Reception has a list. Anyone not on it waits. No work order replaces a system entry.
  • Mandatory callback for unannounced visitors: "I'll call [Company X] directly to confirm the appointment" — not the visitor, not the number on the work order. Look up the number independently, call independently.
  • Escort policy with no exceptions: External contractors are accompanied — always. Not to the door. Through the entire time on premises. "Just leaving them for a minute" is not a defined exception.
  • Names as trust signals must be invalidated: "Mr [manager] is expecting me" is not an access authorisation. Mr [manager] is contacted directly — not through the visitor — and confirms the appointment personally.
  • Security awareness that actually trains pretexting: Not: "don't click suspicious links." Instead: scenarios showing physical pretexting and vishing, with role plays, with concrete response options. People need a script for the moment of confrontation — not just an awareness that attacks exist.
  • Clear escalation routes without social pressure: Staff must know: stopping a visitor who isn't in the system is correct — even if they have a convincing work order, even if they become impatient, even if they drop names. Escalation is the process, not a personal judgement call.

What a physical pentest with a pretexting component reveals that no checklist can: whether your processes hold in the real moment of social pressure — or only on paper. An audit checks whether the escort policy exists. A pentest checks whether it's enforced when someone is in a hurry to get in and knows the facility manager's first name.

Conclusion: The legend beats the fence. Every time.

Technical security measures have a property that pretexting lacks: consistency. A card reader checks every badge the same way. A firewall applies its rules without fatigue. People don't. They are friendly, under time pressure, socially embedded, helpful — and in everyday life these are not weaknesses, they are strengths.

Pretexting exploits exactly these strengths. Not through deception an attentive person would catch — but through social frameworks in which the right thing looks wrong and the wrong thing looks right. Stopping the maintenance technician who urgently needs to get into the server room and knows the manager's name: that feels wrong. Letting them through: that feels right. That's where the risk lives.

If you want to know whether your processes hold, you don't need a questionnaire — you need someone to try. Further reading: how attackers bypass physical access systems is covered in the post on RFID Vulnerabilities. How rogue devices are deployed after successful access is explained in the post on Rogue Devices. And what vishing can achieve through the digital channel is shown in the post on the MGM Hack.

Would your team see through the legend?

We test whether your processes hold under real social pressure — with physical pretexting scenarios, vishing components, and a report showing exactly where the gap is.

Request Physical Pentest →
Tags // #Vishing #SocialEngineering #Awareness #PhysicalPentest #BuildingSecurity #OSINT #RedTeam #Pretexting

© AccessGranted X GmbH