Lock, Badge, Breach: Inside a Real-World Physical Pentest

No ratings

Presented at Wild West Hackin' Fest 2026 by

Most organizations spend millions securing networks and cloud systems — yet leave the front door wide open. In this session, we’ll walk through the anatomy of a real-world physical penetration test that mirrors how adversaries exploit the human and physical layer to gain initial access.From OSINT-driven reconnaissance to RFID cloning, badge spoofing, and tailgating tactics, Paul Nieto III — Founder of 0x3 Security and Red Team Operator — demonstrates how small oversights lead to complete compromise. Attendees will see the tools and tradecraft used during engagements, including Proxmark3, Flipper Zero, and covert entry techniques that make physical security an attacker’s easiest target.We’ll connect every physical action to its digital impact: rogue devices planted inside, data exfiltrated over hidden networks, and how a single cloned badge can turn into full domain access. Finally, we’ll break down defense strategies and awareness programs that actually work — from layered access control to behavioral monitoring and culture-driven deterrence.This talk bridges the gap between red and blue teams, giving defenders a front-row seat to how real-world intrusions unfold — and how to stop them before they start.