Skip to main content
Security Assessment

The Walmart Impersonation Con: Social Engineering News

By July 25, 2023No Comments

Are you expecting a Door Dash delivery, an office equipment technician, a vending machine supplier, an office supply delivery, or pest control? Do your employees wear corporate logo apparel to promote your brand? If so, your company may be at risk of a physical security breach. By simply “looking the part” and/or having the correct papers/credentials in order, a threat actor could pose as an employee, or impersonate a known company vendor and physically infiltrate your building.

Looking the part is all it took for a criminal to infiltrate a Walmart Supercenter in Picayune, Mississippi on June 27, 2023. The Miami Herald reports that a man, wearing a Walmart employee uniform disabled a fire exit, setting the stage for him to return to the store during the night. Security camera footage reveals that for seven hours he removed thousands of dollars in merchandise from the store undisturbed.

The Walmart Impersonation Con

Image: The Miami Herald

Test. Educate. Protect.

You may find it hard to believe that someone could simply disguise themselves as a Walmart worker and get away with stealing thousands of dollars in merchandise. However, that is exactly what happened. It’s actually quite easy to impersonate a Walmart employee. A quick internet search and you will find Walmart employee logo apparel for sale on sites such as eBay and Poshmark, demonstrating the real threat an impersonation attack poses to enterprises. To meet this threat, Social-Engineer provides security assessment services. We deploy professionally trained social engineers for onsite impersonation testing of vendor/visitor access policies and your physical perimeter security. We offer this service for either day or night testing. This is a full-scope program with multiple layers which may include badge cloning, credential harvesting, and network control. Are you curious how our expert social engineers prepare for and execute an onsite security assessment? Listed below are two insightful behind-the-scenes experiences from our expert social engineers.

Chris Hadnagy, CEO for Social-Engineer, and Chief Operating Officer, Ryan MacDougall, pose as pest control technicians – Social-Engineer Podcast Episode 184

Curt Klump, Human Risk Analyst for Social-Engineer poses as a GPS clock field technician – Breaking In for NOOBZ!: Social Engineering Onsite Infiltration

Protect your organization in 2023 by implementing security assessments to test commonly used social engineering attacks such as impersonation. Stay one step ahead of the criminals by educating and regularly testing your employees for possible physical security vulnerabilities.

Please contact us today for a consultation.

You May Also Like

Impersonation Attacks

Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.