Electronic access control systems are a cornerstone of physical security for most organisations. Employees badge in, doors unlock, and an audit trail is created. But the technology behind many of these systems is decades old, and the gap between perceived security and actual security can be significant.

How RFID access control works

Most building access control systems use RFID (Radio-Frequency Identification) or NFC (Near-Field Communication) technology. An employee holds a card or fob near a reader, the reader picks up a unique identifier from the card, and the access control system checks whether that identifier is authorised for that door at that time.

The critical distinction is between the two main frequency bands used:

Low-frequency (125 kHz). Cards operating at this frequency — including the widely deployed HID Prox and EM4100 formats — transmit their identifier in the clear, with no encryption or authentication. The card simply broadcasts its number whenever it is powered by the reader’s electromagnetic field. These cards have been in use since the 1990s and remain extremely common.

High-frequency (13.56 MHz). Cards at this frequency — including MIFARE Classic, MIFARE DESFire, HID iCLASS, and HID SEOS — offer varying levels of security. Some, like MIFARE Classic, have known cryptographic weaknesses that have been publicly documented since 2008. Others, like MIFARE DESFire EV2/EV3 and HID SEOS, use strong encryption and mutual authentication that make cloning significantly more difficult.

How badges are cloned

The ease of cloning depends entirely on the card technology in use.

125 kHz cards. These are trivially cloneable. A device such as a Proxmark or a purpose-built cloner can read the card’s identifier from a distance of several centimetres and write it to a blank card in seconds. The equipment is inexpensive and readily available. An attacker needs only brief proximity to the target — standing nearby in a lift, sitting next to someone in a cafe, or brushing past them in a corridor.

MIFARE Classic. Despite operating at the higher 13.56 MHz frequency, MIFARE Classic cards use a proprietary encryption algorithm (Crypto-1) that was reverse-engineered and publicly broken in 2008. With the right equipment, an attacker can extract the encryption keys and clone the card. This takes longer than cloning a 125 kHz card but is well within the capability of a moderately skilled attacker.

Long-range reading. While standard readers operate at close range, purpose-built antennas can extend the read range significantly — particularly for 125 kHz cards. Concealed in a bag or briefcase, a long-range reader can capture card data from a distance that the target would never notice.

Social engineering. Sometimes the simplest approach is to borrow or steal a badge. An assessor might pose as a facilities contractor who needs to “test” a badge, or distract a receptionist long enough to lift a spare badge from behind the desk. Lost and unreported badges are another common attack vector.

Why so many organisations are still vulnerable

Despite the known weaknesses in older card technologies, a large number of organisations continue to use them. There are several reasons:

Legacy infrastructure. Replacing an access control system is expensive. It is not just the cards — it is every reader on every door, the controller hardware, the wiring, and the back-end software. For a multi-site organisation, this can represent a significant capital investment.

Lack of awareness. Many organisations do not know which card technology their system uses, or that it is vulnerable. The system was installed by a contractor, it works, and no one has questioned its security since.

Assumed security. The presence of an access control system creates a perception of security, regardless of the underlying technology. If employees are badging in and doors are locking, the system appears to be functioning correctly.

Mixed environments. Organisations that have upgraded some doors but not others, or that operate across multiple sites with different systems, may have a patchwork of strong and weak controls.

How this fits into a physical security assessment

RFID badge cloning is a standard technique in physical penetration testing. During an assessment, the tester will:

  1. Identify the card technology. By visually inspecting cards and readers, or by using a detection device, the assessor determines what technology is in use and whether it is vulnerable to cloning.

  2. Attempt to capture card data. If the technology is cloneable, the assessor will attempt to read a card — either through close proximity to an employee or by obtaining a card through social engineering.

  3. Clone the card. The captured data is written to a blank card, which is then used to test whether it grants access to the target areas.

  4. Document the findings. The report details which card technology is in use, how the data was captured, whether cloning was successful, and which areas could be accessed with the cloned badge.

Defending against badge cloning

Organisations can significantly reduce their exposure to badge cloning through a combination of technology upgrades and procedural controls.

Upgrade card technology. Move to cards that use strong, proven encryption and mutual authentication. MIFARE DESFire EV2 or EV3, and HID SEOS, are current best-practice options. Ensure that readers are configured to require encrypted communication — some readers support multiple protocols and may fall back to insecure modes if not properly configured.

Multi-factor physical access. For sensitive areas such as server rooms, data centres, and executive floors, require a second factor in addition to the badge. This could be a PIN, a biometric (fingerprint or facial recognition), or a mobile credential. A cloned badge alone should not be sufficient to access high-value areas.

Shielded badge holders. RFID-blocking sleeves or wallets prevent cards from being read when not in use. While not a substitute for upgrading card technology, they reduce the window of opportunity for long-range reading.

Monitor for anomalies. Access control systems generate logs. Monitor them for unusual patterns: a badge used at two distant locations in quick succession, access attempts outside normal working hours, or repeated failed attempts at a single door.

Visitor and contractor management. Ensure that temporary badges are issued, tracked, and returned. Deactivate badges for former employees and contractors promptly. Audit the active badge list regularly.

Challenge culture. Technology alone is not sufficient. Staff should be encouraged — and trained — to challenge unfamiliar individuals and to report lost or stolen badges immediately.

The bigger picture

RFID badge cloning is one technique among many in a physical attacker’s toolkit. It is effective because it is quiet, fast, and leaves no visible trace. An attacker who clones a badge and walks through the front door using someone else’s identity will not trigger an alarm, will not be captured on camera as an intruder, and will appear in the access logs as a legitimate employee.

Understanding the real-world security of your access control system — not just the theoretical security described in the vendor’s brochure — is a critical part of any physical security programme.