Ocean’s Eleven Heists In a Louvre Four World

What real-world heists and insider-threat data reveal about who actually breaks into buildings, and what a physical penetration test is worth.

A still from Ocean’s Eleven: two thieves in black tactical gear and gloves work at a stainless steel vault door.

Several months ago, some dudes climbed through a window of the Louvre Museum at 9:30 in the morning and stole around $104 million worth of French Crown Jewels.

They were dressed as construction workers.

The first time I broke into a building, I shimmed a door latch from an emergency exit stairwell and walked in.

I was dressed as a guy who only owns gray t-shirts and black jeans.

My project partner had already signed the office suite guest book (a formality), used his toolbox and clipboard to make a convincing pitch that he needed to do an off-schedule check of the fire alarms, and gotten comfortable next to an exposed ethernet port.

So I joined him and we let our contact know that we had made it in and no one seemed to care, kicking off the walkthrough part of the project where we demoed badge cloning, opened some server room doors, and talked through improvements they could make.

After, as we were packing up, our contact asked me a question I thought I had the answer to: how often do people actually commit crimes this way?

I had no idea.

My quick internal logic told me that either there were Ocean’s Eleven-esque heists happening all around corporate America all the time, and no one was getting caught, or corporate office buildings don’t often deal with break-ins at all and we were performing a novelty service.

But the Louvre heist was hardly Ocean’s Eleven (even calling it a heist feels generous), and the impact was still enormous, especially since most of what was stolen hasn’t been recovered (opens in new tab) as of my writing.

So what is the value of a physical penetration test, and why on earth would you pay someone to break into your buildings?

I went to Florida to find out.

The Gurus On Mount Tampa

Last month, I got to spend a few days cloning badges in coffee shops, taking photos of security cameras from over a hundred feet away, and bypassing locked doors to plant malware on laptops.

I was attending the Practical Physical Exploitation (opens in new tab) training course put on by Ralph May and Travis Weathers of the Mayweather Group (opens in new tab), and aside from having fun in Florida with some friends while the rest of the United States tried not to freeze to death, my goal was to understand the basics of physical intrusion enough to start slowly building it into my own services.

It wasn’t the first time I had used badge cloners or bypass tools, nor was it the first time I had to socially engineer my way into a restricted area, but I like to round out any knowledge gaps with good training before I try and accept anyone’s money.

Exhausted by the intensity but invigorated by the fun, I spent the plane ride home thinking through how I would communicate the importance of physical security to a potential customer, which reminded me of the story I opened this blog with.

There were two questions I felt I needed answers to:

  1. Who do physical penetration tests help anyone defend against?

  2. Why is a physical penetration test a worthwhile expenditure?

My time in Tampa helped me with part of the first answer, which was “anyone who could do any part of what we were doing”. Obviously a clone of me who had defective intent (bad bad guy) instead of cooperative intent (good bad guy) would be an obvious threat.

We can also surmise that someone more skilled than I would be a bigger threat, and someone less skilled would be a smaller threat, but skills with a lock pick set don’t matter to a brick if the door is made of glass, and why use my lock picks as anything but paper weights if I have an undisclosed 0-day for your firewalls?

The second question is harder to answer for any organization that hasn’t already dealt with physical threats and, admittedly, this wasn’t the focus of the course.

Much like when a company undergoes its first ever internal network pentest, after which they realize how much - ahem, technical liability - they’ve inherited from Active Directory’s “intended design”, it is quite difficult to just imagine the impact, especially if you’re not sure how anyone would go about making one.

“Why would anyone go after us?” the perennial question goes. Well, have you ever considered what someone looking to make some money could do with documents you leave out in the open?

Clearly, there are some margins of uncertainty to address, here. We can do thought exercises all day, but I’m here to determine if one of the best things you can do is just let someone break in.

But let’s not get ahead of ourselves.

Who Are These People Anyway?

Somewhere in between fleecing the Las Vegas strip with George Clooney and lifting candy from a convenience store are the real threats to businesses, and when it comes to which ones anyone should pay attention to - as with all things in security) - it depends.

In the end, I came up with five threat profiles that I would use for threat modeling an organization, ordered by sophistication level:

  1. Petty Thieves: Opportunistic with access to basic, commercially available tooling if not just a bat they can break glass with. They’re most likely looking to make a quick buck.

  2. Associated Threats: Not actual employees of an organization but still familiar presences, e.g. delivery drivers, cleaning crews, maintenance staff.

  3. Insider Threats: Current and former employees of the actual business with knowledge of day-to-day operations go and what the weaknesses may be.

  4. High-Capability Threats: The dark-side version of a physical pentester, with all the tooling and expertise to match. Probably the closest real-world analog to George Clooney.

  5. Nation-State Actors: Highly sophisticated and well equipped members of an adversarial government looking to cause damage to or steal information from critical systems and facilities (and probably don’t need to use physical means to accomplish this very often, if at all).

If we factor in the statistics presented by Gartner in 2024 (opens in new tab), insider threats account for around 75% of security breaches, even if just by accident. While exact numbers aren’t easy to find, for the sake of discussion, let’s imagine that the graph is fairly bell-shaped:

         │
         │                    75%
    % of │                    ┌──┐
breaches │                    │  │
  caused │                    │  │
         │                    │  │
         │  ?%       ?%       │  │     ?%       ?%
         │  ┌──┐     ┌──┐     │  │     ┌──┐     ┌──┐
         └──┴──┴─────┴──┴─────┴──┴─────┴──┴─────┴──┴─
           Petty   Assoc.   Insider  Hi-Cap   Nation

Within the bounds of their 2024 report (opens in new tab), leaving out situations in which credentials were compromised by phishing (A) or other means, insider error (B) was slightly more common than insider malice (C), but only just over half as financially damaging.

Physical security issues (D) sit on the low end of breach causes, just above 9%.

A scatter plot of breach causes plotted by share of all breaches (horizontal axis) against average cost in USD millions (vertical axis), highlighting phishing (A), insider error (B), malicious insider (C), and physical theft or security issue (D).

As has been the case for a long time, most insider threat-caused breaches (including phishing victims) are rarely due to someone acting maliciously. However, they are certainly the most expensive.

Now, because the raw data is not available from IBM and they admit in their report that their sampling methodology was selective:

Our study drew upon a representative, nonstatistical sample of global entities. Statistical inferences, margins of error and confidence intervals can’t be applied to this data, given that our sampling methods weren’t scientific.

So, we have no idea if they incorporate physical breaches into insider threats, or if all possible insider activity falls under “physical theft or security issue”. Without the data, this could mean anything from a stolen laptop with sensitive data on it (from a company location or even just a parked car) to a badge being cloned Mr. Robot-style.

In writing this, I haven’t been able to find a statistically sound source of data on how many breaches started with an insider threat specifically letting someone piggyback through a door (error) or stealing data from their job (malice). But, for the sake of coming to some kind of useful conclusion, we don’t need impact measurements to discuss who could possibly break into a building.

To actually answer the question about who on earth we are actually protecting against with recommendations from a physical pentest, likelihood and impact aside, we should look at each of the five threat profiles I listed above and understand how we can mesh them with parts of the process.

Once again, we are trying to answer the question of who is actually doing anything like this, not how much it hurts when they do. That is a separate question for people with access to good data.

Let’s establish phases of a physical intrusion and cross-reference them with said threat profiles:

  1. Reconnaissance: Learning, either from a distance or in person, what the physical security posture of a target building consists of, a.k.a. “casing the joint”.

  2. Initial Access: Gaining unauthorized entry to a facility intended to house and protect assets or information.

  3. Post-exploitation: Using the access gained to steal assets or establish persistence mechanisms for future use, e.g. malware on an unlocked workstation or a drop-device plugged into an ethernet port.

  4. Profiteering: Making money off of the whole thing by selling stolen assets/information or extorting the organization. This is when the ethical hackers are writing reports.

Petty Thieves

You’ve seen them on the news during periods of high tension and unrest, barging into electronics stores and stealing whatever they can easily sell on the secondhand market for easy money.

If they’re not taking advantage of localized chaos, they’re most likely just going to smash the glass door you put a badge reader next to. Their goal is to get in, get out, and get away, making as much money as they can with as little associated risk as possible.

Your job is to make sure that anything valuable is a pain to get to. Locked (and non-smashable) interior doors to things like storage rooms and closets go a long way to deter someone who didn’t drop 100 dollars on Covert Instruments (opens in new tab) and watch a bunch of YouTube videos on lock picking and door bypasses.

Associated Threats

These are regular people doing regular work in and around the physical area you’re concerned about, but aren’t explicitly employees.

Maybe they’re part of the maintenance team for the building you share with four other businesses. Maybe they’re the package service driver usually on the route you get deliveries from. Someone who is a familiar, frequent face but might have access that wouldn’t just be afforded to someone off the street.

While they most likely have too much going on to be concerned with exfiltrating confidential data, they inherit a default level of trust that can be abused by someone either in this category or someone wanting to look like someone in this category. Clip boards and toolboxes don’t cost very much at Home Depot.

Insider Threats

When discussing insider threats, it’s vital to understand that motive is vital to the story. This is where we borrow a razor from Hanlon (opens in new tab):

Never attribute to malice that which can be adequately explained by neglect, ignorance or incompetence.

  • modelthinkers.com

Ignorance of best practice does not place the insider under blame, though neglect and malice absolutely should.

Neglect may look as benign as an overly courteous door holder, not wanting to cause any interpersonal friction by closing a purposely access controlled door behind them, despite someone jogging up behind them, arms full of pizza boxes, making them scan their badge if they have one with some degree of frustration.

Similarly, ignorance might be allowing a guest to sign the visitors’ log book and simply stepping into a privileged office space without verifying who they are or who they are there to see. If no one communicated this policy outside of, say, the front desk receptionist, it is simply a case of not knowing best practice.

Finally, the rarer insider threat according to the IBM data from before, is one acting with malice. A disgruntled employee (or ex-employee) may leave a door unlocked, weakening the security perimeter and hoping someone takes advantage of the gap.

More directly, they may know where sensitive or valuable information is kept and can access it and sell it without anyone knowing.

High-Capability Threats

These are the people I’m not sure actually exist, and are the reason I’m writing this particular post.

How many people out there are high-capability threats and how many are high-capability threat consultants like myself? Statistically speaking, there’s a non-zero chance they exist, and maybe they’ve even been to the Louvre recently, but what is the likelihood that a business will have to deal with such a person, and how much should they spend on preparing to do so?

Nation-State Actors

While information on nation-state activity is difficult to find, I’m fortunate enough to know some people who could point me in the right direction without divulging information they’re sworn to protect.

According to the Federal Bureau of Investigation (FBI), economic espionage (opens in new tab) is notoriously difficult to prosecute. Without proof that the defendant was acting as a foreign agent or on behalf of a foreign government’s interests, the cases are usually prosecuted as trade secret thefts.

Notable examples of actual economic espionage cases include not just the theft of aerospace (opens in new tab) and missile (opens in new tab) technology secrets, but Akamai customer lists and security system designs (opens in new tab) as well as source code for trading software (opens in new tab) that made the financial firm Citadel quite a lot of money.

In the Coverage Lies the Point

Remembering the four stages of a physical intrusion from earlier in this post, it’s time for some cross-referencing. How can we correlate phases and components of a physical intrusion assessment to the five threat profiles?

Much like network security, it helps to start from the inside and work your way out. What do the people who already have access (associated/insider threats) pose, and how can those risks be mitigated?

Post-exploitation has the answers.

Moving outward, how could someone gain access if they do not have it already (petty thieves and high-capability threats)?

Initial access tests will find out.

But what does that actually mean? Some of the more eye-opening potential, I think, lies in the sort of finding each phase can produce. Here are some examples of findings I have put in reports for actual clients:

Recon

  • Security guards don’t follow a regular patrol schedule and often take breaks in their cars.

  • Employees all use the same six-digit code on the side door keypad.

  • People hold the door open for each other constantly.

Initial Access

  • Badges are easily cloned as they are worn in plain sight and can be easily read by a long-range badge reader in a shared space such as an elevator.

  • The front door has a thumb lock that someone can turn from the outside with a $20 j-tool (opens in new tab).

  • The back door is never locked because delivery drivers are coming and going 24/7.

Post-Exploitation

  • The CEO’s computer was left unlocked and could be infected with malware.

  • Employee social security numbers were left in the HR managers mailbox.

  • The wireless password was written on a conference room white board.

You may have noticed that I left out the final phase. Profiteering is not a canonical part of a physical penetration test because, well, that would just make the whole exercise just a crime. It is certainly part of a real physical intrusion.

However, once malware is on a laptop, all of the risk associated with the “Phishing” data point from IBM becomes yours, since there’s more than one way to infect a computer. Ransomware and other kinds of extortion hacking took the world by storm a mere 13 years ago beginning with CryptoLocker (opens in new tab).

Sounds like profiteering to me.

In Summary

Ultimately, the most I or anyone else can do to effectively convey the risks of a threat actor engaging in any kind of intrusion activity is to tie real-world consequences to everyday ignorance or negligence.

Until the impact has already been made, you might not see the value of a physical security assessment until it’s too late.

Also published on Substack.