Tommy

The Trace · Episode 35

Rfid Skimming

2,051 words

Tommy The Hamburger here, following the trace. One hair, one login, one smear, one weird little inconsistency, that's all it takes to bury a lie. Most motherfuckers look at the big mess. I look at the stubborn little detail that refuses to shut the fuck up. Listen close, because every fucking cover up sheds something, and every scrap of residue can rat that shit out. The fucking trace is the duplicate badge swipe. Not the ransomware note. Not the chest thumping memo about a sophisticated breach. Not the big scary noise from the ruined servers after the fact. The duplicate badge swipe. Two successful reads from the same access badge so close together they should not exist as ordinary use. I am in the bunker with the access control export on one screen, the door map on another, and a cold takeout box leaking grease into the evidence table. The company says someone got into the server room after hours and stole the data. Fine. Then explain why one employee badge seemed to split into twins for a second and a half, motherfucker. Badge systems are simple when you stop letting security vendors talk like priests. You tap the card. The door reader sees the badge number. The system checks whether that badge should be allowed through that door. Then it writes down what happened. Time. Door. Badge number. Granted or denied. That is it. If the same badge appears twice at the same high security door almost back to back, you do not need mystical math to know something is off. Either the system glitched or somebody copied the card. My job is to figure out which one survives contact with the rest of the evidence. This case starts at a midsize tech company that gets hit overnight. Server room accessed after closing. Customer records pulled. Destructive software dropped on the way out to make the whole thing look like an outside cyber smash. The internal panic team wants to focus on encryption keys and malware families and all the other sexy little phrases people use when they are praying the problem came from far away. I look at the physical access log first because whoever touched the servers still had to get their ass through a door. The door in question is the outer server room entry. Restricted access. Not the kind of place random staff drift through for fun. The log looks normal until late at night. Then the same badge number gets two successful grants almost on top of each other. Same door. Same badge identity. Two opens. Way too close. Then seconds later the real badge owner shows up and gets denied. That sequence is the trace. I start with the obvious honest question. Could the system just be dirty? Readers can double catch if someone fumbles a card, right? Sure, sometimes a sloppy user can produce weird door chatter. But the building vendor manual and prior logs show this reader's normal behavior. One granted read followed by door open state, then no second clean grant from the same badge that fast unless it is presented again under circumstances that do not match a normal single person pass. More important, the real owner's immediate denial afterward turns the weirdness into a story. The system did not simply hiccup. It reacted. The badge belongs to Sarah Chen, a network administrator with legitimate server room access. Sarah says she was called in late for an emergency and arrived to find her card suddenly rejected. Security chalked it up to a temporary problem at first. That is the kind of lazy assumption people make when they still think the disaster is on the network side only. But the log says the denial came right after two successful reads using Sarah's badge identity at the exact door she was trying to enter. That is not a random outage. That is a copied identity colliding with the real one, which is where the whole case finally starts to get useful. I pull Sarah's earlier badge activity from the same day. Normal building use. Garage entrance in the morning. Office floor. Break room. Admin corridor. Nothing strange. Then late at night, after she had already gone home, her badge identity magically returns at the server room before she physically gets there. That means the identity moved without the woman. Once you understand that, the rest of the case stops trying to be complicated. Somebody skimmed or copied her access badge and used that clone after hours. I still need to prove it cleanly, so I keep stacking the boring stuff. Security camera on the garage level catches Sarah arriving that morning. A van is parked too close to the pedestrian route to the employee entry reader. Later review finds a man lingering by the support pillar with a messenger bag held exactly where a cheap badge skimmer would sit. Nothing theatrical. Just enough proximity to harvest what he needed. No one noticed because office life is crowded with little inconveniences people train themselves to ignore. Then I compare door timing to Sarah's actual movements. Her phone location and parking records put her off site until the emergency call. She could not have made those first two late night granted reads herself. Meanwhile the attacker clearly knew exactly which door mattered and whose badge was worth copying. That tells me this was not some random opportunist trying every door in the building. It was targeted. The duplicate grant pattern also tells me something about the clone. Two fast successful reads with the same badge identity suggests the copied badge was being tested, then used again to hold the access window or make sure the reader took it cleanly. That is clumsy, but not uncommon. People doing physical cloning attacks are often good enough to get in and still stupid enough to leave a weird rhythm behind. They are thinking about the inside job, not the tiny ugly receipt at the threshold. Then Sarah arrives for real and the system refuses her. Why? Because the access control software saw impossible behavior around her badge identity and temporarily treated it as suspect. That matters because it means the denial was not just bad luck. It was a reaction to the earlier duplicate activity. The real card owner got punished by the same trace that exposed the fake one. Brutal little irony. At this point the company still wants to talk like this is all cyber wizardry. No. The breach has a physical front door. The copied badge is how it opened. I check who would know Sarah's access level, her routine, and the value of the server room. Former contractor Viktor Kozlov pops up fast. Had worked on database support. Knew where the good stuff lived. Left bitter after termination. Still knew the building layout. Still knew which staff kept privileged access. And sure enough, old parking lot footage and vendor records tie him to the van on the day Sarah's badge was likely copied. Now the cloned badge stops being a general theory and starts smelling like one specific asshole. But I do not like landing on motive too early, so I go back to the trace and keep it honest. The access log by itself proves a copied identity was used. It does not magically tell me who held the clone in their hand. So I add the other quiet systems. Exterior camera catches the van near the side employee lot. Later that night, side entry footage picks up a figure entering the building at the right time. Not enough for a clean face. Enough for build and clothing. Elevator logs show a trip to the data floor. Then the server room badge clone opens the outer door. Then the database activity starts. That is the route. The route is always where truth hardens. Inside the network logs, the attacker uses admin credentials that Sarah had access to but insists she did not touch. Fair. The copied badge got the body through the door. A planted password grabber from weeks earlier likely got the credentials. Physical and digital traces are kissing each other now, which is exactly what real intrusions do. They do not care about our tidy categories. A copied badge gets you near a machine. A stolen password gets you through the console. Then the bastard on the other side pretends it was all abstract remote magic. The company hated hearing that because it meant their beloved security layers were not stacked so much as leaning drunkenly against each other. And this is why the duplicate swipe matters more than the glamorous wreckage on the servers. The malware could have been purchased. The deletion script could have been downloaded. The ransomware note could have been pasted in by any thieving clown who knew how to shop in dark corners. But the duplicate badge read is specific. It shows how the attack physically started. It proves somebody carried Sarah's identity to a door she was not at, then bumped into the real Sarah moments later. Once we frame it that way, even the company's own guard statements get useful. One guard remembers being told Sarah was having card trouble when she arrived. Another remembers a contractor type from months back who used to complain about how easy it was to tailgate into the secure corridor if you timed the shift break right. That was Viktor. He had talked too much when he was still trusted, and later the duplicate swipe showed he had learned exactly enough to weaponize the place. I hate how often people think copied badges are some cinematic super hack. A lot of the time it is just laziness meeting cheap hardware. An employee carries the card openly. A skimmer gets close. The badge number gets copied. Then the clone walks where the original is supposed to walk. If nobody reads the access logs carefully, the lie lives. Here, the system wrote down the impossible echo and no one respected it until after the damage was done. That little echo is what cracked the whole job open. Fuck me sideways, the duplicate swipe made the whole job look like what it was, a cheap copied pass in the hands of a greedy motherfucker. That is where the safe little version goes to shit and the trace starts fucking up the timeline. Once the machine residue lines up, every polished explanation sounds like bullshit and every clean user story looks half fucked. That is why I trust the ugly log scrap more than the official script, because the trace does not give a shit who cleared the panel and it will fuck the cover route anyway. After that, the file is not complicated, it is just a shit wrapped performance with one fucked sequence still telling the truth. By the time law enforcement pulls the rest together, Viktor's apartment coughs up blank cards, a handheld badge reader, company floor maps, and a storage drive full of the stolen records. Great. But notice what got us there. Not a genius malware signature. Not a dramatic confession. A duplicate grant at one server room door and a real employee suddenly locked out by her own identity. Tiny trace. Huge wound. People always ask why I obsess over scraps like that. Because scraps do not have to impress anybody. They just have to stay stubborn long enough for the bigger lie to fall apart around them. The cloned badge left an impossible rhythm in the log, and that rhythm kept saying the same thing until everyone finally shut up and listened. The trace proved Sarah Chen's badge identity was copied and used at the server room door before Sarah herself arrived, producing duplicate successful grants that should not have happened in normal use and triggering the denial that hit her real card seconds later. That mattered because it showed the breach began with a cloned access badge and an inside route, not some faceless remote phantom, which turned the whole investigation back toward the fired contractor who knew the building, knew the target, and thought a copied badge would keep him invisible. That's the trace for today. Now you know what happened. Every residue tells a story if you're willing to follow it.