Friday, May 9, 2025
HomeCyber Security NewsPenetration Testers Arrested During Approved Physical Penetration Testing

Penetration Testers Arrested During Approved Physical Penetration Testing

Published on

SIEM as a Service

Follow Us on Google News

A routine physical penetration test conducted by cybersecurity professionals took an unexpected turn when armed police officers arrested two security experts during a simulated breach of a corporate office in Malta.

Physical penetration testing is a critical component of cybersecurity assessments. It evaluates not only technical defenses but also physical access controls and human response mechanisms.

While this test revealed significant vulnerabilities in the client’s security setup, it also underscored the importance of preparing for real-world scenarios where miscommunication can have serious consequences.

- Advertisement - Google News

Penetration testers Curt Hems and his colleague from Threat Spike Labs, part of a “black team” engagement, had been hired to evaluate the physical and operational security of a client’s premises.

Their mission included bypassing security controls, accessing sensitive areas, and identifying vulnerabilities in the organization’s defenses. Over the course of two hours, the team successfully:

  • Gained unauthorized access to the main office.
  • Stole a key card granting access to all rooms.
  • Retrieved sensitive information, including passwords.
  • Simulated account takeovers on multiple websites.

“Physical penetration tests don’t always go as planned sometimes they end with flashing lights and handcuffs.” Curt Hems explained in his LinkedIn post.

Despite their success in exposing critical security gaps, the engagement ended abruptly when 11 armed police officers intervened. The testers were detained despite having authorization documents signed by the client’s general manager.

“The findings were critical major gaps in physical security, access control, and operational security. Yet, despite our success, we were ultimately apprehended. Not by security. Not by IT. But by 11 armed police officers.”

Miscommunication Leads to Escalation

The situation escalated due to apparent miscommunication between the client’s management and local authorities.

The general manager, who had approved the test, reportedly panicked when informed of the breach.

Law enforcement was called under the assumption that a real attack was underway. The testers repeatedly explained their role and presented their authorization letter, but it took time for the situation to be resolved.

This incident highlights several important lessons for organizations conducting penetration tests:

  1. Improved Coordination: Clear communication between all stakeholders including management, security teams, and law enforcement, is essential to avoid misunderstandings during penetration tests.
  2. Authorization Protocols: Organizations should ensure that all relevant parties are informed about scheduled tests and provided with the necessary documentation.
  3. Incident Response Evaluation: The event served as a stress test for the client’s incident response procedures, revealing gaps in escalation protocols and coordination with authorities.

The testers emphasized that such engagements are designed to simulate real threats and improve organizational resilience. “In a real attack, stakes are much higher,” one of them noted.

The incident serves as a reminder for companies to ensure robust processes are in place to detect intrusions and handle escalations effectively.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates

Kaaviya
Kaaviya
Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Latest articles

Chinese Hackers Exploit SAP RCE Vulnerability to Deploy Supershell Backdoors

A critical remote code execution (RCE) vulnerability, identified as CVE-2025-31324, in SAP NetWeaver Visual...

Hackers Target IT Admins by Poisoning SEO to Push Malware to Top Search Results

Cybercriminals are increasingly targeting IT administrators through sophisticated Search Engine Optimization (SEO) poisoning techniques. By...

New Mamona Ransomware Targets Windows Systems Using Abused Ping Command

Cybersecurity researchers are raising the alarm about a newly discovered commodity ransomware strain dubbed Mamona,...

Malicious Python Package Impersonates Discord Developers to Deploy Remote Commands

A seemingly innocuous Python package named ‘discordpydebug’ surfaced on the Python Package Index (PyPI)...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Chinese Hackers Exploit SAP RCE Vulnerability to Deploy Supershell Backdoors

A critical remote code execution (RCE) vulnerability, identified as CVE-2025-31324, in SAP NetWeaver Visual...

Hackers Target IT Admins by Poisoning SEO to Push Malware to Top Search Results

Cybercriminals are increasingly targeting IT administrators through sophisticated Search Engine Optimization (SEO) poisoning techniques. By...

New Mamona Ransomware Targets Windows Systems Using Abused Ping Command

Cybersecurity researchers are raising the alarm about a newly discovered commodity ransomware strain dubbed Mamona,...