Phone: 0 (552) 380 25 25  |  Weekdays 10:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Access Control & Attendance

Access Card Cloning: How the Risk Arises, How to Spot a Cloned Card and How to Shut It Down

How access card cloning works, how a cloned card shows up in your door logs and which controls cut the risk. A six-step plan for card access systems.

9 min read  · Digital Bridge Engineering Team
Access Card Cloning: How the Risk Arises, How to Spot a Cloned Card and How to Shut It Down

Access card cloning is copying the identity data on an employee's badge to another card or device so a door accepts the copy as genuine. It works wherever the card ID is readable in the clear and the reader skips cryptographic verification. Defend with a modern card family, properly configured readers, a second factor on critical doors and log review.

Why nobody notices a cloned card

The unsettling thing about a cloned badge is how quiet it is. When the copy is presented, the system records that the genuine cardholder walked in. The guard sees nothing unusual and the access report shows an authorised entry.

Nobody has to steal the card, either. Badges sit on lanyards, in pockets and in bags, and they come within a few centimetres of strangers in lifts, on staff buses and in the canteen queue; with older cards, that brief moment can be enough. Sometimes no copy is needed at all: an employee who lends a card "just for a minute" produces the same result without any technical skill.

This article is not about which frequency to choose. It covers how cloning risk arises on your site, how to detect it and how to close it. For the frequency and card-family comparison, see our guide to 125 kHz vs 13.56 MHz cards.

How access cards actually get cloned

Understanding the attack paths is the quickest way to see what each control actually fixes. Four routes come up again and again in the field:

  • The ID number is broadcast in the clear. Many legacy proximity cards transmit a fixed number with no encryption. Once it has been read and written to a blank card, the reader cannot tell the two apart.
  • The reader only checks the serial number (UID). Even when a card carries encrypted memory, a reader configured to look only at the UID never uses that encryption. Cards and gadgets that emulate a UID exploit exactly this.
  • Broken legacy encryption. The cryptography of some older 13.56 MHz card families was broken years ago in published research. They may be marketed as "encrypted", but they offer little resistance to copying.
  • Lent cards and cards nobody revoked. Not technical, but the most common route of all. If a departed contractor's badge is still active, the outcome is identical to a clone.

In a penetration test that covers physical security, card cloning is among the first techniques testers reach for, so the risk is far from theoretical.

The cost of living with clonable cards

Legacy card technologies that are easy to copy are still common. A survey of more than 1,200 respondents by HID Global found that one in three companies still support 125 kHz low-frequency proximity cards, and nearly 30% still run systems that use magnetic stripe cards (HID 2024 State of Physical Access Control Report, via CampusIDNews).

An access card is the physical counterpart of a password: it is the only thing proving who is at the door. On the digital side we know how effective a stolen credential is:

Verizon's 2026 Data Breach Investigations Report found that the use of stolen credentials held steady as an action in 36% of breaches. (Verizon 2026 Data Breach Investigations Report)

A server room or records store entered with a cloned card can turn a physical incident into a data breach. According to the IBM Cost of a Data Breach Report 2026, the global average cost of a breach has reached $4.99 million. In Türkiye, where the KVKK (the national data protection law, similar in spirit to GDPR) requires data controllers to report personal data breaches, the Authority's 2025 Annual Report records 328 breach notifications in 2025. An incident that starts at a door can fall within that duty; our guide to the 72-hour breach notification explains the process.

How a cloned card shows up in access logs

A cloned card goes unnoticed at the door, but it usually leaves traces in the event log. The table below lists the signals worth reviewing regularly and what each one suggests:

SignalLikely meaningWhat to do
Same card at two distant doors within minutesTwo physical cards exist (a clone)Suspend the card and speak to the holder
Second entry with no exit recordedCard passed back or copiedConsider an anti-passback rule
Out-of-hours entry to an unusual zoneExcess rights or misuseMatch the event against CCTV
Entry on the card of someone on leave or sickCard is in someone else's handsCompare with attendance records
Repeated reads of a revoked cardOld or cloned card being triedReview that reader's location and times
Successful entry on a leaver's cardRevocation process is not workingFix the HR-to-access-control link

Some of these signals can be enforced as rules. The logic that blocks a second entry without an exit is covered in anti-passback explained. Bringing door events together with server, email and network logs is the job of SIEM and log management; seeing physical and digital events on one timeline answers "clone or data glitch?" quickly.

The strongest way to confirm a suspicious event is video. Pairing critical-door cameras with access events is easier with central IP camera management, and the footage itself must be retained in line with the rules in CCTV recording and KVKK.

Six steps to reduce access card cloning risk

  1. Inventory cards and readers. Which reader sits on which door, which card family does it read, and how does it verify the card? More often than not the weakness is a reader configured to read the UID only, not the card itself.
  2. Classify zones by risk. A car park barrier and a server room do not need the same protection. Our article on zone-based access in factories is a good starting point.
  3. Never let the card stand alone on critical doors. Card plus PIN or card plus biometrics makes a cloned card useless by itself. The trade-offs are set out in fingerprint vs card vs face recognition.
  4. Upgrade the card family together with key management. Modern encrypted cards only protect you when readers are set to perform cryptographic authentication. Who holds the keys, and how they are loaded at card issue, should be written down from day one.
  5. Close the card lifecycle. Joiners, role changes, leavers and lost-card reports should reach the access system on the same day. The email equivalent of this problem is covered in offboarding email access.
  6. Review logs and test regularly. Turn the table above into a weekly checklist, and commission a test that includes physical security at least once a year.

If your current system cannot support most of these steps, our guide to replacing legacy access control shows how to change cards and readers without downtime. For the fundamentals, start with our card access control guide.

How Digital Bridge approaches card security

Because hardware and software are built by the same team, we treat card security as one job running from the door to the database:

  • Discovery and risk map. We survey your readers, card types and zones on site, and report which doors are open to cloning and how each reader verifies cards. The technical feasibility study for hardware is free of charge.
  • Pilot. We first trial the new card and reader set-up on a handful of critical doors, such as the server room, warehouse or archive, with real users. Under our card access control service we install readers, controllers, locks and turnstiles, and add fingerprint access where a second factor is needed.
  • Security and compliance. Key management, log-monitoring rules and the scope of physical testing sit within our cyber security consultancy; retention of card data and access records is handled under data protection compliance.
  • Integration. We build system integrations so that a leaver recorded in HR reaches the access system the same day, instead of relying on someone remembering an email.

Narrowing cloning risk with SmartPass

Our own SmartPass uses 13.56 MHz RFID cards for staff and single-use, time-limited QR codes for visitors; both are read by the same terminal and governed by the same access rules. Because visitors never receive a card, there is no "visitor badge that never came back"; the QR code simply expires.

With SmartPass, card security continues in the database. Card numbers are never stored in plain text but as an irreversible hash, so even someone with database access cannot extract a list of card numbers to clone. Every permission change is written to an audit trail with old and new values, and the auditor role is read-only.

A concrete scenario: at midnight, the security lead sees an entry to the warehouse zone on the card of an employee who is on leave. The live monitoring screen shows who is inside each zone right now, and the event can be checked against camera footage. If the situation escalates, every door can be locked in a single action. Rules are written in plain language, such as "The warehouse team may enter the Warehouse zone during working hours", and the rule simulator shows whether a new rule conflicts with an existing one before it goes live.

To be clear, these database-side safeguards do not on their own stop a card at the door from being copied. The card family, reader configuration and second factor on critical doors are addressed separately during the discovery and pilot stages described above.

Next step

If you do not know whether the cards on your doors can be cloned, the first job is to find out. Send us the card and reader model and we will map the risk on your critical doors and outline a phased improvement plan. To arrange a site visit or request a proposal, use our contact page.

For more guides in this area, visit our Access Control & Attendance hub.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

Can my access card be cloned, and how can I tell?

You have to assess the card and the reader together. If the card is a legacy proximity card that broadcasts its ID unencrypted, or the reader only checks the serial number, the cloning risk is high. The manufacturer marking on the card and the reader model are usually enough for a first assessment; a definitive answer needs a review of the reader configuration and a controlled test.

Is cloning an access card illegal?

Copying someone else's access card without permission and using it to enter a restricted area can have serious criminal and employment consequences in most jurisdictions, including Türkiye. An organisation testing its own system should do so under written authorisation with a clearly defined scope. For a legal view, consult your lawyer; this article is not legal advice.

Do 13.56 MHz cards stop cloning completely?

No. The encryption of some older 13.56 MHz card families has been broken, and many installations configure readers to check only the card's serial number. In those cases a 13.56 MHz card is as easy to imitate as a legacy proximity card. You need a current encrypted card family, readers set up for cryptographic authentication and a second factor on critical doors.

What should we do if we suspect a cloned card?

First suspend the card in the system and issue the holder a new one. Then match recent events on that card against camera footage and establish which zones were entered. If a zone holding personal data was accessed without authorisation, assess the event under your breach-response procedure. Finally, review every other door that uses the same reader type.

How do we stop staff lending their cards to others?

There is no purely technical fix; policy, training and records work together. Make it clear in writing at onboarding that the card is personal, and require a PIN or biometric alongside the card on critical doors. Comparing access events with attendance and camera records on a regular basis makes lent cards visible and discourages the habit.

How does SmartPass store card numbers?

SmartPass never stores card numbers in plain text; it keeps an irreversible hash instead. Anyone who gains access to the database therefore cannot extract a list of card numbers. Records past their retention period are anonymised, permission changes are logged with old and new values, and the auditor role works with read-only access.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.