Access card cloning is copying the identity data on an employee's badge to another card or device so a door accepts the copy as genuine. It works wherever the card ID is readable in the clear and the reader skips cryptographic verification. Defend with a modern card family, properly configured readers, a second factor on critical doors and log review.
Why nobody notices a cloned card
The unsettling thing about a cloned badge is how quiet it is. When the copy is presented, the system records that the genuine cardholder walked in. The guard sees nothing unusual and the access report shows an authorised entry.
Nobody has to steal the card, either. Badges sit on lanyards, in pockets and in bags, and they come within a few centimetres of strangers in lifts, on staff buses and in the canteen queue; with older cards, that brief moment can be enough. Sometimes no copy is needed at all: an employee who lends a card "just for a minute" produces the same result without any technical skill.
This article is not about which frequency to choose. It covers how cloning risk arises on your site, how to detect it and how to close it. For the frequency and card-family comparison, see our guide to 125 kHz vs 13.56 MHz cards.
How access cards actually get cloned
Understanding the attack paths is the quickest way to see what each control actually fixes. Four routes come up again and again in the field:
- The ID number is broadcast in the clear. Many legacy proximity cards transmit a fixed number with no encryption. Once it has been read and written to a blank card, the reader cannot tell the two apart.
- The reader only checks the serial number (UID). Even when a card carries encrypted memory, a reader configured to look only at the UID never uses that encryption. Cards and gadgets that emulate a UID exploit exactly this.
- Broken legacy encryption. The cryptography of some older 13.56 MHz card families was broken years ago in published research. They may be marketed as "encrypted", but they offer little resistance to copying.
- Lent cards and cards nobody revoked. Not technical, but the most common route of all. If a departed contractor's badge is still active, the outcome is identical to a clone.
In a penetration test that covers physical security, card cloning is among the first techniques testers reach for, so the risk is far from theoretical.
The cost of living with clonable cards
Legacy card technologies that are easy to copy are still common. A survey of more than 1,200 respondents by HID Global found that one in three companies still support 125 kHz low-frequency proximity cards, and nearly 30% still run systems that use magnetic stripe cards (HID 2024 State of Physical Access Control Report, via CampusIDNews).
An access card is the physical counterpart of a password: it is the only thing proving who is at the door. On the digital side we know how effective a stolen credential is:
Verizon's 2026 Data Breach Investigations Report found that the use of stolen credentials held steady as an action in 36% of breaches. (Verizon 2026 Data Breach Investigations Report)
A server room or records store entered with a cloned card can turn a physical incident into a data breach. According to the IBM Cost of a Data Breach Report 2026, the global average cost of a breach has reached $4.99 million. In Türkiye, where the KVKK (the national data protection law, similar in spirit to GDPR) requires data controllers to report personal data breaches, the Authority's 2025 Annual Report records 328 breach notifications in 2025. An incident that starts at a door can fall within that duty; our guide to the 72-hour breach notification explains the process.
How a cloned card shows up in access logs
A cloned card goes unnoticed at the door, but it usually leaves traces in the event log. The table below lists the signals worth reviewing regularly and what each one suggests:
| Signal | Likely meaning | What to do |
|---|---|---|
| Same card at two distant doors within minutes | Two physical cards exist (a clone) | Suspend the card and speak to the holder |
| Second entry with no exit recorded | Card passed back or copied | Consider an anti-passback rule |
| Out-of-hours entry to an unusual zone | Excess rights or misuse | Match the event against CCTV |
| Entry on the card of someone on leave or sick | Card is in someone else's hands | Compare with attendance records |
| Repeated reads of a revoked card | Old or cloned card being tried | Review that reader's location and times |
| Successful entry on a leaver's card | Revocation process is not working | Fix the HR-to-access-control link |
Some of these signals can be enforced as rules. The logic that blocks a second entry without an exit is covered in anti-passback explained. Bringing door events together with server, email and network logs is the job of SIEM and log management; seeing physical and digital events on one timeline answers "clone or data glitch?" quickly.
The strongest way to confirm a suspicious event is video. Pairing critical-door cameras with access events is easier with central IP camera management, and the footage itself must be retained in line with the rules in CCTV recording and KVKK.
Six steps to reduce access card cloning risk
- Inventory cards and readers. Which reader sits on which door, which card family does it read, and how does it verify the card? More often than not the weakness is a reader configured to read the UID only, not the card itself.
- Classify zones by risk. A car park barrier and a server room do not need the same protection. Our article on zone-based access in factories is a good starting point.
- Never let the card stand alone on critical doors. Card plus PIN or card plus biometrics makes a cloned card useless by itself. The trade-offs are set out in fingerprint vs card vs face recognition.
- Upgrade the card family together with key management. Modern encrypted cards only protect you when readers are set to perform cryptographic authentication. Who holds the keys, and how they are loaded at card issue, should be written down from day one.
- Close the card lifecycle. Joiners, role changes, leavers and lost-card reports should reach the access system on the same day. The email equivalent of this problem is covered in offboarding email access.
- Review logs and test regularly. Turn the table above into a weekly checklist, and commission a test that includes physical security at least once a year.
If your current system cannot support most of these steps, our guide to replacing legacy access control shows how to change cards and readers without downtime. For the fundamentals, start with our card access control guide.
How Digital Bridge approaches card security
Because hardware and software are built by the same team, we treat card security as one job running from the door to the database:
- Discovery and risk map. We survey your readers, card types and zones on site, and report which doors are open to cloning and how each reader verifies cards. The technical feasibility study for hardware is free of charge.
- Pilot. We first trial the new card and reader set-up on a handful of critical doors, such as the server room, warehouse or archive, with real users. Under our card access control service we install readers, controllers, locks and turnstiles, and add fingerprint access where a second factor is needed.
- Security and compliance. Key management, log-monitoring rules and the scope of physical testing sit within our cyber security consultancy; retention of card data and access records is handled under data protection compliance.
- Integration. We build system integrations so that a leaver recorded in HR reaches the access system the same day, instead of relying on someone remembering an email.
Narrowing cloning risk with SmartPass
Our own SmartPass uses 13.56 MHz RFID cards for staff and single-use, time-limited QR codes for visitors; both are read by the same terminal and governed by the same access rules. Because visitors never receive a card, there is no "visitor badge that never came back"; the QR code simply expires.
With SmartPass, card security continues in the database. Card numbers are never stored in plain text but as an irreversible hash, so even someone with database access cannot extract a list of card numbers to clone. Every permission change is written to an audit trail with old and new values, and the auditor role is read-only.
A concrete scenario: at midnight, the security lead sees an entry to the warehouse zone on the card of an employee who is on leave. The live monitoring screen shows who is inside each zone right now, and the event can be checked against camera footage. If the situation escalates, every door can be locked in a single action. Rules are written in plain language, such as "The warehouse team may enter the Warehouse zone during working hours", and the rule simulator shows whether a new rule conflicts with an existing one before it goes live.
To be clear, these database-side safeguards do not on their own stop a card at the door from being copied. The card family, reader configuration and second factor on critical doors are addressed separately during the discovery and pilot stages described above.
Next step
If you do not know whether the cards on your doors can be cloned, the first job is to find out. Send us the card and reader model and we will map the risk on your critical doors and outline a phased improvement plan. To arrange a site visit or request a proposal, use our contact page.
For more guides in this area, visit our Access Control & Attendance hub.