How a security analyst sent his mother to a state correctional facility with fake credentials to plant malicious USB drives, resulting in the director using one
Security analyst John Strand had a contract to test a correctional facility's defenses. He sent the best person for the job: his mother. Tweets: @condenast and @kimzetter Tweets: Cond Nast / @condenast : Some sons send their moms flowers, and some help fulfill their wish to break into a highly secured facility. All it took was a fake badge and the right chitchat—@WIRED has the story: https://www.wired.com/... Kim Zetter / @kimzetter : Dear election officials: “John equipped Rita with so-called Rubber Duckies, malicious USB sticks that she would plug into every device she could. The thumb drives would beacon back to her Black Hills colleagues and give them access to the prison's systems” https://www.wired.com/...
Context & Ripple Effects
This feature sits in a long-running thread about how easily humans defeat technical perimeters. A [[a:923412|professional penetration tester had already described walking into high-security facilities on charm alone]] two years earlier, and prisons have their own insider problem: an inmate once hid computers in the ceiling to reach the prison's internal network. What John Strand's test adds is the family twist — his mother Rita, armed with a fake badge and Rubber Ducky USB drives, got past a state correctional facility's gatekeeping where badges and cameras were supposed to be enough.
The payoff is the detail every security team dreads: the facility's own director plugged one of the planted drives in, handing simulated attackers a path into prison systems. It belongs to the same lineage as Jon DiMaggio later using fake personas to infiltrate LockBit — deception aimed at people, not code, remains the cheapest way through hardened targets.
First-order effects
- The correctional facility learned its access controls fail at the front desk: a visitor with a fabricated credential reached staff machines, and the director himself executed the malicious payload.
- Strand's client now has concrete evidence that its security budget was defending against the wrong threat model — network hardening did nothing against a hand-delivered USB drive.
Second-order effects
- Other correctional systems and high-security facilities face pressure to add social-engineering and physical-red-team tests to their audits, since this case shows compliance-grade perimeter security can be bypassed by one persuasive visitor.
- Vendors of locked-down endpoints and USB port control gain a sales argument: every facility that reads this story has a director who plugged in an unknown drive.
Third-order effects
- If the pattern holds, security assurance for sensitive institutions shifts toward routinely contracting deception operations — fake badges, planted devices, persona-based intrusion — making human-layer testing a standard line item rather than an occasional stunt.
- It also sharpens the insider-versus-outsider ambiguity regulators will have to grapple with: the most effective 'attacker' here was an authorized contractor's mother operating under a legitimate engagement.
The trend: Across prisons, ransomware groups, and state-linked intrusions, the reliable attack surface is the trusted human, and security testing is professionalizing around exactly that weakness.