Your building has card readers, cameras, a visitor log and a security desk. Jenny Radcliffe will be inside it by lunchtime, and nobody will have done anything wrong.
She is a social engineer — hired by organizations to breach their own premises so that the gaps are found by someone friendly. She calls herself a burglar for hire. What she actually does is demonstrate, repeatedly and expensively, that the most sophisticated physical security in the world is administered by people who would rather be helpful than difficult.
People Hacker is her account of thirty years of doing this. For anyone responsible for a site, a building or a workforce, it is uncomfortable in exactly the right way.
What the book actually covers
Radcliffe's method is almost entirely non-technical. She does not defeat the lock; she persuades someone to hold the door. She has talked her way into banks, data centers, corporate headquarters — using pretext, confidence, appropriate clothing and an unshakeable air of belonging.
The mechanics she describes are the ones that matter operationally. Reconnaissance first: what an organization publishes about itself, who its suppliers are, what its lanyards look like, when its shifts change. Then the pretext — a role plausible enough that challenging it feels rude. Then the exploitation of the two most reliable human tendencies in any workplace: the reluctance to challenge someone who appears senior, and the instinct to help a person who seems to be struggling.
Her most useful observation is that forced entry is the amateur's route. Talking your way in is safer, quieter, leaves less evidence and works more often. That reframing should worry anyone whose security posture is built around barriers rather than behavior.
She is candid about the near-misses, and about the toll of a working life spent deceiving decent people for their own good. The book is funny, which makes the underlying finding land harder.

Why it matters for your risk posture
Read it because the human layer is the one almost nobody tests. Organizations commission penetration tests of their networks as a matter of routine and almost never commission the physical and social equivalent. Radcliffe's career exists because that gap is universal.
Read it for the reconnaissance material. Most of her work is done before she arrives, using information the target published voluntarily — organizational charts, supplier relationships, photographs with lanyards visible, social media posts revealing schedules. That is precisely the exposure a proper open-source assessment identifies, and this book demonstrates what an adversary does with it.
And read it for the training implication. Radcliffe is emphatic that awareness training fails when it tells staff to be suspicious, because being suspicious conflicts with being good at a customer-facing job. What works is giving people a specific, socially acceptable script for verification — a way to check that does not require them to be rude. That distinction is the difference between a policy that is followed and one that is quietly ignored.
Key takeaways
- The barrier is not the control; the person operating it is. Access systems are administered by staff whose instinct is to be helpful, and that instinct is the actual attack surface.
- Reconnaissance is done from your own published material. Org charts, supplier names, visible lanyards and posted schedules are the raw material of a successful pretext.
- Talking in beats breaking in. It is safer, quieter and more reliable — which is why the sophisticated adversary never touches the lock.
- Train the script, not the suspicion. Staff need a polite, specific way to verify. Telling them to be wary conflicts with their job and loses.
About the author
Jenny Radcliffe is a social engineer and founder of Human Factor Security, working in physical infiltration and the psychology of scams, cons and fraud. Her firm has been engaged by organizations to test their premises and their people, and to build the awareness programs that follow.
She was inducted into Infosecurity Europe's Hall of Fame in 2022 in recognition of her work on the human-centered side of information security, and is a multiple TEDx contributor.
People Hacker: Confessions of a Burglar for Hire was published by Simon & Schuster in 2023.
Beyond the Book
Jenny Radcliffe — social engineer; founder, Human Factor Security
- Listen, free: her podcast Human Factor Security ran from 2016 to 2023, interviewing practitioners from across the field. The archive of roughly 100 episodes remains freely available, and it is still the best free resource on this subject.
- She speaks widely: she has keynoted security conferences and corporate events internationally, with talks aimed specifically at waking up a workforce to social-engineering risk.
- The same test can be commissioned. Human Factor Security has offered physical infiltration assessments and awareness programs of this kind. For an organization that has never tested its human layer, commissioning one is the actionable step this book points to.
- Read alongside: The Official CIA Manual of Trickery and Deception for the attention-management mechanics underneath her method, and The Gift of Fear by Gavin de Becker for the signals that indicate manipulation in progress.

Where the proceeds go
We donate 100% of what we earn to Children of Fallen Heroes
If you buy through the link above we may earn a small commission, at no extra cost to you. Every penny of it goes to Children of Fallen Heroes, a registered 501(c)(3). We keep none of it.
They run an 82-acre campus for the children of military families, first responders and foster youth — STEAM education in aviation, robotics and drones, alongside leadership and healing programs. More than 15,000 young people and families have been through it in eleven years.
We participate in the Amazon Services LLC Associates Program and similar affiliate programs; these relationships do not influence our recommendations. Cookies and similar technologies record interactions with affiliate links — see our Privacy Policy to disable them, or reach us via Contact.
