Key fobs are a popular choice for many businesses to control who can enter their buildings. As with all types of access control, nothing is foolproof, and it’s possible for someone to clone a key fob.
Cloning a key fob is surprisingly easy, and all building administrators and owners should be aware of this potential security risk. The ability to duplicate key fob credentials using low-cost RFID devices means your building’s safety could be compromised without a single visible sign of tampering.
Here, we’ll cover key fob cloning, why and how they can be copied, and what you can do to make your building more secure.
Key Takeaways
- Most legacy key fobs (125kHz) can be cloned in under 10 seconds using devices available online for less than $30 — with no technical skills required.
- When a fob is cloned, the access log can’t tell the difference between the original and the copy — meaning a breach can go undetected for weeks or months.
- Not all fobs are equally vulnerable. Modern key fobs using 13.56MHz DESFire EV3 encrypted technology are effectively impossible to clone with consumer tools.
- The biggest risk isn’t strangers — it’s insiders. Employees and tenants can clone their own fob before returning it, leaving you with no indication that a key fob copy exists.
Have a security project?
What Are Key Fobs?

Key fobs are small devices used to control access to open doors or access points. Users must place them in front of a door reader to access a building or a restricted area. They’re small and convenient; many people hang their key fobs on keychains or carry them in their wallets.
A key fob uses radio frequency identification (RFID) technology. When the user presents their fob to an RFID reader, the code stored on the RFID chip is read, and if it’s an approved code in the database, the door will unlock or open.
They are commonly used in access control and are often preferred by users because they’re simple and convenient — making entry to office buildings, schools, and government facilities fast and secure.
Can You Clone a Key Fob?
Yes, key fobs can be cloned. However, while convenient, key fobs do pose a security risk. Just as someone can make a copy of a traditional key, they can make a key fob copy.
In that sense, systems that use key fobs for access control are as secure as those that use a traditional key. They’re more convenient for building administrators and users because they’re simple to use and program.
Administrators can revoke access without physically confiscating a key, and users don’t need to fumble with a lock when entering the building. Building management teams appreciate the ability to instantly revoke credentials and track who entered and when.
That said, not all key fobs carry the same risk. Whether your fobs are vulnerable depends on the technology they run on — and most businesses have no idea which type they’re running.
Have a security project?
Two Ways To Clone an Original Key Fob
1. Using a Kiosk or Online Service
One straightforward way to clone a key fob is to take the existing fob to a kiosk or use an online key fob copy service. Many companies offer this cloning service for around $20–$30, and the process is fast and easy to initiate.
The process involves sending the original fob’s data to the provider, who then creates a duplicate key fob and sends it back to the user. These services store the credential data, write it onto a new fob, and ship the key fob duplicate back — often within days. This method is convenient and requires minimal effort from the user.
2. Using an RFID Copier
Another method is to use an RFID copier—a small, handheld device that reads and clones RFID key fobs and access cards. A basic handheld RFID writer — available online for under $30 — can read and clone a 125kHz fob in roughly 10 seconds. More sophisticated tools like the Flipper Zero ($169) can copy a fob in under a second, even through a wallet or pocket, without the fob owner knowing. Here’s how the basic process works:
- Reading the RFID Key Fobs: Hold the existing fob to the RFID copier and press the “read” button. The device will capture the fob’s signal, usually indicated by a beep.
- Writing to a New Fob: Hold a blank fob up to the copier and press the “write” button after capturing the signal. The device transfers the captured data to the new fob, creating an exact duplicate.
It’s worth noting that this process only works on legacy 125kHz fobs, which broadcast their credential data openly with no encryption. Modern encrypted fobs (13.56MHz with AES-128 or DESFire EV3) do not transmit in a way that consumer cloning devices can capture or replicate.
Additional Cloning Options
Beyond creating new key fobs, some services and devices also allow cloning onto phone stickers that function as key fob copies. These can be placed in a wallet or on a phone for added convenience.

How Key Fob Cloning Impacts Businesses
While the idea of key fob cloning may seem like a fringe issue, it’s actually more common than you’d think. Here are a few real-world situations where cloning had a direct impact on business security:
Unauthorized Employee Access After Termination
An employee at a logistics warehouse was let go, but had previously used a key fob copy service before returning their original key fob. They were able to re-enter the premises after hours and steal valuable inventory before the company realized what happened. The original fob had been deactivated — but the cloned copy remained active because it wasn’t on the admin’s radar.
Lesson: Always treat lost or unreturned fobs as a potential cloning threat, and deactivate the access code system-wide when revoking privileges. Cloud-managed access control systems like Brivo allow instant remote revocation and flag unusual access patterns — a critical advantage over standalone reader systems.
Apartment Complex Security Breach
A tenant cloned their building’s access fob and sold duplicate key fobs to non-residents for a fee. Over time, dozens of unauthorized individuals gained access to the building’s common areas and parking garage, resulting in multiple thefts and disturbances.
Lesson: For high-traffic facilities such as multi-unit housing, it’s essential to use encrypted fobs and regularly audit entry logs.
Retail Store Internal Theft
A former part-time retail employee cloned their fob and used it to access the store stockroom after hours for weeks before being caught on camera. Despite the store’s efforts to change PINs and reissue some credentials, they overlooked key fob security.
Lesson: Even low-profile roles should be managed through secure, trackable credentials — and key fob management should be part of offboarding protocols.
Why Is Key Fob Cloning a Security Risk for Your Business?

Key fobs can be cloned by criminals and well-intentioned people who want an extra key fob as a backup.
For example, someone might want to store an extra fob in their car in case they forget their original key fob. Criminals can also make copies if they get their hands on a fob, or intercept the RFID signal in a relay attack — where a device captures and re-transmits the fob’s signal to a door reader without the credential holder knowing.
The deeper problem is what security professionals call the “invisible breach.” When a cloned fob is used on a legacy 125kHz system, the access log records the same credential code as the original key fob. There’s no flag, no alert, no way to know the entry was made from a duplicate rather than the authorized fob. By the time the breach is discovered — if it’s discovered — weeks or months of unauthorized access may have occurred.
How vulnerable is your system? It comes down to technology. Legacy 125kHz fobs store credential data on an RFID chip with no encryption — they broadcast their signal to any nearby reader, authorized or not. Modern 13.56 MHz fobs use encrypted protocols (e.g., MIFARE DESFire EV3 with AES-128) that require cryptographic authentication before any data is exchanged. A $30 handheld copier can clone a 125kHz fob in about 5 seconds. That same device cannot touch a properly encrypted 13.56MHz credential. Unfortunately, 125kHz systems remain common in older commercial buildings because they look identical to modern key fobs from the outside — most building management teams have no idea which type they’re running.
If you’re concerned that people are copying key fobs, you can deactivate the original codes. Because they share the same credential code, a key fob copy won’t work once that code has been cancelled. Make sure your users know the importance of reporting lost or stolen fobs so the code can be swiftly deactivated. Also document every fob issued and whether it was returned during offboarding — a returned fob may have already been programmed as a duplicate before it came back.
FAQs
Is key fob cloning legal?
You can clone a key fob or copy key cards for your own use as a backup or for convenience, as long as it’s legal. The legality of cloning depends on the purpose for which it is done.
However, cloning someone else’s key fob without their permission is illegal and could be considered a form of theft or breach of security in any industry. Property managers should also be aware that if cloned fobs result in unauthorized access or harm to residents, there may be liability exposure — consult legal counsel if you suspect a breach has occurred.
Using advanced technology in your access control system can help ensure your credentials remain reliable and reduce the likelihood that devices will stop working due to outdated encryption.
How can I protect my key fob from being cloned?
The most effective protection is upgrading to an enhanced security credential system. Modern key fobs with DESFire EV3 encryption are effectively immune to the cloning devices available to the general public — this is a technology-level protection, not just a policy measure.
For legacy systems you haven’t yet upgraded, some interim measures help: store fobs in RFID-blocking sleeves when not in use, never leave them unattended in public areas, and ask your integrator whether “press-to-activate” fobs (which only broadcast when a button is pressed) are compatible with your current RFID reader setup.
Regularly auditing access logs for unusual patterns and maintaining a strict offboarding protocol — verifying fob return and cancelling credentials immediately at separation — will reduce your exposure until an upgrade is complete. Choosing encrypted credentials that work perfectly with your existing hardware can make day-to-day operations more hassle free and ultimately make your life easier while maintaining security.
Is Key Fob Cloning the Same Risk for Cars and Buildings?
No — and this distinction matters. Most news coverage about key fob cloning focuses on car and vehicle theft: relay attacks that amplify a car key’s signal from inside a home, or OBD port devices that program a blank fob to start a car. These are real threats, but they operate differently from the access-control risks faced by commercial buildings and facilities.
For commercial buildings, the primary cloning risk is someone using a low-cost RFID copier to duplicate an access card or key fob credential — then using that key fob copy to enter restricted areas long after their authorization has been revoked.
The concern isn’t a relay attack from a distance; it’s a static RFID code being copied and reused indefinitely. Car key fobs typically use rolling codes that change with every use, making simple replay attacks ineffective on vehicles. Many commercial building fobs — especially legacy 125kHz systems — do not use rolling codes, which is why they remain far more vulnerable to direct duplication than modern car door entry systems.
If you manage a commercial property, government facility, school, or multi-tenant building, the threat model differs from that for car theft. The solution is also different: upgrade to encrypted building credentials and cloud-managed access control, not a Faraday pouch. A qualified locksmith or security integrator can assess your current system and recommend the right credential technology for your facility.
Does Key Fob Cloning Affect SLED and Government Facilities?
Yes — and the consequences are more serious than in a typical commercial setting. Government buildings, K-12 schools, universities, and other public sector facilities often have compliance requirements tied directly to access control security. A cloned key fob that grants unauthorized access to a restricted area isn’t just a property loss issue — it can trigger an audit, jeopardize a facility’s compliance standing, or expose administrators to liability.
For SLED facilities, the stakes are compounded by the fact that access control systems often serve as a foundation for broader physical safety posture. An undetected credential breach can lead to unauthorized access to server rooms, record storage, student areas, or sensitive government spaces.
The most defensible approach for SLED and government environments is a cloud-managed access control system using encrypted credentials — one that maintains a complete audit trail, supports instant remote revocation across multiple buildings or campuses, and integrates with video surveillance.
These requirements align with procurement-approved platforms available through cooperative vehicles like CMAS, PEPPM, and GSA Schedules, which is how many public sector organizations procure security upgrades without a lengthy bidding process. Contact us to learn which platforms are available on your procurement vehicle.
Key Fob Alternatives
Many property and business owners find the thought of key fobs being easily cloned scary. Fortunately, there are many enhanced security options to make a key fob access control system more secure, as well as alternate access control systems to choose from — especially when installed by professionals who provide great customer service and ensure the system fits perfectly with your facility’s needs.
First, you can add a layer of security to a key fob system. For example, you can add biometric access control or a keypad. You can also use smart access cards or key cards instead of key fobs.
RFID cards and key cards operate similarly to fobs but use modern encrypted protocols. The most secure options — such as those using 13.56MHz DESFire EV3 with AES-128 encryption and mutual authentication — are essentially unclonable with any consumer device currently available. This is a meaningful technology upgrade, not just “more difficult to clone.” They can also serve as an ID badge, enhancing safety once inside the building.
The upgrade typically requires replacing both readers and credentials, so budget accordingly — but most modern access control platforms accept both formats during a transition period. Once configured properly, the upgraded system typically worked fine with existing infrastructure during phased rollouts and can be managed through a centralized computer interface for streamlined administration.
Mobile credentials are another option worth considering. Smartphone-based access via Bluetooth or NFC uses your phone as a secure, encrypted key that can’t be duplicated like physical fobs. Platforms like Brivo support phone-based credentials alongside encrypted RFID cards and fobs, with cloud-based management that gives administrators real-time visibility, instant remote revocation, and detailed access logs — directly addressing the invisible breach problem plaguing legacy fob systems.
Not sure whether your current system uses encrypted credentials? The frequency isn’t labeled on most fobs — you’ll need to check with your integrator or have a security assessment done. If your system is more than 5–7 years old, there’s a reasonable chance it’s running legacy 125kHz technology. A locksmith or certified security integrator can identify the credential type and help you understand your upgrade options and associated costs.
Have a security project?
References
[1] https://ict.co/blog/the-125khz-proximity-card-dilemma/
[2] https://www.blackhillsinfosec.com/rfid-proximity-cloning-attacks/
