Laura Hobson, Co-Founder & COO, YoursGlobal · · 6 min read
Your apartment lock has never been easier to bypass. Not because of broken locks. Because of technology you've never heard of.
Shalini Thakur came home one day and realized someone had been in her apartment while she slept. She had obtained a copy of her apartment key. How? No one forced the lock. No one broke a window. She simply made a copy of the key and walked inside.
Here's what no one talks about: modern apartment and hotel locks are vulnerable to attacks most renters and travelers don't even know exist.
Most apartment and hotel locks today aren't simple mechanical locks. They're smart locks that use NFC (Near Field Communication)—the same technology that powers contactless payments and Apple Pay.
Here's how it works:
You get an access card. The card has an NFC chip. You tap it on the lock reader. The reader verifies the card is legitimate. The door opens.
Simple. Convenient. Completely vulnerable to someone who knows how to exploit it.
An abuser watches you tap your key card on your lock. With an NFC card reader (available on Amazon for $30–50), they can read the data on your card. That data isn't encrypted in the way you'd think. It's often just an ID number—sometimes even a default PIN.
They take that data, write it to a blank NFC card (a few dollars), and they have a duplicate of your key. They can now open your door anytime.
This is exactly what authorities believe happened to Shalini.
An attacker doesn't need to clone your card. They can place a small NFC device directly on your lock reader—hidden under a sticker, taped inside the lock, or integrated into the lock frame. When you tap your card, the rogue device intercepts the signal and captures your credentials. Now the attacker has your card data without ever touching your card.
Some smart locks have default credentials or unpatched vulnerabilities. An attacker who knows these can change the lock's settings remotely—add themselves as an authorized user, disable access logging, or lock you out entirely.
In 2025, security researchers disclosed CVE-2025-25650: a critical vulnerability in Dorset DG 201 smart locks that allows remote NFC card cloning. CVSS severity: 9.1 (critical).
In 2023, Flient Smart Locks were found to have unencrypted NFC tags, allowing anyone with an NFC reader to clone a key card from proximity.
In 2022, Ultraloq UL3 2nd Gen locks had BLE session reuse vulnerabilities allowing attackers to sniff and replay authentication.
These vulnerabilities exist in locks that are in homes and rental properties right now. And most people don't know about them.
It's a liability nightmare. If a hotel admits that key card cloning is possible, they're admitting that their locks can be bypassed. If a rental property discloses NFC vulnerabilities, they're admitting renters could be at risk.
So they say nothing. They assume attackers won't bother. They hope law enforcement will handle it if something goes wrong.
It's the same logic that kept Shalini in danger. Someone had a copy of her key and was entering her home. But the lock company didn't warn her. The apartment didn't warn her. The system assumed it wouldn't happen.
It happened anyway.
When you sign a lease, ask what type of lock the apartment uses. Is it a traditional mechanical lock? A smart lock? What access controls are in place?
If the building still has traditional deadbolts on the inside of the door, use them. A mechanical lock can't be cloned digitally.
If your apartment uses a smart lock with a code, change it as soon as you move in. Reset it periodically. This assumes you're not being targeted, but it's a good baseline.
Even if your smart lock is compromised, a chain and interior deadbolt make it much harder for someone to enter undetected.
If you're concerned about NFC vulnerabilities, a door wedge or portable door lock (physical, not smart) is your backup layer.
Look at your lock every day for signs of tampering: unfamiliar stickers, USB devices, wires, or anything attached to the reader. If something looks wrong, contact your landlord and law enforcement.
Always use the interior deadbolt, chain, or safety bar. Don't rely solely on the key card lock.
Don't leave expensive items, documents, or anything with personal information in your room. Carry them or lock them in the hotel safe.
If you notice someone trying your door, someone lurking near the lock reader, or anything that seems off, tell hotel security immediately.
Portable door alarms (about $10–20) alert you if someone opens the door while you're inside. These work independently of the lock system.
If a room feels unsafe, change rooms. If a lock feels compromised, request a different room on a different floor.
Apps like YourSweep can detect rogue NFC devices placed on your lock reader—they show up as unauthorized cards or devices attempting to communicate with your lock. If YourSweep detects an unknown device, call the police and your landlord immediately.
If you suspect tampering, take photos and videos. Note dates and times. Don't remove any evidence—let law enforcement do that.
You rent an apartment. You didn't choose the lock. You didn't approve the security system. You don't get to decide what level of access control is appropriate. You're dependent on your landlord, and your landlord is dependent on the lock company.
If the lock company doesn't know about—or doesn't disclose—vulnerabilities, you're exposed.
This is how Shalini ended up with someone who had a copy of her key. It wasn't her fault. It was a gap in the system.
Apartment and hotel locks should be:
You can't fix the lock system. But you can protect yourself within it:
Because the system that's supposed to protect your home has gaps. And until those gaps are closed, you need to be your own first line of defense.
If you believe your home has been burglarized or if you suspect someone is using an unauthorized key to access your apartment, contact local law enforcement immediately. Document everything and preserve any suspicious devices for police investigation.