The penetration testing industry has a low barrier to entry. Anyone can start a company and declare themselves a “pentest expert.” The result? A market full of providers who sell low-quality services or outright scam clients under the guise of professional testing.
This article describes the most common patterns of dishonest practices and shows how to protect yourself.
Most Common Scam Patterns
1. Vulnerability Scan Sold as Pentest
How it works: The firm runs an automated scanner (Nessus, OpenVAS, Qualys) and delivers the results as a “penetration test report.” The entire “test” takes hours instead of days.
How to recognize:
- Report contains mainly scanner screenshots
- No proof-of-concept for vulnerabilities
- Hundreds of “findings” without contextual prioritization
- Completion time disproportionately short for the scope
- Price significantly below market
Why it’s a problem: Vulnerability scans only detect known problems with known signatures. They don’t test business logic, don’t chain vulnerabilities into attack paths, don’t validate actual exploitability.
2. Copy-Paste Reports
How it works: The firm has report templates from previous projects. They change the client name and a few details, but most content is generic material unrelated to the tested environment.
How to recognize:
- Inconsistencies between descriptions and actual environment
- References to technologies you don’t use
- Screenshots from other systems (different hostnames, dates)
- Identical phrases in reports from the same firm for different clients
Why it’s a problem: You pay for analysis of your environment but get a generic document. Real vulnerabilities may be missed.
3. False Qualifications
How it works: The firm claims certifications and experience they don’t have. “Our pentesters have OSCP” – but they can’t prove it.
How to recognize:
- Refusal to provide certificates for verification
- No way to contact specific pentesters
- Certificates easy to fake (no online verification)
- “Industry experience” without specific examples
Why it’s a problem: A pentester without proper competencies won’t detect advanced vulnerabilities. You may get a false picture of security.
4. Scope Creep and Hidden Costs
How it works: Low initial price, but every additional activity costs extra. Retest? Additional fee. Results presentation? Extra. Consultation? Per hour.
How to recognize:
- Price “from” without clear scope
- No detailed pricing in the offer
- Reluctance for fixed-price contract
- Contract with many exclusions
Why it’s a problem: Final cost may be 2-3x higher than the offer. And once you’ve paid for tests, you’re in a weak negotiating position.
5. The Test That Never Was
How it works: The firm takes money, delivers a report, but the test was never conducted or was minimal. The report is a compilation of publicly available information.
How to recognize:
- No test logs on client side
- Findings only from public sources (Shodan, SSL Labs)
- No interaction attempts with systems (no SIEM/WAF alerts)
- Report delivered suspiciously quickly
Why it’s a problem: You pay for fiction. You get no value, and a fake report may be used for compliance – which is fraud against auditors.
6. Conflict of Interest
How it works: The pentesting firm “coincidentally” finds problems that are solved by products they sell or implement.
How to recognize:
- Firm offers both pentests and security solutions
- Recommendations always lead to specific products
- No neutral alternatives in recommendations
- Pressure for quick decision “because the vulnerability is critical”
Why it’s a problem: You lose objective assessment. You may buy unnecessary solutions or overlook real problems.
📚 Read the complete guide: Cyberbezpieczeństwo: Kompletny przewodnik po cyberbezpieczeństwie dla zarządów i menedżerów
Warning Signs During Bidding
Communication
- No questions about your environment – a professional needs details to quote
- Instant offer – reliable pricing requires analysis
- Avoiding meetings/calls – only email communication
- Aggressive sales – “offer valid only today”
Offer
- No detailed scope – “application pentest” without defining what that means
- “100% security” guarantee – impossible to fulfill
- Flat rate without knowing scope – how did they price something they don’t know?
- No team information – who will be testing?
Contract
- No NDA – professionals protect client data
- No liability insurance – risk for both parties
- One-sided liability exclusions – “we’re responsible for nothing”
- No escalation procedure – what about critical findings?
How to Verify Providers
Check Certifications
- OSCP can be verified through Offensive Security
- CREST maintains a public registry of certified firms
- Ask for certificate numbers and verify independently
Request References
- Contact provided references directly
- Ask about specific projects, not general impressions
- Check if references are current
Evaluate a Sample Report
- Request an anonymized report from a previous project
- Check quality: structure, detail, recommendations
- Look for proof-of-concept
Do Background Check
- Check the company in business registries
- Look for online reviews (but be critical – they may be fake)
- Check history – how long have they operated?
Test During the Process
- Ask technical questions – are answers competent?
- Request scope modification – how do they react?
- Negotiate – professionals understand business
What to Do If You’ve Been Victimized
Document Everything
- Keep all communication
- Archive the report and contract
- Collect logs from your own systems (or their absence)
Assess the Damage
- Was the report used for compliance?
- Were decisions made based on false results?
- Was data exposed?
Consider Legal Action
- Consult with a lawyer
- Report to consumer protection agencies
- File a police report (fraud)
Fix the Situation
- Commission a real pentest from a verified firm
- Inform stakeholders about the situation
- Update vendor selection processes
Red Flags During the Project
Even after selecting a provider, watch for:
- No communication – silence throughout testing
- No questions – a professional has questions about the environment
- No alerts in your systems – if they’re testing, you should see activity
- Report in 24h after completion – thorough analysis takes time
- Findings only from public sources – Shodan, SSL Labs you can check yourself
Summary
The pentest market is unregulated. Responsibility for verifying providers rests with the client. Key principles:
- Don’t choose by price – the cheapest offer is often the most expensive mistake
- Verify competencies – certifications, references, sample reports
- Read the contract – scope, deliverables, liability
- Monitor the project – be engaged, not just a report recipient
- Trust your instincts – if something seems too good, it probably is
A professional pentest is an investment. A scam is a cost without value and a false sense of security – the worst possible combination.
Have doubts about the quality of penetration tests you received? Contact us – we can conduct an independent assessment.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- IT Infrastructure Penetration Testing — IT infrastructure penetration testing is a controlled and ethical process of…
- Wi-Fi Network Penetration Testing — Wi-Fi network penetration testing is the process of assessing the security of…
- Penetration Testing — Penetration testing, also known as pentesting, is a controlled process of…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Phishing — Phishing is a type of social engineering attack that aims to deceive the victim…
Learn More
Explore related articles in our knowledge base:
- Active Directory Penetration Testing: Specifics, Techniques, and Attack Paths
- Benefits of Regular Penetration Testing for Medium Enterprises
- Penetration Testing (Pentests)
- Penetration Testing Tools - Overview of Key Solutions
- The Role of Social Engineering in Penetration Testing
Explore Our Services
Need cybersecurity support? Check out:
- Penetration Testing - identify vulnerabilities in your infrastructure
- Red Team - advanced attack simulations
