Skip to content
Knowledge base Updated: February 5, 2026

Penetration Testing Industry Scams: How to Recognize Unreliable Vendors

Not every company offering 'penetration testing' actually performs it. Learn common industry scams - from scans sold as pentests to fake reports - and how to recognize them.

The penetration testing industry has a low barrier to entry. Anyone can start a company and declare themselves a “pentest expert.” The result? A market full of providers who sell low-quality services or outright scam clients under the guise of professional testing.

This article describes the most common patterns of dishonest practices and shows how to protect yourself.

Most Common Scam Patterns

1. Vulnerability Scan Sold as Pentest

How it works: The firm runs an automated scanner (Nessus, OpenVAS, Qualys) and delivers the results as a “penetration test report.” The entire “test” takes hours instead of days.

How to recognize:

  • Report contains mainly scanner screenshots
  • No proof-of-concept for vulnerabilities
  • Hundreds of “findings” without contextual prioritization
  • Completion time disproportionately short for the scope
  • Price significantly below market

Why it’s a problem: Vulnerability scans only detect known problems with known signatures. They don’t test business logic, don’t chain vulnerabilities into attack paths, don’t validate actual exploitability.

2. Copy-Paste Reports

How it works: The firm has report templates from previous projects. They change the client name and a few details, but most content is generic material unrelated to the tested environment.

How to recognize:

  • Inconsistencies between descriptions and actual environment
  • References to technologies you don’t use
  • Screenshots from other systems (different hostnames, dates)
  • Identical phrases in reports from the same firm for different clients

Why it’s a problem: You pay for analysis of your environment but get a generic document. Real vulnerabilities may be missed.

3. False Qualifications

How it works: The firm claims certifications and experience they don’t have. “Our pentesters have OSCP” – but they can’t prove it.

How to recognize:

  • Refusal to provide certificates for verification
  • No way to contact specific pentesters
  • Certificates easy to fake (no online verification)
  • “Industry experience” without specific examples

Why it’s a problem: A pentester without proper competencies won’t detect advanced vulnerabilities. You may get a false picture of security.

4. Scope Creep and Hidden Costs

How it works: Low initial price, but every additional activity costs extra. Retest? Additional fee. Results presentation? Extra. Consultation? Per hour.

How to recognize:

  • Price “from” without clear scope
  • No detailed pricing in the offer
  • Reluctance for fixed-price contract
  • Contract with many exclusions

Why it’s a problem: Final cost may be 2-3x higher than the offer. And once you’ve paid for tests, you’re in a weak negotiating position.

5. The Test That Never Was

How it works: The firm takes money, delivers a report, but the test was never conducted or was minimal. The report is a compilation of publicly available information.

How to recognize:

  • No test logs on client side
  • Findings only from public sources (Shodan, SSL Labs)
  • No interaction attempts with systems (no SIEM/WAF alerts)
  • Report delivered suspiciously quickly

Why it’s a problem: You pay for fiction. You get no value, and a fake report may be used for compliance – which is fraud against auditors.

6. Conflict of Interest

How it works: The pentesting firm “coincidentally” finds problems that are solved by products they sell or implement.

How to recognize:

  • Firm offers both pentests and security solutions
  • Recommendations always lead to specific products
  • No neutral alternatives in recommendations
  • Pressure for quick decision “because the vulnerability is critical”

Why it’s a problem: You lose objective assessment. You may buy unnecessary solutions or overlook real problems.

📚 Read the complete guide: Cyberbezpieczeństwo: Kompletny przewodnik po cyberbezpieczeństwie dla zarządów i menedżerów

Warning Signs During Bidding

Communication

  • No questions about your environment – a professional needs details to quote
  • Instant offer – reliable pricing requires analysis
  • Avoiding meetings/calls – only email communication
  • Aggressive sales – “offer valid only today”

Offer

  • No detailed scope – “application pentest” without defining what that means
  • “100% security” guarantee – impossible to fulfill
  • Flat rate without knowing scope – how did they price something they don’t know?
  • No team information – who will be testing?

Contract

  • No NDA – professionals protect client data
  • No liability insurance – risk for both parties
  • One-sided liability exclusions – “we’re responsible for nothing”
  • No escalation procedure – what about critical findings?

How to Verify Providers

Check Certifications

  • OSCP can be verified through Offensive Security
  • CREST maintains a public registry of certified firms
  • Ask for certificate numbers and verify independently

Request References

  • Contact provided references directly
  • Ask about specific projects, not general impressions
  • Check if references are current

Evaluate a Sample Report

  • Request an anonymized report from a previous project
  • Check quality: structure, detail, recommendations
  • Look for proof-of-concept

Do Background Check

  • Check the company in business registries
  • Look for online reviews (but be critical – they may be fake)
  • Check history – how long have they operated?

Test During the Process

  • Ask technical questions – are answers competent?
  • Request scope modification – how do they react?
  • Negotiate – professionals understand business

What to Do If You’ve Been Victimized

Document Everything

  • Keep all communication
  • Archive the report and contract
  • Collect logs from your own systems (or their absence)

Assess the Damage

  • Was the report used for compliance?
  • Were decisions made based on false results?
  • Was data exposed?
  • Consult with a lawyer
  • Report to consumer protection agencies
  • File a police report (fraud)

Fix the Situation

  • Commission a real pentest from a verified firm
  • Inform stakeholders about the situation
  • Update vendor selection processes

Red Flags During the Project

Even after selecting a provider, watch for:

  • No communication – silence throughout testing
  • No questions – a professional has questions about the environment
  • No alerts in your systems – if they’re testing, you should see activity
  • Report in 24h after completion – thorough analysis takes time
  • Findings only from public sourcesShodan, SSL Labs you can check yourself

Summary

The pentest market is unregulated. Responsibility for verifying providers rests with the client. Key principles:

  1. Don’t choose by price – the cheapest offer is often the most expensive mistake
  2. Verify competencies – certifications, references, sample reports
  3. Read the contract – scope, deliverables, liability
  4. Monitor the project – be engaged, not just a report recipient
  5. Trust your instincts – if something seems too good, it probably is

A professional pentest is an investment. A scam is a cost without value and a false sense of security – the worst possible combination.


Have doubts about the quality of penetration tests you received? Contact us – we can conduct an independent assessment.

Learn key terms related to this article in our cybersecurity glossary:


Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist