Attack type comparisons

Baiting vs phishing: what is the difference?

Phishing pushes a lure at the target. Baiting leaves something the target chooses to pick up, such as a USB drive, a free download or a gift-card offer, so the victim initiates the compromise themselves. That voluntary step is what makes baiting hard to train against.

Phishing requires the attacker to reach an inbox and survive a filter. Baiting skips both. Nothing arrives, so nothing can be scanned. The attacker relies on curiosity, or on the appearance of a legitimate free item, and the victim performs the action that grants access.

Baiting is also often physical, which puts it outside every email and network control an organisation owns.

Documented cases

The control that breaks it

  • Disable autorun, block unknown USB mass-storage devices by policy, and use application allowlisting so an executable from removable media cannot run.
  • The behavioural half matters just as much: give people a no-blame route to hand in a found device, because the alternative is that someone plugs it in to find out whose it is.