Baiting leaves something tempting where a target will find it, relying on curiosity or greed. Quid pro quo offers a direct exchange, usually help or a reward in return for access or information. Baiting is passive and waits; quid pro quo is an active offer.
Both exploit reciprocity, but the defence differs. Baiting is countered by technical restrictions on untrusted media. Quid pro quo is countered by process, because the target is being persuaded to hand something over deliberately.
Documented cases
- Baiting, measured: in the UIUC USB drop study, researchers scattered 297 drives on campus. About 98% were removed from where they were dropped, and files were opened on 45% of them.
- Baiting, weaponised: FIN7 mailed packages posing as Best Buy gift-card rewards, containing hardware implants, to HR and IT staff.
- Quid pro quo: Rapid7 used a new-employee pretext, offering a helpable problem in exchange for access.
The control that breaks it
- Block or restrict removable media by policy, so curiosity cannot execute anything.
- Route unsolicited devices and gifts to security, and say so before they arrive.
- Require verified identity before granting access, whatever the offered justification.
Related: USB drop attack vs baiting · baiting vs phishing · Physical social engineering
Related