← All terms

Baiting

Baiting is a social engineering attack that lures victims with a tempting item — such as a USB drive, free download, or prize — to deliver malware or harvest credentials.

Baiting exploits curiosity or greed by offering something the target wants — a free USB drive, a movie download, a gift card, or exclusive content — in exchange for an action that compromises security. Unlike phishing, which impersonates a trusted entity, baiting relies on the lure itself to drive interaction.

How it works

Baiting takes both physical and digital forms:

  • USB drops. Labeled USB drives ("Salary Review Q3," "Confidential — HR") are left in parking lots, lobbies, or break rooms. When an employee plugs one in, it installs malware, opens a reverse shell, or redirects to a credential-harvesting page. Some advanced USB devices emulate a keyboard and execute commands in seconds.
  • Malicious downloads. Fake software, cracked applications, pirated media, or "free tools" hosted on lookalike sites bundle malware with the download.
  • Prize and reward scams. Messages promising gift cards, contest winnings, or exclusive access lead to phishing pages or malware installers.
  • Trojanized peripherals. In targeted attacks, devices like charging cables or conference room adapters have been modified to capture data or inject keystrokes.

The effectiveness of baiting depends on the gap between the perceived reward and the perceived risk. A USB labeled "Layoff Plans" in a company going through restructuring exploits both curiosity and anxiety.

How to defend against it

  • Include USB drop simulations in your security testing program. NOUSEC supports physical-channel simulations including USB drops to measure and improve employee response.
  • Disable USB auto-run and restrict removable media on corporate endpoints through group policy or endpoint management.
  • Train employees on baiting tactics — the "too good to be true" rule applies to physical objects and free downloads just as it does to email offers. The interactive cousin of baiting, the quid pro quo attack, deserves its own scenario: there the attacker delivers the "favor" in person.
  • Establish a process for found devices — employees should bring unknown USB drives or hardware to IT security rather than plugging them in.

Related terms

Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo