Honey Trap
A honey trap is a social engineering attack that builds a fake romantic or personal relationship to extract credentials, secrets, or access from a target.
A honey trap is a social engineering attack in which the attacker constructs a fake romantic, flirtatious, or close personal relationship — usually through an attractive online persona — to manipulate a target into revealing sensitive information, opening malicious files, or granting access. One of the oldest techniques in espionage, it has migrated wholesale to LinkedIn, Instagram, and dating apps, where a persuasive profile photo and a few weeks of patient conversation can reach employees that a phishing email never would.
How it works
The attacker starts with OSINT: identifying employees with access worth having — engineers, defense contractors, finance staff, system administrators — and studying their interests and social footprint. A tailored persona then makes contact, often posing as a recruiter, industry peer, photographer, or simply an admirer. The relationship is cultivated slowly across weeks or months, moving from public platforms to private channels.
Only after trust is established does the ask arrive, and it rarely feels like an ask: a "portfolio" or "job description" attachment that carries malware, a request to review a document on a credential-harvesting site, curiosity about a project ("what is it you actually work on?"), or escalating requests for photos and information that can later fuel blackmail. Security researchers have documented sustained state-aligned campaigns of exactly this shape — such as the "Mia Ash" persona that targeted engineers at Middle East organizations — and prosecutions in several countries have involved intelligence services running romantic personas against government and industry employees.
The corporate risk compounds when the relationship turns coercive: a compromised employee who fears exposure can be pressured into becoming a deliberate insider threat.
How to defend against it
- Teach the pattern, not just the medium. Awareness programs should cover relationship-based manipulation explicitly — unsolicited attention from strangers who take unusual interest in your work is a flag, however flattering.
- Set social media guardrails. Limit what employees in sensitive roles publish about projects and clearances, and encourage skepticism toward connection requests from unverifiable profiles.
- Create a no-blame reporting path. Victims stay silent out of embarrassment; a culture where reporting "I think I'm being cultivated" is praised — reinforced through security awareness training — catches honey traps while they are still harmless conversations.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo