← All terms

Quid Pro Quo Attack

A quid pro quo attack is a social engineering technique that offers a service or benefit — often fake IT support — in exchange for access, credentials, or data.

A quid pro quo attack is a social engineering technique built on an exchange: the attacker offers something the victim wants — help, a service, a perk — and collects credentials, access, or sensitive data as the "payment." Where baiting dangles a passive lure (a free download, a dropped USB stick), quid pro quo is transactional and usually interactive: the attacker is present, delivering the promised favor while harvesting what they came for.

How it works

The classic version is fake IT support. The attacker cold-calls employees claiming to be from the help desk, offering to fix a slow machine, resolve a ticket, or roll out an update. Sooner or later they reach someone who actually has a problem — and that person gratefully hands over their password, approves an MFA prompt, or installs "support software" that is really a remote access tool. The exchange feels legitimate because the victim receives real, immediate value: their apparent problem gets attention.

Other common shapes include fake research surveys that trade gift cards for answers to questions suspiciously like password-reset prompts (first pet, first school), "free security audits" that ask for network details, and social media offers of exclusive access or upgrades in return for account verification. The defining feature is always reciprocity: people feel obligated to give something back to someone who has just helped them, and attackers exploit that instinct deliberately.

Quid pro quo often overlaps with pretexting — the fabricated identity supplies the cover story, and the favor supplies the motive to engage.

How to defend against it

  • Verify before you accept help. Unsolicited support calls should be treated like unsolicited links: hang up and call the help desk back on its published internal number.
  • Establish that IT never asks for passwords. Make it a stated, absolute policy — then employees know any such request is an attack, whatever the caller offers.
  • Rehearse the scenario. Voice-channel lures belong in your phishing simulation program alongside email — our guide to vishing and smishing attacks covers building that reflex in depth.
  • Track who engages. Feeding simulation outcomes into a Human Risk Score shows which teams accept unverified "help" and need targeted coaching.

Related terms

PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.VishingVishing (voice phishing) is a social engineering attack conducted over phone calls to manipulate victims into revealing sensitive information or taking harmful actions.BaitingBaiting is a social engineering attack that lures victims with a tempting item — such as a USB drive, free download, or prize — to deliver malware or harvest credentials.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo