Skip to content

Baiting

In plain terms

You're offered something you want — a file, paid software made free, a found USB drive, a gift in exchange for a survey. You go looking for it yourself, and that's what makes the attack effective.

Definition

Baiting offers a desirable trade — content, software, an object, or a benefit — whose acquisition requires an action from the victim: opening a file, installing a program, plugging in a device, or providing information in exchange.

How it works

Bait reverses the usual relationship: the victim isn't approached, they take the initiative. A storage device abandoned in a busy area will get plugged in out of curiosity, and that curiosity is predictable. Paid software offered for free will be downloaded and installed voluntarily, with the permissions that implies. Coveted content — a document, a recording, a series — justifies disabling a security warning. Since the action comes from the person, protections aren't bypassed technically: they're authorized. The so-called quid pro quo variant trades the bait for a service: free tech support, a gift in exchange for a questionnaire, access in exchange for information.

Warning signs

  • Paid or rare content offered for free, with no explanation for why
  • A found storage device, received by mail, or handed over with no clear origin
  • An install that asks you to disable a protection or ignore a warning
  • A reward offered in exchange for information or access
  • A file whose extension doesn't match what it claims to be
  • A feeling of having found a great deal, before any verification

How to verify

Ask the missing question: why is this free, and who's paying? Software has a publisher and an official site, content has a distributor, and a storage device has an identifiable owner. In the absence of an answer, the bait is the product, and you're what's being acquired.

What to do

Never plug in a storage device whose origin you don't know — hand it to the relevant department instead of examining it yourself. Only install software from its publisher's site, and never disable a protection to get an install to complete.

If it already happened

Disconnect the device from the network and have it scanned with an up-to-date security tool. From another, clean device, change the passwords of sensitive accounts, starting with email. If the device belongs to an organization, notify IT before any manipulation: the traces are useful.

Test yourself

A USB drive is sitting in the lobby, labeled "2026 Payroll."

Start the simulation

Frequently asked questions

Is it risky to plug in a USB drive just to see what's on it?
Yes, and more than it seems: a device can present itself to the system as a keyboard and type commands without you opening a single file. So looking at the contents isn't a sufficient precaution.
I installed free software found online — what should I check?
Uninstall it, run a full scan, then check what's most often modified: browser extensions, startup programs, and your email's forwarding rules. Then change your passwords from another device.

Official sources

This article is part of the Social engineering family. Last updated: 2026-09-02.