What Is Baiting in Cyber Security? How Physical Traps Steal Data
Baiting is a social engineering attack that exploits curiosity or greed, offering something tempting, like a free USB drive or download, to trick a victim into installing malware or handing over credentials. If you have ever doubted that anyone would actually plug in a random USB drive found in a parking lot, real research shows they genuinely do, and quickly.
What Is Baiting in Cyber Security?
Baiting is a social engineering technique that exploits human curiosity or greed by offering something enticing, a free item, a tempting download, a seemingly lost device, specifically to trick a victim into taking an action that compromises security. Unlike attacks relying purely on urgency or fear, baiting works because people want to see what they have found, or claim something offered to them.
The classic example is a physical device, a USB drive left somewhere it will be found, but baiting extends equally to digital lures, fake downloads, gift card scams, and enticing offers designed to prompt the same curiosity-driven click.
Baiting vs Phishing vs Pretexting: Where Curiosity Fits in the Social Engineering Family
| Technique | Primary Psychological Lever | Typical Delivery |
| Phishing | Trust, urgency, fear | Email, text, phone |
| Pretexting | Fabricated scenario, authority | Direct conversation, impersonation |
| Baiting | Curiosity, greed | Physical device, tempting offer |
Phishing relies primarily on trust, urgency and fear, impersonating a legitimate source to prompt quick, unconsidered action. Pretexting relies on a fabricated scenario and often assumed authority, an attacker posing as IT support or a vendor to extract information through a constructed conversation.
Baiting occupies a genuinely distinct position in this family, since it relies specifically on curiosity or greed rather than trust or fear. A victim is not being deceived about who is contacting them the way phishing and pretexting both require. They are being tempted by something they want to investigate or claim, making baiting effective even against people who have been trained to distrust unsolicited emails and calls, since the psychological trigger is entirely different.
USB Drop Attacks: The Classic Example, and the Real Numbers Behind Why They Work
USB drop attacks work by leaving infected USB drives in locations where potential victims will find them, a parking lot, a lobby, a break room, relying on the finder’s curiosity or good intentions to plug the drive into a computer.
The genuinely striking part is how well documented this technique’s success rate actually is. Researchers from Google, the University of Illinois Urbana-Champaign, and the University of Michigan dropped 297 USB drives around a university campus and tracked what happened. The result: 48% of the dropped drives were picked up, plugged in, and had at least one file opened. The first drive was connected in under six minutes. Notably, 68% of people who plugged in a drive said they did so for altruistic reasons, genuinely wanting to return it to its owner, while another 18% admitted curiosity alone drove them to look. Only 16% of people scanned the drive with antivirus software before opening anything on it.
This matters far beyond academic curiosity. The study demonstrates that baiting succeeds specifically because it exploits genuinely positive human instincts, wanting to help, wanting to know, not just carelessness or naivety. An employee who would never click a suspicious email link might still plug in a USB drive labeled “Payroll 2026” found in the office parking lot, purely out of concern that a colleague lost something important. This is precisely why baiting defense cannot rely solely on telling people to “be more careful.” The instinct being exploited is a good one, and effective defense has to account for that rather than assuming only careless people fall for it.
Real Examples: From a Mailed CD in 2018 to Targeted Campaigns Like Sogu and Snowydrive
Baiting is not a historical curiosity confined to academic studies. It remains an active, evolving technique used in genuinely current attack campaigns.
In 2018, malware-infected CDs were mailed from China to several US state and local government agencies, containing Mandarin-language Word documents embedded with malicious Visual Basic scripts. The attempt notably failed, since recipients were cautious enough to avoid opening the disks, a reminder that awareness genuinely defeats even sophisticated baiting attempts when people pause before acting.
More recently, security firm Mandiant reported a threefold increase in USB-delivered malware attacks during the first half of 2023 alone. Two campaigns stood out specifically. Sogu, attributed to a China-linked threat actor tracked as TEMP.Hex, also known as Camaro Dragon and Mustang Panda, became the most aggressive USB-based cyber-espionage campaign observed, targeting construction, engineering, government, healthcare and transportation organizations across the US, UK, and more than a dozen other countries. The infection chain begins with a legitimate-looking executable on the USB drive that decrypts and launches a backdoor capable of exfiltrating files, keystrokes and screenshots. Snowydrive, attributed to a separate cluster called UNC4698, specifically targeted oil and gas organizations in Asia, establishing a backdoor and spreading itself automatically to any other USB drive connected to the infected system.
Mandiant’s own research specifically flagged hotels and local print shops as infection hotspots, locations where business travelers are more likely to use unfamiliar equipment and let their guard down. This progression, from a failed, relatively unsophisticated 2018 mail campaign to precisely targeted, nation-state-linked USB operations exploiting real business travel habits, shows baiting has genuinely matured as a technique rather than fading as awareness has grown.
Beyond USBs: Digital Baiting
Digital baiting applies the identical curiosity-and-greed principle without any physical device involved. Free movie or software downloads promising content that would normally require payment frequently deliver malware instead of the promised content. Fake gift card or prize notifications, arriving by email or text, ask victims to click through and enter personal information to claim a reward that does not exist.
Malvertising, fraudulent advertisements placed on otherwise legitimate websites, leads unsuspecting users toward malicious downloads simply by promising something appealing enough to click. The defense principle stays consistent across both physical and digital baiting: anything offered unexpectedly, whether a found USB drive or an unbelievable online deal, deserves the same skepticism before acting.
What Does UK Guidance Require?
The UK’s National Cyber Security Centre maintains current, active guidance on removable media specifically within its ongoing “10 Steps to Cyber Security” collection, alongside a dedicated document on the secure sanitisation of storage media covering appropriate disposal and reuse of devices that may have held sensitive data.
Here is a distinction worth making directly, since older links circulating online can genuinely mislead. A separate, standalone “10 Steps: Summary” document previously published on GOV.UK has been formally withdrawn, with its content moved entirely into NCSC’s own current guidance pages. If you encounter that older, withdrawn version while researching your own policy, treat it as historical rather than authoritative, and refer instead to NCSC’s own live guidance directly.
Current NCSC recommendations specifically call for producing a written removable media policy limiting which device types, users and information categories are permitted, scanning all external media using a standalone scanner before any data reaches your organization’s systems, and, per NCSC and CPNI’s own joint bulletin, increasingly favoring hardware-based scanning solutions specifically where software controls alone cannot reliably neutralize the threat a given device carries. For organizations operating industrial control or operational technology systems, NCSC also points toward RITICS-published guidance addressing removable media risks specific to that environment, since a standard office removable media policy rarely accounts for the unique constraints of production and safety-critical systems.
How Do You Build a Layered Defence Against Baiting?
Establish a clear, written removable media policy naming exactly which devices, if any, are permitted, and require every external device to pass through a standalone scanning station before connecting to any work system. Disable autorun functionality across all organizational devices, removing the automatic execution step that lets a plugged-in drive run malicious code without any further action from the user.
Train employees specifically on baiting’s curiosity-driven mechanism, not just generic phishing awareness, since the psychological trigger genuinely differs and deserves its own explicit coverage. Extend the same skepticism to digital baiting, unexpected downloads, gift card offers, too-good-to-be-true deals, using the identical “pause before acting on an unsolicited offer” principle that defeats physical USB baiting. Cyber Security Solutions Ltd builds exactly this kind of layered, curiosity-aware defense into security awareness programs, recognizing that baiting exploits good instincts as often as careless ones.
Conclusion
Baiting works precisely because it exploits genuinely good instincts, curiosity and the desire to help, not just carelessness, which is exactly why real research shows it succeeds against cautious people too. Start by disabling autorun across your devices and establishing a clear scanning process for any external media before it reaches your systems. To build a layered defense against both physical and digital baiting, visit cybersecuritysolutionsltd.com for expert support from Cyber Security Solutions Ltd.
FAQs
Baiting is a social engineering technique exploiting curiosity or greed, offering something tempting like a free USB drive or download, to trick a victim into installing malware or revealing credentials. It differs from phishing by targeting curiosity rather than trust or urgency.
Phishing relies on trust, urgency and fear, typically impersonating a legitimate source. Baiting relies specifically on curiosity or greed, tempting a victim with something enticing, like a found USB drive or a tempting offer, rather than deceiving them about who is contacting them.
Yes, genuinely often. A study by Google and university researchers found 48% of dropped USB drives were picked up, plugged in, and had files opened, with the first drive connected in under six minutes. Most did so for altruistic reasons, not carelessness.
Sogu and Snowydrive are current USB-delivered malware campaigns identified by Mandiant. Sogu, linked to a China-based threat actor, targets multiple industries globally for espionage. Snowydrive, attributed to a separate group, specifically targets oil and gas organizations in Asia.
Yes. NCSC maintains active guidance within its ongoing “10 Steps to Cyber Security” collection and a dedicated sanitisation guidance document. A separate, older standalone summary document has been formally withdrawn, so verify you are referencing NCSC’s current live guidance directly.
Establish a written removable media policy, scan all external devices at a standalone station before connecting them to work systems, disable autorun functionality, and train employees specifically on baiting’s curiosity-driven mechanism rather than relying only on generic phishing awareness.
