TechKnowSurge
VideoSecurityFree

Baiting

Baiting is a social engineering technique that uses enticing offers to lure victims into clicking malicious links, downloading harmful files, or surrendering sensitive information. It is one of the most common methods behind phishing emails and spam campaigns.

Complete this video to capture a CTF flag worth 1 point.

About this video

Baiting is a social engineering tactic that relies on human curiosity or desire to manipulate a target into taking an action that benefits the attacker. Rather than using direct deception or impersonation alone, baiting works by constructing an offer that feels genuinely appealing, making the victim a willing participant in their own compromise. Common examples include promises of free ebooks, software downloads, gift cards, or exclusive content that require only a click or a subscription to claim. This technique is closely tied to phishing, and the connection is more than conceptual. The term phishing itself reflects the fishing analogy at the core of baiting: attackers cast a wide net of enticing messages hoping targets will bite. Once a user engages with the bait, they may unknowingly install malware, hand over credentials, or expose personal and organizational data. Recognizing the structure of a baiting attempt, an offer that seems disproportionately rewarding for minimal effort, is a foundational skill in defending against social engineering attacks.

What you'll learn

What's covered

Baiting in Social Engineering

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Baiting
A social engineering technique that uses an enticing offer or lure to trick a victim into taking an action that compromises their security.

Topics

Social Engineering Baiting Phishing Cybersecurity Malware Delivery User Awareness

Transcript

An adversary is going to use baiting techniques, ways to trick the end user into falling for their scams. When we go fishing, we do the same thing: we bait a hook. We put a worm on the end of the hook, using it as bait, something that's going to entice the fish to come and grab our hook. Otherwise, why would they bite into our hook? It doesn't really make sense that they'd swim up to our hook and just bite into it. Instead, we're enticing them with this bait.

So baiting is creating an enticing offer to allure the victim into a social engineering trap. "Download free Making Millions ebook. Just click and subscribe." This is an enticing offer. All we need to do is click and subscribe for this Making Millions ebook. And maybe I think, oh, that sounds really great, a Making Millions ebook. I'm being baited to click and subscribe.

We see baiting happening on a lot of spam and phishing emails. In fact, why do you think it's called phishing? Because you're fishing out there for information. You're trying to get information, and you're baiting that hook, somehow baiting them to fall for those phishing emails.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →