Baiting is a social engineering technique that uses enticing offers to lure victims into clicking malicious links, downloading harmful files, or surrendering sensitive information. It is one of the most common methods behind phishing emails and spam campaigns.
Baiting in Social Engineering
An adversary is going to use baiting techniques, ways to trick the end user into falling for their scams. When we go fishing, we do the same thing: we bait a hook. We put a worm on the end of the hook, using it as bait, something that's going to entice the fish to come and grab our hook. Otherwise, why would they bite into our hook? It doesn't really make sense that they'd swim up to our hook and just bite into it. Instead, we're enticing them with this bait.
So baiting is creating an enticing offer to allure the victim into a social engineering trap. "Download free Making Millions ebook. Just click and subscribe." This is an enticing offer. All we need to do is click and subscribe for this Making Millions ebook. And maybe I think, oh, that sounds really great, a Making Millions ebook. I'm being baited to click and subscribe.
We see baiting happening on a lot of spam and phishing emails. In fact, why do you think it's called phishing? Because you're fishing out there for information. You're trying to get information, and you're baiting that hook, somehow baiting them to fall for those phishing emails.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →