Overview Attack Chain Techniques Statistics Demo Prevention Legal Resources

Quid Pro Quo Guide

What is Quid Pro Quo?

Quid Pro Quo (Latin for "something for something") is a social engineering attack where the attacker offers a service, benefit, or favor in exchange for sensitive information (login credentials, personal data, financial information) or access to restricted systems. The attacker exploits the victim's desire for free services, technical support, or professional favors. Common quid pro quo attacks include fake IT support calls ("I can remove the virus if you give me your password"), fake software offers ("Free premium software in exchange for survey"), and fake technical assistance ("I'll fix your computer issue if you share your screen").

Attack Prevalence: 60% of organizations experienced quid pro quo attacks in 2023. IT support impersonation accounts for 45% of quid pro quo attacks. Average cost per incident: $1.2 million (data breach, financial fraud).

60%
Organizations Affected (2023)
45%
IT Support Impersonation
$1.2M
Average Cost per Incident

Common quid pro quo attack vectors:

How Quid Pro Quo Works (Attack Chain)

1. Approach

Attacker contacts victim via phone, email, or chat. Poses as IT support, technical specialist, or service provider.

2. Offer

Attacker offers service: "Free virus removal", "Software update", "Computer optimization", "Technical support".

3. Exchange

Victim provides login credentials, installs remote access tool (TeamViewer, AnyDesk), or shares sensitive information.

4. Exploitation

Attacker accesses accounts, steals data, installs malware, or uses remote access for financial fraud.

Quid Pro Quo Techniques & Social Engineering

IT Support Impersonation

Attacker calls victim pretending to be IT support (Microsoft, Apple, Dell, ISP). Claims computer is infected with virus or sending error reports. Requests remote access (TeamViewer, AnyDesk, LogMeIn) or login credentials.

Most Common

Free Software Offer

Attacker offers free premium software (antivirus, VPN, password manager) in exchange for completing survey or providing email/password. Software is malware (info-stealer, backdoor).

Technical Assistance Scam

Attacker offers free computer optimization or speed-up service. Requests remote access (AnyDesk, TeamViewer) to "fix" non-existent issues. Installs malware or steals files.

Gift Card Scams

Attacker offers $100 gift card (Amazon, Starbucks, Walmart) in exchange for completing survey. Survey asks for personal information (SSN, credit card number).

Quid Pro Quo Statistics

// Quid pro quo attack statistics (FBI IC3, FTC, 2023) - 70% of IT support scams target elderly victims (age 60+) - 65% of victims provided remote access (TeamViewer, AnyDesk) - 50% of victims shared login credentials (banking, email, social media) - Average financial loss per IT support scam: $15,000 (individual), $500,000+ (business) - $2.5 billion lost to tech support scams (2020-2023, FTC data) - 40% of organizations have no quid pro quo training policy - 25% of employees would provide password to "IT support" (security awareness test) // Major quid pro quo scams 1. Microsoft Tech Support Scam (2020-2023): $500 million stolen 2. "Free Antivirus" Survey Scam (2022): 2 million victims 3. Remote Access Tool (RAT) Scams (2021-2023): $100 million stolen

Quid Pro Quo Attack Simulation (IT Support Scam)

This demonstration simulates a quid pro quo attack where an attacker poses as IT support to steal credentials:

Click "Accept IT Support Offer" to see quid pro quo attack simulation

This is a simulated demonstration. Real quid pro quo attacks can steal login credentials, install remote access tools (TeamViewer, AnyDesk), and cause financial fraud. Never share credentials over phone. IT support will never ask for your password. Hang up and call back using official number. Enable MFA (Multi-Factor Authentication) on all accounts.

Preventing Quid Pro Quo Attacks

Security Awareness Training

Train employees: IT support never asks for passwords. Verify caller identity (call back using official number). Never install remote access software (TeamViewer, AnyDesk) for unsolicited callers.

Multi-Factor Authentication (MFA)

MFA prevents account takeover even if password stolen. Use TOTP (Google Authenticator), hardware tokens (YubiKey), or push notifications (Duo).

Caller ID Spoofing Detection

Attackers spoof caller ID to appear as internal IT number. Hang up and call back using official company number (from directory, not caller ID).

Remote Access Tool Policies

Restrict installation of remote access tools (TeamViewer, AnyDesk, LogMeIn). Require IT approval before installation. Monitor unauthorized remote access attempts.

Best Practice - Verify Before Trusting: IT support will never ask for your password. Never provide credentials over phone. Hang up and call back using official company number. Never install remote access software for unsolicited callers. Enable MFA on all accounts (prevents account takeover even if password stolen). Report suspicious calls to IT security.

Further Resources

FTC Tech Support Scam Alerts

FTC consumer alerts: how to recognize and report tech support scams.

Microsoft Tech Support Scam Prevention

Microsoft official guidance: Microsoft never makes unsolicited support calls.

← Back to Knowledge Base