Quid Pro Quo (Latin for "something for something") is a social engineering attack where the attacker offers a service, benefit, or favor in exchange for sensitive information (login credentials, personal data, financial information) or access to restricted systems. The attacker exploits the victim's desire for free services, technical support, or professional favors. Common quid pro quo attacks include fake IT support calls ("I can remove the virus if you give me your password"), fake software offers ("Free premium software in exchange for survey"), and fake technical assistance ("I'll fix your computer issue if you share your screen").
Attack Prevalence: 60% of organizations experienced quid pro quo attacks in 2023. IT support impersonation accounts for 45% of quid pro quo attacks. Average cost per incident: $1.2 million (data breach, financial fraud).
Common quid pro quo attack vectors:
Attacker contacts victim via phone, email, or chat. Poses as IT support, technical specialist, or service provider.
Attacker offers service: "Free virus removal", "Software update", "Computer optimization", "Technical support".
Victim provides login credentials, installs remote access tool (TeamViewer, AnyDesk), or shares sensitive information.
Attacker accesses accounts, steals data, installs malware, or uses remote access for financial fraud.
Attacker calls victim pretending to be IT support (Microsoft, Apple, Dell, ISP). Claims computer is infected with virus or sending error reports. Requests remote access (TeamViewer, AnyDesk, LogMeIn) or login credentials.
Attacker offers free premium software (antivirus, VPN, password manager) in exchange for completing survey or providing email/password. Software is malware (info-stealer, backdoor).
Attacker offers free computer optimization or speed-up service. Requests remote access (AnyDesk, TeamViewer) to "fix" non-existent issues. Installs malware or steals files.
Attacker offers $100 gift card (Amazon, Starbucks, Walmart) in exchange for completing survey. Survey asks for personal information (SSN, credit card number).
// Quid pro quo attack statistics (FBI IC3, FTC, 2023)
- 70% of IT support scams target elderly victims (age 60+)
- 65% of victims provided remote access (TeamViewer, AnyDesk)
- 50% of victims shared login credentials (banking, email, social media)
- Average financial loss per IT support scam: $15,000 (individual), $500,000+ (business)
- $2.5 billion lost to tech support scams (2020-2023, FTC data)
- 40% of organizations have no quid pro quo training policy
- 25% of employees would provide password to "IT support" (security awareness test)
// Major quid pro quo scams
1. Microsoft Tech Support Scam (2020-2023): $500 million stolen
2. "Free Antivirus" Survey Scam (2022): 2 million victims
3. Remote Access Tool (RAT) Scams (2021-2023): $100 million stolen
This demonstration simulates a quid pro quo attack where an attacker poses as IT support to steal credentials:
This is a simulated demonstration. Real quid pro quo attacks can steal login credentials, install remote access tools (TeamViewer, AnyDesk), and cause financial fraud. Never share credentials over phone. IT support will never ask for your password. Hang up and call back using official number. Enable MFA (Multi-Factor Authentication) on all accounts.
Train employees: IT support never asks for passwords. Verify caller identity (call back using official number). Never install remote access software (TeamViewer, AnyDesk) for unsolicited callers.
MFA prevents account takeover even if password stolen. Use TOTP (Google Authenticator), hardware tokens (YubiKey), or push notifications (Duo).
Attackers spoof caller ID to appear as internal IT number. Hang up and call back using official company number (from directory, not caller ID).
Restrict installation of remote access tools (TeamViewer, AnyDesk, LogMeIn). Require IT approval before installation. Monitor unauthorized remote access attempts.
Best Practice - Verify Before Trusting: IT support will never ask for your password. Never provide credentials over phone. Hang up and call back using official company number. Never install remote access software for unsolicited callers. Enable MFA on all accounts (prevents account takeover even if password stolen). Report suspicious calls to IT security.
Quid pro quo attacks (fraud, identity theft, unauthorized access) are illegal in all jurisdictions:
Quid pro quo attacks (fraud, social engineering) are illegal. Penalties include:
Important: This guide is for educational and defensive purposes only. Quid pro quo attacks are illegal and harmful.
FTC consumer alerts: how to recognize and report tech support scams.
Microsoft official guidance: Microsoft never makes unsolicited support calls.