S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.11
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Quid Pro Quo

Human Vector · Reciprocity-Based Attack · High
Red Flag
How It WorksSEC 01

A quid pro quo attack offers the target a service, benefit, or favor — most often “technical help” — in exchange for credentials, access, or an action that compromises security. The Latin means “something for something,” and the technique weaponizes the norm of reciprocity: when someone does us a favor, we feel obligated to give something back. The attacker manufactures the favor.

The archetype is the fake IT/help-desk call. The attacker phones employees claiming to “resolve a reported issue,” “run a required update,” or “help with a slow computer,” and in the course of “helping” asks the grateful target to disclose a password or MFA code, install remote-access software, or disable a security control. The exchange feels fair and even friendly — the target believes they are receiving help — which is precisely what lowers scrutiny.

It differs from pure authority impersonation in emotional register: rather than commanding from above, the quid-pro-quo attacker serves from beside or below, trading on gratitude and social obligation rather than fear of rank. Reciprocity is powerful because it operates below deliberation — the obligation to reciprocate is triggered by the favor itself, regardless of whether it was requested or the giver is trustworthy. A small helpful act earns trust that is then spent on a larger, security-relevant ask.

Warning SignsSEC 02
  • Unsolicited support you didn't request — no ticket you opened, from someone you can't confirm through a known channel.
  • A favor offered first , with a security-relevant ask attached — the reciprocity signature.
  • A request for your password, MFA code, or a remote-access install as part of the "help."
  • Unusual friendliness and gratitude-inducing framing that disarms scrutiny.
  • Pressure to act "while I've got you on the line" before you can verify.
  • Reluctance to let you call back or verify identity out-of-band.
Frequently Paired WithSEC 03
  • Pretexting · T14.1
    Parent frame — the fabricated backstory
  • Authority Impersonation · T14.7
    "Helpful IT" blends favor with rank
  • Reciprocity · T5.9
    The core persuasion lever, home entry
  • Phishing · T14.2
    "Prize/survey" quid pro quo by message
How the Attack UnfoldsSEC 04
  • Stage 01 · The Offer
    Unsolicited "help," a gift, or a prize arrives — often a fake IT/help-desk call offering to fix an issue.
  • Stage 02 · The Obligation
    Accepting the favor creates a felt debt; a warm, helpful manner builds rapport and lowers scrutiny.
  • Stage 03 · The Ask
    The "helper" spends the goodwill — requesting a password or MFA code, or a remote-access install that hands over control.
Counter-ProtocolSEC 05
Defense: You owe nothing for unrequested help — verify the helper, share no secrets.
  • Pause on unsolicited help. A favor attached to a credential or access request is a stop signal.
  • Verify identity out-of-band. Confirm any support person through the official help-desk number or ticket system you initiate — not the contact they provide.
  • Share no secrets. Never disclose a password or MFA code; never install remote-access tools on someone's say-so.
  • Unhook the obligation. Name the gratitude and set it aside — real IT never asks for your password.
  • Report unsolicited support contacts so the pattern is caught early.