A quid pro quo attack offers the target a service, benefit, or favor — most often “technical help” — in exchange for credentials, access, or an action that compromises security. The Latin means “something for something,” and the technique weaponizes the norm of reciprocity: when someone does us a favor, we feel obligated to give something back. The attacker manufactures the favor.
The archetype is the fake IT/help-desk call. The attacker phones employees claiming to “resolve a reported issue,” “run a required update,” or “help with a slow computer,” and in the course of “helping” asks the grateful target to disclose a password or MFA code, install remote-access software, or disable a security control. The exchange feels fair and even friendly — the target believes they are receiving help — which is precisely what lowers scrutiny.
It differs from pure authority impersonation in emotional register: rather than commanding from above, the quid-pro-quo attacker serves from beside or below, trading on gratitude and social obligation rather than fear of rank. Reciprocity is powerful because it operates below deliberation — the obligation to reciprocate is triggered by the favor itself, regardless of whether it was requested or the giver is trustworthy. A small helpful act earns trust that is then spent on a larger, security-relevant ask.