Skip to content

Legitimacy & Context Mirroring

Legitimacy and context mirroring uses familiar organisational detail to make a request appear plausible. The context may include branding, terminology, workflow sequence, operational timing, relationships, technology, business activity, communication style, security language, or authentic conversation history.

Mirrored context may be genuine, copied, reconstructed or partly fabricated. A request may use real project details, a known supplier, familiar language or an authentic communication thread while altering one or more important elements such as the sender, destination, account details, attachment, approval or requested action. Familiar context should support understanding of the request without replacing verification of the action itself.

Legitimacy and context mirroring can be assessed by asking:

  • What familiar detail makes the interaction appear legitimate?
  • Which parts of the context are independently known to be genuine?
  • What material element has changed?
  • What verification remains appropriate to the requested action?

Legitimacy & Context Mirroring includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.


Legitimacy and context mirroring activity may involve one or more of the following behaviours:

Visual, brand, and interface mirroring

  • copying trusted branding, logos, templates, colours, signatures, disclaimers, or interface layouts
  • using realistic platform pages, login screens, file-sharing portals, forms, approval screens, or notifications
  • placing one deceptive element inside an otherwise familiar-looking message, document, or workflow
  • using official-looking attachments, buttons, QR codes, certificates, padlock imagery, or security language

Language and relationship mirroring

  • using internal terminology, project names, supplier names, team names, staff names, or process language
  • referencing previous discussions, existing relationships, known suppliers, or shared business context
  • continuing or imitating an existing conversation thread, including inserting into a genuine reply chain from a compromised counterparty or supplier mailbox
  • copying writing style, tone, greeting patterns, signature blocks, or expected communication habits
  • presenting the request as routine, expected, already approved, or part of normal business activity

Workflow and operational mirroring

  • aligning the request with payroll runs, invoice cycles, project timelines, audit windows, recruitment activity, supplier transitions, maintenance windows, or event periods
  • imitating approval workflows, procurement steps, HR processes, IT support flows, identity checks, or compliance activities
  • claiming the request follows a known process while changing a key detail such as destination account, contact method, attachment, link, approver, or access scope
  • using a plausible business reason to reduce scrutiny