Legitimacy & Context Mirroring
Legitimacy and context mirroring uses familiar organisational detail to make a request appear plausible. The context may include branding, terminology, workflow sequence, operational timing, relationships, technology, business activity, communication style, security language, or authentic conversation history.
Mirrored context may be genuine, copied, reconstructed or partly fabricated. A request may use real project details, a known supplier, familiar language or an authentic communication thread while altering one or more important elements such as the sender, destination, account details, attachment, approval or requested action. Familiar context should support understanding of the request without replacing verification of the action itself.
Legitimacy and context mirroring can be assessed by asking:
- What familiar detail makes the interaction appear legitimate?
- Which parts of the context are independently known to be genuine?
- What material element has changed?
- What verification remains appropriate to the requested action?
Techniques
Section titled “Techniques”Legitimacy & Context Mirroring includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.
- SE-T009.001Branding & Visual MimicryCopying trusted branding, logos, layouts, colours, templates, or interface design.
- SE-T009.002Organisational Language MirroringUsing internal terminology, communication style, naming conventions, or operational language.
- SE-T009.003Workflow & Process MirroringMimicking legitimate business workflows, approvals, or operational processes.
- SE-T009.004Timing & Operational Context MirroringAligning activity with real-world business timing, events, or operational cycles.
- SE-T009.005Relationship Context MirroringReferencing real relationships, suppliers, teams, reporting lines, or previous communications.
- SE-T009.006Technical Environment Context MirroringReferencing accurate details of the organisation’s technology environment to make a request, warning, or support interaction appear plausible.
- SE-T009.007Business Activity MirroringReferencing legitimate operational activity to create plausibility.
- SE-T009.008Sender Communication Style MirroringCopying the tone, phrasing, punctuation, formatting, greeting, or signature habits associated with a particular person or role.
- SE-T009.009Security & Compliance FramingPresenting activity as part of legitimate security, compliance, governance, or operational policy activity.
- SE-T009.010Thread Hijacking & Authentic-Context InsertionInserting attacker-controlled requests into a genuine conversation or reply chain so authentic context carries the deception.
Behavioural Indicators
Section titled “Behavioural Indicators”Legitimacy and context mirroring activity may involve one or more of the following behaviours:
Visual, brand, and interface mirroring
- copying trusted branding, logos, templates, colours, signatures, disclaimers, or interface layouts
- using realistic platform pages, login screens, file-sharing portals, forms, approval screens, or notifications
- placing one deceptive element inside an otherwise familiar-looking message, document, or workflow
- using official-looking attachments, buttons, QR codes, certificates, padlock imagery, or security language
Language and relationship mirroring
- using internal terminology, project names, supplier names, team names, staff names, or process language
- referencing previous discussions, existing relationships, known suppliers, or shared business context
- continuing or imitating an existing conversation thread, including inserting into a genuine reply chain from a compromised counterparty or supplier mailbox
- copying writing style, tone, greeting patterns, signature blocks, or expected communication habits
- presenting the request as routine, expected, already approved, or part of normal business activity
Workflow and operational mirroring
- aligning the request with payroll runs, invoice cycles, project timelines, audit windows, recruitment activity, supplier transitions, maintenance windows, or event periods
- imitating approval workflows, procurement steps, HR processes, IT support flows, identity checks, or compliance activities
- claiming the request follows a known process while changing a key detail such as destination account, contact method, attachment, link, approver, or access scope
- using a plausible business reason to reduce scrutiny