Skip to content

Trust Exploitation

Trust exploitation uses an existing or assumed relationship, professional credibility, helpfulness, goodwill, shared affiliation, or borrowed legitimacy to make a request feel safe and familiar. Impersonation centres on the identity being presented; trust exploitation centres on the relationship or source of credibility that lowers scrutiny.

The requester may be exactly who they claim to be. The risk arises when trust in a colleague, supplier, professional, community, channel, or routine is carried into an action that is unusual, outside scope, or insufficiently verified. A relationship can be genuine while the current request is mistaken, compromised, coerced, outdated, or unauthorised.

Trust exploitation can be assessed by asking:

  • What relationship or source of trust is being used?
  • What scrutiny is being lowered because the interaction feels familiar, helpful, or professionally credible?
  • How sensitive is the requested action?
  • What verification, approval, or escalation path should still apply?

Trust Exploitation includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.


Trust exploitation activity may involve one or more of the following behaviours.

Relationship and familiarity cues

  • referencing known people, teams, suppliers, customers, stakeholders, locations, events, or business processes
  • using familiar, informal, or over-personal language to reduce scrutiny
  • claiming to have already spoken with someone else inside the organisation
  • presenting the interaction as a normal continuation of an existing relationship
  • using compliments, shared interests, personal details, or common experiences to build rapport quickly

Request and escalation behaviour

  • asking for a small or low-risk action ahead of a more sensitive one
  • increasing the sensitivity, urgency, or impact of requests across a sequence of contacts
  • cultivating a relationship over weeks or months with no early ask, so the eventual request lands against established trust
  • presenting a request as already known, expected, approved, routine, or low-risk
  • routing requests for information, documents, access, introductions, or approvals through informal channels
  • using a relationship claim to sidestep ticketing, identity proofing, approval workflows, or documented verification

Trust-transfer behaviour

  • claiming to be referred by, working with, approved by, acting on behalf of, or following up from a trusted person or organisation
  • borrowing legitimacy from a supplier, partner, event, platform, brand, professional role, community, school, customer group, or stakeholder relationship
  • offering shared context that is mostly accurate but slightly incomplete, outdated, or misapplied
  • framing a challenge to the request as rude, obstructive, or distrustful

Channel and timing indicators

  • starting on one channel and moving the interaction to personal email, SMS, WhatsApp, social media, or phone
  • making contact during busy periods, public events, reception pressure, supplier transitions, onboarding, incidents, or after-hours windows
  • riding an established channel or recurring rhythm, an existing email thread, a recurring-invoice cadence, a known approval routine, so the request inherits the trust of the process rather than the actor
  • continuing contact after hesitation, refusal, or a request for verification