Trust
In plain terms
What reaches you looks like what you know: the name of someone close, your bank's logo, an almost exact address. The resemblance stands in for proof.
Definition
Trust is the exploitation of the signs by which we usually recognize who we are dealing with — display name, visual identity, address, conversation history — signs that can all be reproduced.
Why it works
We almost never authenticate: we recognize. It is a necessary shortcut, since checking every message would be impractical, and it works because most messages are genuine. The attacker breaks nothing: they manufacture the signs of recognition. A sender name is a free-text field, a text message label can be chosen, a caller's number can be spoofed, a profile photo can be copied. The hardest case is when the trust is real — a genuine account that has been compromised — because then no sign is false.
What resists it
Check the channel rather than the content: take another route. Calling a number you already had, opening the official app, using a bookmark — these steps need no expertise and work even when the message is perfectly imitated.
The question to ask yourself
“Do I recognize this person, or only the signs that point to them?”
The 68 attacks that exploit it
- "Sign in with" permission abuse
- Malicious chatbot
- Malicious app
- Investment scam
- Rental scam
- Classified ad scam
- Romance scam
- Bluetooth attack
- Man-in-the-Middle Attack
- Brute-force attack
- Homoglyph attack
- Overlay attack
- Botnet
- Credential stuffing
- Compromised router or gateway
- Hacked security camera
- Trojan Horse
- Voice cloning
- Deepfake video call
- Deepfake video
- Account recovery hijacking
- Browser hijacking
- Session hijacking
- SIM swapping
- DNS Poisoning
- Keylogger
- Personal data exposure
- Malicious browser extension
- Fake AI app
- Fake invoice
- Fake browser update
- Evil Twin Wi-Fi Hotspot
- AI-generated fake profile
- AI-generated fake news site
- Fake website
- Fake download
- Fake bank details change
- ID document fraud
- Data breach
- AI-generated phishing
- Infostealer (credential-stealing malware)
- Network Traffic Interception
- Juice jacking (rigged charging station)
- Spyware
- Data scraping
- Compromised smart device
- Excessive permissions
- Social media account takeover
- Email account takeover
- Malicious Captive Portal
- Pretexting (fabricated scenario)
- Malvertising
- Password spraying
- Quishing (fraudulent QR code)
- Re-identification of anonymous data
- Resale of personal data
- Rootkit
- Stalkerware (surveillance by someone close to you)
- Tabnabbing (swapped tab)
- Tracker stalking
- Abusive ad tracking
- Typosquatting
- ARP Spoofing
- Identity impersonation
- Impersonating a relative by message
- Social media profile impersonation
- Computer Virus
- Vishing (voice phishing)
Other levers · Last updated: 2026-09-02.