Trust exploitation abuses an already-established trusted relationship, identity, or system — a vendor, partner, service provider, colleague, or trusted software channel — to gain access, funds, or data that the target’s own defenses would have blocked from an unknown source. Most security models spend their strength at the perimeter, scrutinizing the stranger. This defeats that by coming from inside the circle of trust: the attacker inherits the credibility of a party the target already trusts, so requests are honored and updates are installed precisely because the source is “known good.”
The mechanism is transitive trust: A trusts B, B is compromised or impersonated, and the attacker rides B’s trust to reach A. It appears at several altitudes. At the human level, a message from a known colleague, vendor contact, or long-standing partner is granted latitude an outsider never would be. At the organizational level, a trusted supplier, managed-service provider, or contractor becomes the conduit — sometimes “island hopping”: breach the smaller, less-defended partner to reach the larger target. At the technical level, the trusted software-update channel is abused so malicious code arrives through a legitimate, signed distribution mechanism.
What makes it so dangerous is that normal detection is inverted: the very signals used to grant trust — a known sender, a signed update, an established account — are the signals the attack rides in on. Defense cannot rest on “is this source known?” but must shift to “is this request verified — even from a known source?”