What Is Spear Phishing? How Targeted Attacks Work and How to Defend Against Them

If regular phishing is casting a wide net, spear phishing is hunting with a rifle. Instead of sending millions of generic emails and waiting for the statistically likely fraction to bite, spear phishing targets a specific individual — and the attacker knows enough about that individual to make their message nearly impossible to distinguish from a legitimate communication.

Spear phishing is responsible for 91% of successful data breaches according to security research firm Trend Micro, and it’s the technique behind some of the most damaging cyberattacks in history — including the 2016 Democratic National Committee breach, the 2020 SolarWinds attack, and countless corporate espionage operations. It is not just a consumer problem. It is a national security problem.

What Is Spear Phishing?

Spear phishing is a highly targeted form of phishing in which the attacker customizes their attack to a specific individual or organization using personalized information gathered through research.

Where generic phishing says “Dear Customer,” spear phishing says “Hi Jennifer — I saw from your LinkedIn that you just joined the finance team at Meridian Corp. I’m sending over the updated vendor payment instructions per our conversation with Mark last week.”

The difference in believability is enormous. And the consequences of falling for it can be catastrophic — corporate credentials, access to financial systems, confidential documents, or large unauthorized wire transfers.

How Spear Phishing Attacks Are Constructed

Phase 1: Reconnaissance.

The attacker researches the target. LinkedIn reveals their employer, job title, colleagues, and professional history. Facebook and Instagram show their personal life, relationships, and interests. Twitter and other public profiles provide recent activities. Company websites reveal organizational structure and key personnel. Data broker sites provide home addresses, phone numbers, and family members’ names. This research phase can last days or weeks for high-value targets.

Phase 2: Building the lure.

Using what they’ve learned, the attacker crafts a message that appears to come from someone the target knows — a colleague, a vendor, a manager, an IT department — and references real, verifiable details. The message contains a call to action: click a link, download a document, approve a wire transfer, provide login credentials.

Phase 3: Domain spoofing and account takeover.

To make the message appear legitimate, attackers often register “lookalike” domains (meridiancoorp.com instead of meridiancoorp.com), compromise a legitimate email account to send from, or use sophisticated email spoofing techniques that make the sender address appear genuine.

Phase 4: The payload.

The victim clicks the link, downloads the document, or provides the requested information. The attacker achieves their goal — credential capture, malware installation, or financial fraud — often without the victim realizing anything happened.

Spear Phishing vs. Phishing — What’s the Difference?

Regular phishing:

– Targets anyone who receives the message

– Generic, mass-produced content

– Low effort per target, high volume

– Relies on statistical probability — some small percentage will click

Spear phishing:

– Targets a specific, researched individual or organization

– Highly personalized content referencing real details

– High effort per target, low volume

– Relies on believability — the target has no generic warning signs to recognize

The practical implication: the warning signs of generic phishing (generic greeting, wrong sender domain, obvious fake branding) often do not apply to spear phishing. A spear phishing email may have the correct sender name, reference real colleagues and real projects, and arrive at exactly the right moment to feel legitimate.

Real-World Examples of Spear Phishing

Business Email Compromise (BEC)

The most financially damaging category of spear phishing. An attacker compromises or spoofs the email address of a CEO, CFO, or vendor, then sends a message to the finance team authorizing a large wire transfer to a fraudulent account. The FBI reports that BEC scams caused $2.9 billion in losses in 2023 — more than any other category of internet crime.

The IT Credential Harvest

An employee receives an email that appears to be from their company’s IT department asking them to verify their Microsoft 365 login due to a security update. The email references their real company name, the real IT department head’s name, and uses the company’s actual email signature template. The link leads to a fake M365 login page.

The Invoice Fraud

A company’s accounts payable department receives an email from what appears to be a regular vendor, noting that their bank account information has changed and asking all future payments be directed to a new account. The email uses the vendor’s real name, real email format, and references real recent invoices.

The HR Phishing Attack

An employee receives an email appearing to be from HR, requesting they update their direct deposit information through a secure portal before the next payroll cycle. The link leads to a credential-harvesting page.

Spear Phishing Targeting Individuals (Not Just Businesses)

Spear phishing isn’t limited to corporate targets. Individual consumers are also targeted — particularly:

– People going through real estate transactions (fake wire transfer instructions impersonating their title company or real estate agent)

– People applying for jobs (fake onboarding documents or credential requests from fake employers)

– People whose personal information was recently exposed in a data breach

– High-net-worth individuals targeted for investment fraud

– People who have recently been in the news or posted significant life events on social media

How to Protect Yourself From Spear Phishing

Verify unexpected requests through a separate channel.

If you receive an email asking you to do something unusual — approve a payment, click a link, provide credentials, share sensitive information — verify the request by calling the supposed sender at a known number (not a number provided in the email itself).

Be skeptical of unexpected urgency.

Even from people you know, requests framed with unusual urgency (“I need this done today before the end of business — don’t forward this to anyone”) are a red flag. Legitimate business urgency rarely requires bypassing normal verification.

Think before you post.

The information attackers use for spear phishing reconnaissance often comes from public social media profiles. Be thoughtful about what you publish — your employer, your colleagues’ names, your travel schedule, your financial situation.

Use email authentication tools.

If you manage email for a business, implement DMARC, DKIM, and SPF records on your domain. These technical controls significantly reduce the ability of attackers to spoof your domain.

Train employees.

For businesses, regular spear phishing simulation and awareness training significantly reduces click rates. Staff who have experienced a simulated spear phishing attack are substantially less likely to fall for a real one.

Frequently Asked Questions

Q: Is spear phishing the same as whaling?

A: Whaling is a specific subcategory of spear phishing that targets senior executives (CEOs, CFOs, board members). All whaling is spear phishing, but not all spear phishing is whaling.

Q: How do I know if I’ve been spear phished?

A: Signs include unauthorized access to your accounts, unfamiliar transactions, colleagues receiving unusual emails from your account, or your IT department alerting you to suspicious login activity. In many cases, victims don’t know until the damage has been done — which is why proactive verification habits are essential.

Q: Can spam filters catch spear phishing?

A: Standard spam filters are significantly less effective against spear phishing than against mass phishing, because spear phishing messages are personalized, sent in low volumes, and often originate from legitimate or convincingly spoofed addresses. Advanced enterprise email security tools (like Microsoft Defender for Office 365 or Proofpoint) are better equipped to detect targeted attacks.

→ Back to Pillar: https://www.scammed.org/phishing/

→ See also: https://www.scammed.org/phishing/whaling/