Cybersecurity glossary
What is Spear Phishing?
Learn what spear phishing is, how attackers research a specific person or role, why personalized lures bypass generic filters and training, and which controls protect high-value mailboxes.
Definition
Spear phishing is a targeted phishing attack aimed at a specific individual, role, or organization, using researched personal or business context so the lure looks like a genuine message from a colleague, partner, or service the victim already expects to hear from.
Why personalization beats generic awareness slogans
Spear phishing is what remains after commodity filters and “don’t click unknown links” training have done their job. The attacker already knows the unknown link will look known. They read the org chart, the last conference talk, the vendor list, and the assistant’s name. Then they send one message that could have come from inside the week’s real work.
That investment is rational. A single mailbox with OAuth tokens, VPN access, or wire authority is worth more than ten thousand spray-and-pray clicks. Many intrusion sets and BEC crews treat spear phishing as initial access, not as a standalone scam.
The uncomfortable implication for defenders: a well-written spear phish will sometimes be clicked by a careful person. Controls must assume that, and make the click less profitable.
How attackers build a spear-phishing shot
Select a high-yield mailbox
Pick a person whose access, approvals, or relationships justify manual effort—admin, controller, counsel, or executive assistant.
Collect usable context
Gather names, tools, travel, invoices, shared customers, and writing style from public profiles and stolen mail.
Forge a timely pretext
Attach the lure to something the target already expects: a contract redline, a board deck, a vendor portal, a voicemail.
Match sending infrastructure
Use a lookalike domain, a display-name clone, or a compromised partner account that already has thread history.
Deliver a quiet payload
Prefer a proxied login, a trusted-looking file host, or a conversation that leads to a later payload once rapport exists.
Convert access immediately
Create inbox rules, steal sessions, stage BEC, or move into cloud apps before the victim mentions the odd request.
What “targeted” actually looks like in the inbox
Role-specific documents
Finance receives a revised PO. Legal receives a ‘outside counsel’ portal. Engineering receives a Git host SSO prompt that matches the stack they use.
Relationship hijacking
A real customer or MSP mailbox is abused so the spear phish arrives in an existing thread with authentic prior replies.
Executive and assistant pairing
The assistant is targeted because they handle travel, wires, and calendar links the executive will later trust.
Slow-burn rapport
Some crews send harmless mail first, then a payload after the target has already answered once.
Spear phishing versus mass phishing
| Dimension | Mass phishing | Spear phishing |
|---|---|---|
| Volume | Thousands to millions of similar messages | Tens or hundreds, often one mailbox at a time |
| Research | Brand templates and stolen email lists | OSINT, org charts, and sometimes stolen partner mail |
| Detection | Reputation, content, and kit fingerprints help | Unique domains and narratives evade bulk signatures |
| Payoff design | Any credential is a win | A specific access path is the win |
Whaling is spear phishing with an executive-shaped target. The technique is the same; the pretext leans on authority, confidentiality, and calendar pressure.
Protecting people who are worth targeting
- Give executives, finance, legal, IT admins, and their assistants phishing-resistant MFA and extra monitoring, not the same baseline as a generic user.
- Alert on new inbox rules, forwarding, OAuth grants, and unusual sign-in properties on those mailboxes within minutes.
- Lock down who can send as, or on behalf of, senior leaders, and review display-name collisions in the directory.
- Treat unexpected files and SSO prompts that reference a real project as hostile until the request is confirmed on a known-good channel.
- Reduce public org-chart and tool-stack detail that makes reconnaissance free; train staff that LinkedIn job descriptions are attacker source material.
- Watch partner and vendor domains: a compromised supplier is a spear-phishing platform aimed at every customer in its sent folder.
- Run simulations that use realistic internal context—without using real confidential data—and coach on verification, not humiliation.
- Prepare a ‘clicked anyway’ playbook: session revoke, rule audit, device check, and a finance hold if the target can move money.
Detection is a people-plus-telemetry problem
The first detector is often a colleague who says the tone was slightly off. That report must be cheap to file and fast to act on. Telemetry should already be watching the high-value mailboxes those reports will name. Spear phishing is low volume; missing one message is expected, missing the post-click activity is the preventable failure.
The practical takeaway
Spear phishing is phishing with homework. The sender knows enough about the recipient’s week to survive a careful reading. Filters and generic training still matter for the background noise, but they will not reliably stop a one-off, in-thread, partner-authenticated lure.
Protect the mailboxes worth researching. Bind authentication to real origins. Make verification of unusual requests a normal business habit. Assume the well-aimed message will occasionally land, and make that landing expensive.
Related security terms
Phishing
The broader lure class; spear phishing is the researched, low-volume variant.
Business Email Compromise (BEC)
Spear phishing often compromises or impersonates the mailboxes that later drive payment fraud.
Pretexting
The invented context—shared project, travel, legal matter—that makes the targeted message feel expected.
Social Engineering
Spear phishing is social engineering with an email delivery layer and an OSINT homework assignment.
Typosquatting
Lookalike domains frequently host the landing page or sending infrastructure for a named-target campaign.
Frequently asked questions
What is spear phishing in simple terms?
It is phishing aimed at you specifically. The message mentions your project, boss, vendor, or a file you would plausibly receive, instead of a generic ‘your mailbox is full’ blast.
How is spear phishing different from regular phishing?
Volume and research. Commodity phishing sprays thousands of similar lures. Spear phishing invests time in one mailbox, one role, or one company so the story survives a careful read.
What is whaling?
Whaling is spear phishing aimed at executives and other high-authority targets whose access or approval can move money, data, or policy.
Where do attackers get personal details?
Company websites, LinkedIn, press releases, conference agendas, data broker dumps, previous breaches, and conversations stolen from an already-compromised partner mailbox.
Do email gateways stop spear phishing?
They stop many known kits and bad reputations. A unique lookalike domain, a compromised partner account, or a one-off narrative with no malware often still lands.
Who is usually targeted?
Anyone who can grant access or approve funds: executives, finance, HR, IT admins, legal, and assistants who gatekeep those people. Developers and researchers are targeted for source and cloud access.
If the email came from a real vendor, is it still spear phishing?
Yes, if that vendor mailbox was compromised and then used to send a tailored lure into your thread. Authentication will pass; the targeting is what makes it spear phishing.
References
Explore authoritative guidance and frameworks related to spear phishing.
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.