Cybersecurity glossary

What is Spear Phishing?

Learn what spear phishing is, how attackers research a specific person or role, why personalized lures bypass generic filters and training, and which controls protect high-value mailboxes.

Social engineering and user threatsUpdated August 13, 2026
Also known asTargeted phishingSpear-phishing attackWhaling

Definition

Spear phishing is a targeted phishing attack aimed at a specific individual, role, or organization, using researched personal or business context so the lure looks like a genuine message from a colleague, partner, or service the victim already expects to hear from.

Why personalization beats generic awareness slogans

Spear phishing is what remains after commodity filters and “don’t click unknown links” training have done their job. The attacker already knows the unknown link will look known. They read the org chart, the last conference talk, the vendor list, and the assistant’s name. Then they send one message that could have come from inside the week’s real work.

That investment is rational. A single mailbox with OAuth tokens, VPN access, or wire authority is worth more than ten thousand spray-and-pray clicks. Many intrusion sets and BEC crews treat spear phishing as initial access, not as a standalone scam.

The uncomfortable implication for defenders: a well-written spear phish will sometimes be clicked by a careful person. Controls must assume that, and make the click less profitable.

How attackers build a spear-phishing shot

1

Select a high-yield mailbox

Pick a person whose access, approvals, or relationships justify manual effort—admin, controller, counsel, or executive assistant.

2

Collect usable context

Gather names, tools, travel, invoices, shared customers, and writing style from public profiles and stolen mail.

3

Forge a timely pretext

Attach the lure to something the target already expects: a contract redline, a board deck, a vendor portal, a voicemail.

4

Match sending infrastructure

Use a lookalike domain, a display-name clone, or a compromised partner account that already has thread history.

5

Deliver a quiet payload

Prefer a proxied login, a trusted-looking file host, or a conversation that leads to a later payload once rapport exists.

6

Convert access immediately

Create inbox rules, steal sessions, stage BEC, or move into cloud apps before the victim mentions the odd request.

What “targeted” actually looks like in the inbox

Role-specific documents

Finance receives a revised PO. Legal receives a ‘outside counsel’ portal. Engineering receives a Git host SSO prompt that matches the stack they use.

Relationship hijacking

A real customer or MSP mailbox is abused so the spear phish arrives in an existing thread with authentic prior replies.

Executive and assistant pairing

The assistant is targeted because they handle travel, wires, and calendar links the executive will later trust.

Slow-burn rapport

Some crews send harmless mail first, then a payload after the target has already answered once.

Spear phishing versus mass phishing

DimensionMass phishingSpear phishing
VolumeThousands to millions of similar messagesTens or hundreds, often one mailbox at a time
ResearchBrand templates and stolen email listsOSINT, org charts, and sometimes stolen partner mail
DetectionReputation, content, and kit fingerprints helpUnique domains and narratives evade bulk signatures
Payoff designAny credential is a winA specific access path is the win

Whaling is spear phishing with an executive-shaped target. The technique is the same; the pretext leans on authority, confidentiality, and calendar pressure.

Protecting people who are worth targeting

  • Give executives, finance, legal, IT admins, and their assistants phishing-resistant MFA and extra monitoring, not the same baseline as a generic user.
  • Alert on new inbox rules, forwarding, OAuth grants, and unusual sign-in properties on those mailboxes within minutes.
  • Lock down who can send as, or on behalf of, senior leaders, and review display-name collisions in the directory.
  • Treat unexpected files and SSO prompts that reference a real project as hostile until the request is confirmed on a known-good channel.
  • Reduce public org-chart and tool-stack detail that makes reconnaissance free; train staff that LinkedIn job descriptions are attacker source material.
  • Watch partner and vendor domains: a compromised supplier is a spear-phishing platform aimed at every customer in its sent folder.
  • Run simulations that use realistic internal context—without using real confidential data—and coach on verification, not humiliation.
  • Prepare a ‘clicked anyway’ playbook: session revoke, rule audit, device check, and a finance hold if the target can move money.

Detection is a people-plus-telemetry problem

The first detector is often a colleague who says the tone was slightly off. That report must be cheap to file and fast to act on. Telemetry should already be watching the high-value mailboxes those reports will name. Spear phishing is low volume; missing one message is expected, missing the post-click activity is the preventable failure.

The practical takeaway

Spear phishing is phishing with homework. The sender knows enough about the recipient’s week to survive a careful reading. Filters and generic training still matter for the background noise, but they will not reliably stop a one-off, in-thread, partner-authenticated lure.

Protect the mailboxes worth researching. Bind authentication to real origins. Make verification of unusual requests a normal business habit. Assume the well-aimed message will occasionally land, and make that landing expensive.

Related security terms

Frequently asked questions

What is spear phishing in simple terms?

It is phishing aimed at you specifically. The message mentions your project, boss, vendor, or a file you would plausibly receive, instead of a generic ‘your mailbox is full’ blast.

How is spear phishing different from regular phishing?

Volume and research. Commodity phishing sprays thousands of similar lures. Spear phishing invests time in one mailbox, one role, or one company so the story survives a careful read.

What is whaling?

Whaling is spear phishing aimed at executives and other high-authority targets whose access or approval can move money, data, or policy.

Where do attackers get personal details?

Company websites, LinkedIn, press releases, conference agendas, data broker dumps, previous breaches, and conversations stolen from an already-compromised partner mailbox.

Do email gateways stop spear phishing?

They stop many known kits and bad reputations. A unique lookalike domain, a compromised partner account, or a one-off narrative with no malware often still lands.

Who is usually targeted?

Anyone who can grant access or approve funds: executives, finance, HR, IT admins, legal, and assistants who gatekeep those people. Developers and researchers are targeted for source and cloud access.

If the email came from a real vendor, is it still spear phishing?

Yes, if that vendor mailbox was compromised and then used to send a tailored lure into your thread. Authentication will pass; the targeting is what makes it spear phishing.

References

Explore authoritative guidance and frameworks related to spear phishing.

Explore every security definition

Return to the glossary to search by term, alias, starting letter, or security category.

Browse glossary