Cybersecurity Glossary

What is Spear Phishing?

Spear phishing is a targeted phishing attack against selected people or teams. The message incorporates their role, contacts or current work and is therefore more credible than a widely distributed template. It may arrive through email, messaging, a professional network or a combination with telephone calls.

How does spear phishing differ from phishing?

CharacteristicBroad phishingSpear phishing
RecipientsMany random recipients or large lists.A selected person, role or organization.
ContentGeneric pretext.Personal context, real projects or relationships.
EffortLow and highly automated.More research and preparation.
ObjectiveOften as many logins or payments as possible.A particular access path, process, dataset or decision-maker.

An attack against senior executives or particularly influential people is often called whaling. Business email compromise describes the objective or abuse of a business mail process more than the delivery method; spear phishing may be the path into it.

How is an attack prepared?

Attackers collect information from corporate sites, social networks, job listings, leaks and public documents. They register lookalike domains or compromise a real mailbox. They then select a plausible moment, such as travel, an ongoing transaction, a new manager or a known IT migration. Replies inside a compromised mail thread are especially convincing because sender, signature and previous context match.

What do attackers want?

  • Credentials or MFA approval for cloud, VPN and corporate applications.
  • Opening a prepared document, archive or link that installs malware.
  • A transfer, changed bank details or gift-card purchase.
  • Disclosure of confidential documents, personal or project data.
  • A longer relationship through which a more valuable action can be requested later.

How can spear phishing be recognized?

Personalization is not proof of authenticity. Warning signs include a new sender domain, different reply address, unexpected file share and suddenly changed payment or recovery instructions. The combination of urgency, secrecy and a request to skip an established control is particularly concerning. Confirm through a known phone number, existing ticket system or in person, not through details in the same message.

Which controls provide protection?

  • Phishing-resistant MFA such as FIDO2/WebAuthn limits the value of stolen passwords.
  • SPF, DKIM and DMARC reduce some forgery of the real domain; lookalike domains need monitoring as well.
  • Dual approval and independent callback protect payments and master-data changes.
  • Least privilege, secure endpoints and separate administration accounts contain impact.
  • Role-specific exercises prepare highly exposed teams such as finance, assistants, HR and IT support.

What should happen after interaction?

Report the message with headers and timestamp immediately. After password entry, revoke sessions and tokens, replace password and MFA, and inspect mailbox rules and account activity. If a file was opened, isolate and investigate the device. For a payment, every minute matters: contact the bank and internal owners immediately. The security team should also find other recipients and messages from the campaign.

Penetration Tests

Uncover Security Vulnerabilities

Professional penetration testing for your business

Web Apps
Networks
Mobile Apps
10% New Customer Discount
Plan Now

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on Spear Phishing? Tell us!