What is Spear Phishing?
Spear phishing is a targeted social engineering attack in which an attacker researches a specific person or organization and crafts a deceptive message designed to trick that individual into revealing credentials, transferring funds, or installing malware. Unlike bulk phishing, every detail is chosen to appear credible to the recipient.
What it is
Spear phishing is a precision attack. The attacker collects information about the target first: their job title, colleagues' names, recent projects, the tools they use, or their writing style. That research feeds a message that looks legitimate to the specific recipient.
Common delivery channels include email, but also SMS (smishing), voice calls (vishing), and messaging apps. The message typically asks the target to click a link, open an attachment, approve a payment, or hand over login credentials.
A spear phishing message aimed at a finance director might impersonate the CEO and reference a real acquisition rumor. One aimed at an IT administrator might mimic a vendor ticket about a system the team actually runs. The specificity is what separates it from generic phishing.
Why it matters
Generic phishing casts a wide net and relies on volume. Spear phishing trades volume for accuracy. Because the message fits the target's context, it bypasses the instincts that catch obvious scams.
Spear phishing is the entry point for many serious breaches. Business email compromise (BEC), ransomware deployments, and credential theft campaigns frequently start with a single well-crafted message to one person. The cost of a successful attack can far exceed the cost of prevention.
Executives, finance staff, IT administrators, and anyone with access to sensitive systems or large transfers are common targets.
How tools address it
No tool stops spear phishing at the source, but several categories reduce the risk:
- Phishing simulation platforms (such as those in the Phishing Simulation category) send realistic, targeted test messages to employees, including role-specific scenarios that mimic spear phishing tactics. They measure who clicks, who reports, and who needs more training.
- teaches employees to recognize the signs: urgency, unusual sender addresses, requests that bypass normal process, and mismatched links.