SardineCon SF/2026

Learn More

What is Spear phishing?

SUBSCRIBE

Spear phishing is targeted phishing aimed at a specific person or role, built from real details about them so the message looks credible. Unlike mass phishing blasts, it does the homework first, which is why it so often gets finance staff and admins to pay or hand over access.

What is spear phishing, in plain English?

Spear phishing is phishing that has been tailored to one target. Instead of a generic message sent to millions, the attacker researches a specific person or role and builds a message that fits their world: the right manager's name, a real project, a genuine vendor, the tone of a colleague. That context is what makes it work; the message reads like something the target was already expecting.

The aim is almost always access or money. Common targets are finance staff who can move funds, administrators who hold privileged accounts, and executives whose approval unlocks big payments. Spear phishing is the usual first move in business email compromise, where a well-crafted message convinces someone to wire money or share credentials.

The tells are subtle by design: highly relevant detail, a spoofed or lookalike sender domain that is one character off, and a request for a payment, a login, or a code. Because it is low-volume and personalized, generic spam filters often let it through, which is why it lands where broad phishing would be caught.

How a spear phishing attack unfolds

  1. Recon — Pick and profile a target. The attacker studies a named person: their role, their boss, their vendors, their current projects.
  2. Spoof — Set up a credible sender. They register a lookalike domain or spoof a known address so the message appears to come from a trusted colleague or supplier.
  3. Lure — Send a tailored request. The message references real context and asks for a payment, a credential, or a document, framed as routine and time-sensitive.
  4. Exploit — Collect the payoff. The target pays the fake invoice or enters credentials, handing over money or a foothold for deeper compromise.

Spear phishing versus mass phishing

What changes

Mass phishing

Spear phishing

Targeting

Sent to huge lists, no personalization

Aimed at one named person or role

Detail

Generic greeting and story

Real names, projects, and vendors

Volume

High, easy for filters to catch

Low, often slips past spam filters

Payoff

Small individual hits at scale

Large single payments or key access

What it looks like in practice

In practice

A finance analyst gets an email that appears to come from a supplier the company really uses, referencing an open purchase order by number and noting the supplier has changed banks. It asks that the next payment go to new account details, attached on a clean-looking form.

The domain is a near-perfect lookalike, one letter swapped, and the invoice matches a real order the attacker learned about from a compromised inbox. The analyst updates the payee, and the next scheduled payment lands in the fraudster's account instead of the supplier's.

Why it matters to operators

Spear phishing is the human on-ramp to some of the most expensive fraud you will see: business email compromise, vendor payment diversion, and privileged account takeover. Because the message is targeted and low-volume, you cannot rely on volume-based spam defenses. The failure point is a person making a reasonable-looking decision, so the money movement is often the first hard signal.

That pushes weight onto payment controls and change verification: independent callback on bank-detail changes, dual approval on large or first-time payees, and email authentication to make spoofing harder. Role-based awareness matters too, because the people targeted, finance and admins, are a small, knowable group you can train and protect directly.

What to watch for

  • Bank-detail changes. A supplier or payee suddenly changing account details, especially just before a scheduled payment.
  • Lookalike domains. Sender addresses one character off from a real colleague or vendor domain.
  • Urgent, quiet requests. Pressure to act fast and keep it between the two parties, discouraging a second check.
  • Role targeting. Repeated attempts aimed at finance, payroll, or admin staff who can move money or grant access.
  • Reply-to mismatch. A display name that matches a known person but a reply address that routes somewhere else.

Quick questions

How is spear phishing different from phishing?

Regular phishing is a mass, generic blast. Spear phishing is researched and personalized for a specific target, which makes it far more convincing and much harder for filters to catch.

How is it different from whaling?

Whaling is spear phishing aimed specifically at senior executives. It is the same technique, but the target is chosen for the size of the payoff their authority unlocks.

Why is it linked to business email compromise?

Spear phishing is usually how BEC starts. A tailored message convinces finance staff to pay a fake invoice or to hand over credentials that let the attacker take over a real inbox.

Do spam filters stop it?

Often not. It is low-volume and personalized, so it lacks the patterns that mass-spam filters key on. Email authentication and payment verification catch more of it than content filtering alone.

What is the best single control?

Independent verification of any payment or bank-detail change through a known, separate channel. A callback to a trusted number defeats most spear phishing even when the email is convincing.

Can attackers fake a real internal address?

Yes, through spoofing or by compromising a real account. That is why display names and even genuine-looking addresses should not be trusted for sensitive requests without a second check.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

What to know alongside Spear phishing