How Spear Phishing works
Three-step view of how it operates in practice.
- Reconnaissance. The attacker studies LinkedIn, public press, your website, and social media to build a profile of the target and their relationships.
- Pretext. A plausible scenario is crafted, a referenced meeting, a mutual contact, a project in flight. The pretext is what makes the message believable.
- Execute. The message arrives with a link to a credential-harvesting site, a malicious attachment, or a fraudulent request for action.
Why Spear Phishing matters
Spear phishing is how capable attackers open doors at organizations of every size, a bookkeeper at a fifty-person firm is targeted with the same craft as a Fortune 500 controller, because the wire clears either way. Since the message may be technically flawless, the durable defense is procedural: a standing rule that money movement and credential requests get verified through a second channel, every time, with no exception for apparent seniority.
Bulk phishing vs spear phishing vs whaling vs BEC
- Bulk phishing. Generic lures blasted to enormous lists, playing pure odds. Crude, but it establishes the baseline every filter is tuned against.
- Spear phishing. One target, researched: the message references your actual vendor, your project, your colleague's name. The research is the weapon.
- Whaling. Spear phishing aimed at the biggest fish โ owners, executives, board members, whose accounts and authority unlock the most. Lures skew to lawsuits, deals, and confidential matters.
- BEC. The endgame the others enable: impersonation or a hijacked mailbox converted into fraudulent payments. Spear phishing is often how the attacker first gets the access BEC monetizes.
Common Spear Phishing mistakes
- Trusting filters against bespoke attacks. A hand-written message from a clean domain with no malware attached gives scanning engines almost nothing to flag. Against spear phishing, verification habits and a suspicious-by-default culture do the work technology can't.
- Feeding the reconnaissance. Org charts, vendor announcements, travel posts, and detailed job listings hand attackers their pretext material. Audit what your organization publishes about who does what โ especially in finance, and trim what serves no business purpose.
- Training only on generic examples. Staff who ace simulations full of fake shipping notices still fall for a message naming their real manager and a real project. Include targeted, personalized scenarios in awareness testing, and brief high-risk roles on what's public about them.