(518) 292-4500|sales@logical.net|M-F 8am-5pm ยท 24/7 SOC
MSP 501 Winner 2025Client Portal โ†’
Threats & Attacks

What is Spear Phishing?

Spear phishing is a highly targeted form of phishing aimed at specific individuals or small groups.

How Spear Phishing works

Three-step view of how it operates in practice.

  • Reconnaissance. The attacker studies LinkedIn, public press, your website, and social media to build a profile of the target and their relationships.
  • Pretext. A plausible scenario is crafted, a referenced meeting, a mutual contact, a project in flight. The pretext is what makes the message believable.
  • Execute. The message arrives with a link to a credential-harvesting site, a malicious attachment, or a fraudulent request for action.

Why Spear Phishing matters

Spear phishing is how capable attackers open doors at organizations of every size, a bookkeeper at a fifty-person firm is targeted with the same craft as a Fortune 500 controller, because the wire clears either way. Since the message may be technically flawless, the durable defense is procedural: a standing rule that money movement and credential requests get verified through a second channel, every time, with no exception for apparent seniority.

Bulk phishing vs spear phishing vs whaling vs BEC

  • Bulk phishing. Generic lures blasted to enormous lists, playing pure odds. Crude, but it establishes the baseline every filter is tuned against.
  • Spear phishing. One target, researched: the message references your actual vendor, your project, your colleague's name. The research is the weapon.
  • Whaling. Spear phishing aimed at the biggest fish โ€” owners, executives, board members, whose accounts and authority unlock the most. Lures skew to lawsuits, deals, and confidential matters.
  • BEC. The endgame the others enable: impersonation or a hijacked mailbox converted into fraudulent payments. Spear phishing is often how the attacker first gets the access BEC monetizes.

Common Spear Phishing mistakes

  • Trusting filters against bespoke attacks. A hand-written message from a clean domain with no malware attached gives scanning engines almost nothing to flag. Against spear phishing, verification habits and a suspicious-by-default culture do the work technology can't.
  • Feeding the reconnaissance. Org charts, vendor announcements, travel posts, and detailed job listings hand attackers their pretext material. Audit what your organization publishes about who does what โ€” especially in finance, and trim what serves no business purpose.
  • Training only on generic examples. Staff who ace simulations full of fake shipping notices still fall for a message naming their real manager and a real project. Include targeted, personalized scenarios in awareness testing, and brief high-risk roles on what's public about them.
Related terms

Need this in your environment?

We turn these controls on for Capital Region organizations every day. Let's talk about yours.