How spear phishing differs from mass phishing, which roles attackers target, and the one verification habit that stops most attempts.
Most phishing is untargeted: one message sent to millions, fishing for the small fraction who click. Spear phishing is the opposite — a single message aimed at one person, built from real details about them.
The trade works. Spear phishing is less than 0.1 percent of the phishing email sent, but it is behind more than 65 percent of successful attacks. Precision beats volume.
What makes it different
A generic phishing email impersonates a well-known brand and relies on probability. A spear phishing email names your manager, references the project you are actually working on, and asks for something that fits your job. That specificity is the attack. When a message appears to come from someone you know and mentions something real, the instinct to check it carefully is much weaker.
Where the details come from
Attackers rarely need privileged access. LinkedIn supplies job titles and reporting lines. Company sites and press releases supply acquisitions, launches, and leadership names. Social media adds travel and personal context. Old data breaches supply addresses and phone numbers — you can check if your email address is in a data breach free. The research usually takes longer than writing the email does.
Who gets targeted
- Finance and accounts payable — invoice and payment-detail changes, often called business email compromise.
- Executives and their assistants — urgent wire transfers or gift-card requests. See CEO fraud and whaling prevention.
- IT and helpdesk staff — credentials that unlock systems and other people's accounts.
- New employees — still learning what a normal request looks like.
- Anyone with vendor relationships — impersonating a supplier the target already trusts.
Why it works
This is not primarily a technology problem. Most spear phishing carries no malicious attachment or link for a filter to catch; it is plain text making a plausible request. It works by exploiting familiarity (a known sender lowers scrutiny), authority (few people push back on the CEO), and urgency (a deadline compresses the time available to think).
How to defend
Verify unusual requests on a second channel. Anything involving money, credentials, or sensitive data gets a phone call to a number you already have — never a reply to the email. This single habit defeats most attempts.
Then make it routine rather than rude: write policies that require out-of-band confirmation for wire transfers, payroll data requests, and credential changes. Review what your organisation publishes publicly too — not to hide everything, but so employees understand why a stranger might know their manager's name. Implement SPF, DKIM, and DMARC so your domain is harder to spoof — you can run a free email spoof test on your domain to see whether all three are already published. And run spear phishing simulations for your high-risk groups — generic simulations prepare people for volume attacks, not targeted ones.
The AI shift
AI has removed most of the effort. Research is automated, and AI-generated messages are grammatically clean and tonally right. The old tells — typos, generic greetings, awkward phrasing — are gone. Training that still teaches those signals is preparing people for the wrong attack. The durable defence is behavioural: verification habits that do not depend on spotting a mistake.
Related Learning
More Learning Resources
View all learning resourcesBusiness Email Compromise (BEC) Explained
Learn what Business Email Compromise (BEC) is, how these sophisticated financial scams work, and the strategies organizations can use to defend against them.
Quick Guide: Phishing Simulation Frequency
How often to run phishing simulations, what changes at each cadence, and the scheduling mistakes that make results meaningless.
What Is Phishing Awareness Training?
How phishing awareness training differs from simulation, what separates programmes that change behaviour from ones that do not, and the metrics worth tracking.
Ready to stop phishing attacks?
Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.