Glossary
Spear phishing is a targeted form of phishing aimed at a specific individual or organization, using personal or contextual details to make the deception far more convincing than mass phishing. Where ordinary phishing casts a wide, generic net, spear phishing is a precision attack researched and crafted for its target.
The personalization is what makes spear phishing so dangerous. A message that references your name, role, recent activity, colleagues, or a real pending transaction is enormously more believable than a generic "your account is locked" blast.
The attacker first researches the target (from social media, data breaches, company websites, and prior breaches) to gather details that lend credibility. They then craft a tailored message impersonating a trusted party (a manager, a known vendor, the target’s bank) and referencing specifics only a legitimate sender would seem to know. The request is plausible in context: approve this invoice, review this document, reset this credential. Because it fits the target’s world, it slips past the skepticism a generic phish would trigger.
Two high-value variants deserve mention. Whaling targets senior executives, whose access and authority make them lucrative. Business email compromise (BEC) impersonates an executive or vendor to trick an employee into authorizing a fraudulent payment or sharing sensitive data, one of the costliest forms of corporate fraud, precisely because it exploits trust and authority rather than any technical flaw.
Because spear phishing is so convincing, human vigilance alone is unreliable, and generative AI now makes tailored, flawless messages trivial to produce at scale, erasing the old tells. The durable defenses are technical and procedural: phishing-resistant authentication (passkeys) so stolen credentials are worthless, strong out-of-band verification for sensitive requests like payments (never authorize based on an email alone), email authentication and filtering, and behavioral monitoring to catch the downstream signs of a successful attack. Reducing what a successful spear phish can achieve matters more than hoping every target spots every con.
Mass phishing relies on volume: send a million generic messages, and a fraction will bite. Spear phishing relies on precision, and that changes the success math entirely. A generic "your account is locked" email is easy to dismiss; a message that names your manager, references a real project, and arrives at a plausible moment is not. By investing in research, the attacker trades quantity for a dramatically higher hit rate against high-value targets. This is also why spear phishing is the preferred approach for serious, targeted breaches and for business email compromise: when the payoff is large (access to a corporate network, a fraudulent wire transfer) the extra effort of personalization is well worth it. The uncomfortable implication is that the better your defenses against mass phishing, the more attackers shift to the targeted, personalized version that generic filters and generic training don’t catch.
Why is spear phishing more effective than mass phishing?
Personalization and context dramatically raise the hit rate, which is why it’s favored for targeted breaches and business email compromise.
What is spear phishing?
A targeted phishing attack tailored to a specific individual using personal details to make it highly convincing.
How is spear phishing different from regular phishing?
Regular phishing is generic and mass-sent; spear phishing is researched and personalized for a specific target.
What is business email compromise?
A spear-phishing variant impersonating an executive or vendor to trick an employee into authorizing payments or sharing data.
How do you defend against spear phishing?
Phishing-resistant authentication, out-of-band verification for sensitive requests, email filtering, and behavioral monitoring.
Related: Phishing · Social Engineering · Smishing & Vishing · Passkeys · Account Takeover (ATO)