Spear phishing
Spear phishing is a targeted phishing attack aimed at a specific person, department or organization, in which the fraudster uses information gathered about the victim in advance to make the message look as credible as possible. Unlike mass phishing, here precision is everything — the attacker does not cast a wide net over random recipients, but carefully crafts a lure for a single target.
How spear phishing works
The attack begins with reconnaissance: the attacker collects data from social media, the company website, database leaks and public records, learning the organization's structure, colleagues' names and working relationships. On that basis they build a personalized message that:
- impersonates a person or institution the victim knows (a manager, IT department, bank),
- includes real context — a project name, invoices, specific names,
- creates time pressure or emotion to prompt fast action,
- directs the victim to a fake login page or urges them to open an infected attachment.
A special variant is whaling — an attack on high-level individuals (executives, CFOs), where the stakes can be large wire transfers or access to critical systems.
Spear phishing in practice
Spear phishing is one of the most effective ways to breach a company and a frequent precursor to a ransomware infection or data theft. Defense relies on several layers: deploying two-factor authentication, verifying unusual requests through an additional channel, filtering mail, and configuring SPF, DKIM and DMARC to make domain spoofing harder. The most important element, however, remains employee awareness — regular training and simulated attacks significantly lower the risk, because here the human is the primary target.
Powiązane pojęcia
Najczęstsze pytania
How is spear phishing different from ordinary phishing?
Classic phishing is a mass send of the same message to thousands of recipients. Spear phishing is precisely targeted: the attacker personalizes the content for a specific person, using their name, role and real context, which dramatically increases the scam's success rate.
How do you defend against spear phishing?
The keys are two-factor authentication, verifying unusual requests through another channel (such as a phone call), caution toward urgent and emotional messages, and regular team training. Mail filters and SPF, DKIM and DMARC mechanisms that limit domain spoofing also help.
