What is spear phishing?

    Spear phishing is a targeted phishing attack built for a particular person, role or organization. Instead of sending the same generic lure widely, the attacker uses relevant names, relationships, projects or business processes to make a request appear expected.

    8 min readUpdated September 20, 2026

    Spear phishing vs phishing

    Broad phishing optimizes for scale. A campaign may imitate a bank or delivery company and send thousands of nearly identical messages. Spear phishing optimizes for credibility. The attacker chooses a target, learns the context and writes a message that fits the target's work or personal life.

    The technical destination may be ordinary: a fake Microsoft 365 page, a malicious document or a reply address controlled by the attacker. What makes it spear phishing is the targeting. A message that names a current supplier, references a real conference or appears to continue an existing project is more difficult to dismiss than a generic account alert.

    Spear phishing often overlaps with business email compromise. An attacker may compromise one mailbox, study a conversation and send an invoice or bank-detail change at the moment it is most believable. The message can pass normal email authentication because it comes from a real account.

    What is whaling?

    Whaling is spear phishing aimed at senior executives or other people with valuable authority, information or access. A “whale phishing” message may target a chief executive, finance leader, board member, legal counsel or system administrator.

    The objective is not always the executive's own password. The attacker may impersonate that executive to pressure another employee into releasing payroll data, changing payment instructions or bypassing a normal approval. Defenses therefore need to protect business processes as well as inboxes.

    How attackers research their targets

    Public company pages, professional profiles, press releases, conference agendas, job advertisements and social posts reveal reporting lines, technology, suppliers and travel. Breached data can add private email addresses or reused passwords. Domain records and certificate transparency logs reveal systems and lookalike opportunities.

    Attackers also learn from previous contact. A harmless-looking inquiry can reveal who approves invoices or which file-sharing service a team uses. Compromised mailboxes provide signatures, writing style and live conversation threads. This is why a message containing accurate details is not necessarily authentic.

    Reduce unnecessary exposure, but do not rely on secrecy alone. Build verification into sensitive actions: payment changes, password resets, data exports and remote-access requests should require a separate trusted confirmation.

    Why spear phishing gets past filters

    Filters are effective against known malicious attachments, high-volume senders and previously reported URLs. A targeted message may use a newly registered domain, a reputable cloud service, a clean link that becomes malicious later, or no link at all. Low volume avoids reputation signals.

    A compromised account can pass SPF, DKIM and DMARC. A conversation hijack may quote genuine earlier messages. Generative tools can remove spelling mistakes and mimic tone. Technical controls remain important, but they cannot decide whether a real-looking request makes sense in its business context.

    People need a low-friction way to challenge unusual requests. A culture that punishes delays or questions makes social engineering easier. A short independent verification is a control, not an obstacle.

    What companies can do

    • Require out-of-band verification for bank-detail, payroll and account-recovery changes.
    • Use phishing-resistant multi-factor authentication where possible.
    • Protect email domains with SPF, DKIM and DMARC, while recognizing that these controls do not stop compromised trusted accounts.
    • Limit access and payment authority so one compromised account cannot complete a high-risk action.
    • Give staff a simple reporting route and preserve original messages for investigation.
    • Monitor lookalike domains and remove confirmed impersonation infrastructure through documented abuse channels.

    Security teams that need managed monitoring, evidence preservation and takedown coordination can review Fraudpol's plans.

    For the broader foundation, read what phishing is.

    Phishing cases we have neutralized

    These records come from Fraudpol's public case data. Domains are defanged so they cannot be opened by accident, and retrospectively entered cases are excluded from elapsed-time figures.

    No matching public case records are available right now.

    View all confirmed cases

    Have a URL to report right now?

    Fraudpol triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.

    Report a website to Fraudpol

    Frequently asked questions

    What is spear phishing?

    Spear phishing is a targeted phishing attempt tailored to a specific person, team or organization using relevant context to appear credible.

    What is the difference between phishing and spear phishing?

    Phishing is often broad and generic; spear phishing is researched and personalized for selected targets.

    What is whaling phishing?

    Whaling is spear phishing aimed at executives or other high-value people with authority, sensitive information or privileged access.