What is Spear phishing?
Spear phishing is phishing tailored to one person or team. The attacker researches the target on LinkedIn, the company website or social media first, then writes an email that reads like genuine work correspondence, with the right names, projects and tone.
Compared with mass phishing, a targeted email reaches fewer people but works far more often, because it lacks the usual tells. Finance, HR, procurement and executive assistants are the most frequent targets.
How to spot it
- The email knows your project or colleague, but the request is unusual
- It asks you to skip a procedure or act quietly
- The sender writes from a new or personal address
What to do
- Verify an unusual request through another channel: call a number you already know
- Never use the contact details given in the email itself
Related courses
- Corporate email securityAnatomy of a dangerous email, phishing, BEC and malware, and rules for using work email safely.
- BEC & CEO fraudThe most expensive email attack: the fake CEO, the changed bank account and the transfer. The rule "verify, don't trust".
- Social engineeringSocial engineering techniques and defence: verifying calls, emails and identities, and checking links.
Terms on this topic
More topics
Start with your team's risk baseline
15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.