← Glossary

Spear Phishing

Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural.

Updated

Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural. Where mass phishing plays the odds, spear phishing plays you.

Key facts

  • The raw material is public: LinkedIn, company sites, press releases and breached data provide the personalization.
  • Generative AI has removed the cost barrier: research and fluent per-target messages can be automated at scale, making "spray" attacks read like spear phishing.
  • Spear phishing is the usual first step of larger attacks: credential theft, mailbox takeover, then business email compromise from the inside.

Spear phishing vs phishing vs BEC

PhishingSpear phishingBEC
TargetingAnyoneOne researched personSpecific roles: finance, HR, executives
PersonalizationGenericHigh: real projects and colleaguesHigh: real vendors, invoices, deals
PayloadLink or attachmentLink, attachment or noneUsually none: a request in plain text
GoalCredentials, malwareCredentials, access, paymentsMoney: wire transfers, payroll, invoices
VolumeMassFewFew
DetectionSignatures and reputationBehavior and contextRelationship, request and intent

Anatomy of a spear phishing attack

Reconnaissance (role, projects, colleagues, travel, tone), then the hook: a shared document from a real colleague's spoofed address, a conference follow-up, an IT notice timed to a real migration. The action is small and plausible: log in here, open this, reply with the code. One set of credentials later, the attacker is inside the mailbox, and the next attack is sent from a real account.

How to defend

Assume personalization is machine-made and cheap: tighten what the organization exposes publicly, enforce phishing-resistant MFA so stolen passwords are not enough, verify unusual requests in a second channel, and run behavioral email security that notices what content filters cannot: the right words from the wrong infrastructure, or the right sender behaving abnormally. Understand the pretexting patterns and social engineering levers the attackers rely on.

How Sentaro stops spear phishing

Personalized text says nothing about the sender's legitimacy, so Sentaro judges everything else: Message Defense spots lookalike and newly registered sender infrastructure and reads the credential-harvest intent behind the fluent prose, and Behavioral Defense knows the message does not fit the claimed relationship's history. AI-written bait carries no grammar errors; it still cannot fake your history.

Questions we get asked.

What is spear phishing in simple terms?

Phishing aimed at you specifically, using researched details about your job and colleagues to make a fraudulent request feel routine.

What is the difference between spear phishing and whaling?

Whaling is spear phishing whose target or impersonated persona is a senior executive, where the authority involved raises the stakes.

Why is spear phishing so effective?

Relevance disarms suspicion: a message that references your real project from an apparent colleague does not pattern-match to "scam" for most people, especially under time pressure.

How has AI changed spear phishing?

It automated the expensive parts: reconnaissance and fluent, individually tailored writing in any language. Personalization is no longer evidence that a human studied you, or that the message is genuine.

How do companies prevent spear phishing?

Phishing-resistant MFA, second-channel verification for sensitive requests, minimal public exposure of internal details, ongoing training, and behavioral email security that evaluates sender infrastructure and relationship history rather than just content.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.