Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural. Where mass phishing plays the odds, spear phishing plays you.
Key facts
- The raw material is public: LinkedIn, company sites, press releases and breached data provide the personalization.
- Generative AI has removed the cost barrier: research and fluent per-target messages can be automated at scale, making "spray" attacks read like spear phishing.
- Spear phishing is the usual first step of larger attacks: credential theft, mailbox takeover, then business email compromise from the inside.
Spear phishing vs phishing vs BEC
| Phishing | Spear phishing | BEC | |
|---|---|---|---|
| Targeting | Anyone | One researched person | Specific roles: finance, HR, executives |
| Personalization | Generic | High: real projects and colleagues | High: real vendors, invoices, deals |
| Payload | Link or attachment | Link, attachment or none | Usually none: a request in plain text |
| Goal | Credentials, malware | Credentials, access, payments | Money: wire transfers, payroll, invoices |
| Volume | Mass | Few | Few |
| Detection | Signatures and reputation | Behavior and context | Relationship, request and intent |
Anatomy of a spear phishing attack
Reconnaissance (role, projects, colleagues, travel, tone), then the hook: a shared document from a real colleague's spoofed address, a conference follow-up, an IT notice timed to a real migration. The action is small and plausible: log in here, open this, reply with the code. One set of credentials later, the attacker is inside the mailbox, and the next attack is sent from a real account.
How to defend
Assume personalization is machine-made and cheap: tighten what the organization exposes publicly, enforce phishing-resistant MFA so stolen passwords are not enough, verify unusual requests in a second channel, and run behavioral email security that notices what content filters cannot: the right words from the wrong infrastructure, or the right sender behaving abnormally. Understand the pretexting patterns and social engineering levers the attackers rely on.
How Sentaro stops spear phishing
Personalized text says nothing about the sender's legitimacy, so Sentaro judges everything else: Message Defense spots lookalike and newly registered sender infrastructure and reads the credential-harvest intent behind the fluent prose, and Behavioral Defense knows the message does not fit the claimed relationship's history. AI-written bait carries no grammar errors; it still cannot fake your history.