[{"data":1,"prerenderedAt":103},["ShallowReactive",2],{"glossary:spear-phishing":3},{"term":4,"published":88,"modified":88,"mentions":89,"related":97},{"slug":5,"title":6,"lede":7,"blocks":8,"faqs":72},"spear-phishing","Spear Phishing","Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural.",[9,12,15,21,23,60,62,64,66,68,70],{"t":10,"text":11},"p","Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural. Where mass phishing plays the odds, spear phishing plays you.",{"t":13,"text":14},"h2","Key facts",{"t":16,"items":17},"ul",[18,19,20],"The raw material is public: LinkedIn, company sites, press releases and breached data provide the personalization.","Generative AI has removed the cost barrier: research and fluent per-target messages can be automated at scale, making \"spray\" attacks read like spear phishing.","Spear phishing is the usual first step of larger attacks: credential theft, mailbox takeover, then business email compromise from the inside.",{"t":13,"text":22},"Spear phishing vs phishing vs BEC",{"t":24,"rows":25},"table",[26,31,36,41,46,51,55],[27,28,29,30],"","Phishing","Spear phishing","BEC",[32,33,34,35],"Targeting","Anyone","One researched person","Specific roles: finance, HR, executives",[37,38,39,40],"Personalization","Generic","High: real projects and colleagues","High: real vendors, invoices, deals",[42,43,44,45],"Payload","Link or attachment","Link, attachment or none","Usually none: a request in plain text",[47,48,49,50],"Goal","Credentials, malware","Credentials, access, payments","Money: wire transfers, payroll, invoices",[52,53,54,54],"Volume","Mass","Few",[56,57,58,59],"Detection","Signatures and reputation","Behavior and context","Relationship, request and intent",{"t":13,"text":61},"Anatomy of a spear phishing attack",{"t":10,"text":63},"Reconnaissance (role, projects, colleagues, travel, tone), then the hook: a shared document from a real colleague's spoofed address, a conference follow-up, an IT notice timed to a real migration. The action is small and plausible: log in here, open this, reply with the code. One set of credentials later, the attacker is inside the mailbox, and the next attack is sent from a real account.",{"t":13,"text":65},"How to defend",{"t":10,"text":67},"Assume personalization is machine-made and cheap: tighten what the organization exposes publicly, enforce phishing-resistant MFA so stolen passwords are not enough, verify unusual requests in a second channel, and run behavioral email security that notices what content filters cannot: the right words from the wrong infrastructure, or the right sender behaving abnormally. Understand the pretexting patterns and social engineering levers the attackers rely on.",{"t":13,"text":69},"How Sentaro stops spear phishing",{"t":10,"text":71},"Personalized text says nothing about the sender's legitimacy, so Sentaro judges everything else: Message Defense spots lookalike and newly registered sender infrastructure and reads the credential-harvest intent behind the fluent prose, and Behavioral Defense knows the message does not fit the claimed relationship's history. AI-written bait carries no grammar errors; it still cannot fake your history.",[73,76,79,82,85],{"q":74,"a":75},"What is spear phishing in simple terms?","Phishing aimed at you specifically, using researched details about your job and colleagues to make a fraudulent request feel routine.",{"q":77,"a":78},"What is the difference between spear phishing and whaling?","Whaling is spear phishing whose target or impersonated persona is a senior executive, where the authority involved raises the stakes.",{"q":80,"a":81},"Why is spear phishing so effective?","Relevance disarms suspicion: a message that references your real project from an apparent colleague does not pattern-match to \"scam\" for most people, especially under time pressure.",{"q":83,"a":84},"How has AI changed spear phishing?","It automated the expensive parts: reconnaissance and fluent, individually tailored writing in any language. Personalization is no longer evidence that a human studied you, or that the message is genuine.",{"q":86,"a":87},"How do companies prevent spear phishing?","Phishing-resistant MFA, second-channel verification for sensitive requests, minimal public exposure of internal details, ongoing training, and behavioral email security that evaluates sender infrastructure and relationship history rather than just content.","2026-09-08",[90,91,92,93,94,95,96],"account-takeover","business-email-compromise","cyber-resilience-act","integrated-cloud-email-security","phishing","pretexting","social-engineering",[92,95,96,98,99,100,101,102],"ai-jailbreaking","whaling","ai-native","ransomware-as-a-service","quishing",1789658071104]