Spear Phishing

Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural.

Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural. Where mass phishing plays the odds, spear phishing plays you.

Key facts

Spear phishing vs phishing vs BEC

Mass phishingSpear phishingBEC
TargetingEveryoneOne researched personWhoever moves money
PersonalizationGeneric brand baitYour projects, your colleaguesYour payment processes
PayloadUsually links / malwareOften links or credential pagesUsually none
GoalVolume of victimsAccess or credentialsFraudulent transfer or data

Anatomy of a spear phishing attack

Reconnaissance (role, projects, colleagues, travel, tone), then the hook: a shared document from a real colleague's spoofed address, a conference follow-up, an IT notice timed to a real migration. The action is small and plausible: log in here, open this, reply with the code. One set of credentials later, the attacker is inside the mailbox, and the next attack is sent from a real account.

How to defend

Assume personalization is machine-made and cheap: tighten what the organization exposes publicly, enforce phishing-resistant MFA so stolen passwords are not enough, verify unusual requests in a second channel, and run behavioral email security that notices what content filters cannot: the right words from the wrong infrastructure, or the right sender behaving abnormally. Understand the pretexting patterns and social engineering levers the attackers rely on.

How Sentaro stops spear phishing

Personalized text says nothing about the sender's legitimacy, so Sentaro judges everything else: Domain Intelligence spots lookalike and newly registered sender infrastructure, Behavioral Intelligence knows the message does not fit the claimed relationship's history, and Message Intelligence reads the credential-harvest intent behind the fluent prose. AI-written bait carries no grammar errors; it still cannot fake your history.

FAQ

What is spear phishing in simple terms?

Phishing aimed at you specifically, using researched details about your job and colleagues to make a fraudulent request feel routine.

What is the difference between spear phishing and whaling?

Whaling is spear phishing whose target or impersonated persona is a senior executive, where the authority involved raises the stakes.

Why is spear phishing so effective?

Relevance disarms suspicion: a message that references your real project from an apparent colleague does not pattern-match to "scam" for most people, especially under time pressure.

How has AI changed spear phishing?

It automated the expensive parts: reconnaissance and fluent, individually tailored writing in any language. Personalization is no longer evidence that a human studied you, or that the message is genuine.

How do companies prevent spear phishing?

Phishing-resistant MFA, second-channel verification for sensitive requests, minimal public exposure of internal details, ongoing training, and behavioral email security that evaluates sender infrastructure and relationship history rather than just content.