Spear Phishing
Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural.
Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural. Where mass phishing plays the odds, spear phishing plays you.
Key facts
- The raw material is public: LinkedIn, company sites, press releases and breached data provide the personalization.
- Generative AI has removed the cost barrier: research and fluent per-target messages can be automated at scale, making "spray" attacks read like spear phishing.
- Spear phishing is the usual first step of larger attacks: credential theft, mailbox takeover, then business email compromise from the inside.
Spear phishing vs phishing vs BEC
| Mass phishing | Spear phishing | BEC | |
|---|---|---|---|
| Targeting | Everyone | One researched person | Whoever moves money |
| Personalization | Generic brand bait | Your projects, your colleagues | Your payment processes |
| Payload | Usually links / malware | Often links or credential pages | Usually none |
| Goal | Volume of victims | Access or credentials | Fraudulent transfer or data |
Anatomy of a spear phishing attack
Reconnaissance (role, projects, colleagues, travel, tone), then the hook: a shared document from a real colleague's spoofed address, a conference follow-up, an IT notice timed to a real migration. The action is small and plausible: log in here, open this, reply with the code. One set of credentials later, the attacker is inside the mailbox, and the next attack is sent from a real account.
How to defend
Assume personalization is machine-made and cheap: tighten what the organization exposes publicly, enforce phishing-resistant MFA so stolen passwords are not enough, verify unusual requests in a second channel, and run behavioral email security that notices what content filters cannot: the right words from the wrong infrastructure, or the right sender behaving abnormally. Understand the pretexting patterns and social engineering levers the attackers rely on.
How Sentaro stops spear phishing
Personalized text says nothing about the sender's legitimacy, so Sentaro judges everything else: Domain Intelligence spots lookalike and newly registered sender infrastructure, Behavioral Intelligence knows the message does not fit the claimed relationship's history, and Message Intelligence reads the credential-harvest intent behind the fluent prose. AI-written bait carries no grammar errors; it still cannot fake your history.
FAQ
What is spear phishing in simple terms?
Phishing aimed at you specifically, using researched details about your job and colleagues to make a fraudulent request feel routine.
What is the difference between spear phishing and whaling?
Whaling is spear phishing whose target or impersonated persona is a senior executive, where the authority involved raises the stakes.
Why is spear phishing so effective?
Relevance disarms suspicion: a message that references your real project from an apparent colleague does not pattern-match to "scam" for most people, especially under time pressure.
How has AI changed spear phishing?
It automated the expensive parts: reconnaissance and fluent, individually tailored writing in any language. Personalization is no longer evidence that a human studied you, or that the message is genuine.
How do companies prevent spear phishing?
Phishing-resistant MFA, second-channel verification for sensitive requests, minimal public exposure of internal details, ongoing training, and behavioral email security that evaluates sender infrastructure and relationship history rather than just content.