GlossarySecurity awareness

Spear phishing

Short answer

Spear phishing is a targeted form of phishing aimed at a specific person or small group, using details about their role, colleagues, suppliers or current projects to make the message credible. When it targets senior executives it is often called whaling.

How it differs from mass phishing

Mass phishing sends the same message to thousands of people and relies on volume. Spear phishing is researched: attackers gather information from LinkedIn, company websites, press releases and earlier leaks, then write a message that fits the recipient's day, such as an invoice from a real supplier or a document shared by a colleague.

Typical targets and goals

Finance teams are targeted to change bank details or approve payments, often leading to BEC fraud. IT administrators are targeted for their privileged access. HR receives fake CVs carrying malware. Executives are targeted for their authority, since a request that seems to come from them is rarely questioned.

Why it is getting harder to spot

AI tools let attackers write fluent messages in any language and personalise them at scale, so spelling mistakes are no longer a reliable warning sign. Some campaigns combine email with a phone call or voice message imitating a known person.

How to reduce the risk

Verification procedures for payments and access changes through a separate channel, MFA that resists phishing, DMARC to stop spoofing of your own domain, and awareness training with realistic scenarios for each role. Our article on security awareness under ISO 27001 explains what the standard expects.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub