How it differs from mass phishing
Mass phishing sends the same message to thousands of people and relies on volume. Spear phishing is researched: attackers gather information from LinkedIn, company websites, press releases and earlier leaks, then write a message that fits the recipient's day, such as an invoice from a real supplier or a document shared by a colleague.
Typical targets and goals
Finance teams are targeted to change bank details or approve payments, often leading to BEC fraud. IT administrators are targeted for their privileged access. HR receives fake CVs carrying malware. Executives are targeted for their authority, since a request that seems to come from them is rarely questioned.
Why it is getting harder to spot
AI tools let attackers write fluent messages in any language and personalise them at scale, so spelling mistakes are no longer a reliable warning sign. Some campaigns combine email with a phone call or voice message imitating a known person.
How to reduce the risk
Verification procedures for payments and access changes through a separate channel, MFA that resists phishing, DMARC to stop spoofing of your own domain, and awareness training with realistic scenarios for each role. Our article on security awareness under ISO 27001 explains what the standard expects.




