Spear Phishing
Spear phishing is a phishing attack aimed at a named individual or a small group, built from research about them. Where mass phishing succeeds on volume, spear phishing succeeds on plausibility — and the economics of that difference explain why filtering, training and technical controls all perform worse against it.
| Distinguishing feature | Researched and specific to the recipient, rather than sent at scale |
| Typical volume | One message, or a handful |
| Research sources | Company filings, press releases, professional networks, out-of-office replies, breach data |
| Common pretexts | An in-flight project, a known supplier, a recent event, a colleague’s request |
| Success rate | Far higher than mass phishing — the reason it persists despite the effort |
| Why filtering struggles | A single tailored message from a clean or compromised domain has no bulk signature |
| Targeting executives | Called whaling, and the term is used inconsistently |
| Usual objective | Credentials, session tokens, or a payment instruction |
Why targeting changes the defense
Mass phishing and spear phishing are the same technique operated on opposite economics, and nearly every practical difference follows from that.
| Mass phishing | Spear phishing | |
|---|---|---|
| Messages sent | Millions | One, or a few |
| Cost per attempt | Near zero | Hours of research |
| Detection by volume signature | Effective — the same message hits many mailboxes | Useless — there is no pattern to observe |
| Plausibility | Generic; obvious errors are common | Specific, correct, and contextually timed |
| Who is targeted | Whoever is on the list | Someone chosen for their access or authority |
| What defends it | Filtering, largely | Process, and phishing-resistant authentication |
The third row is the one that matters operationally. Bulk filtering works by noticing that a message resembles many others. A researched message sent once to one person resembles nothing, and when it comes from a compromised legitimate mailbox it passes every authentication check because it is authentic.
How the research is done
None of it requires access to anything. Company filings name executives and describe transactions. Press releases announce partnerships and system migrations. Professional networks list who reports to whom and who just joined. Out-of-office replies confirm who is away and name a deputy. Conference agendas put people in known places on known dates.
Breach data adds the rest. A breach supplies internal email formats, previous passwords and personal details, all of which make a message more convincing and more targeted.
The result is a message that arrives at a plausible moment, references a real project, uses the organization’s own vocabulary, and asks for something the recipient would ordinarily do. The recipient is not being careless when they act on it. They are responding correctly to information that happens to be false.
Why this matters for identity verification
The technical control that holds against spear phishing is the same one that holds against mass phishing, and it is not the one most organizations reach for first.
Training reduces click rates and never reaches zero. Filtering cannot see a single tailored message. What remains is making the stolen credential worthless: authentication cryptographically bound to the genuine site’s origin cannot be relayed by a proxy, which is a different property from having multi-factor authentication enabled. Codes and push approvals are relayable; origin-bound keys are not.
The second half is where the credentials end up. Successful spear phishing leads to account takeover, and takeover concentrates at account recovery — because an attacker who cannot defeat a hardware key simply claims to have lost it. A recovery path resting on knowledge-based authentication rests on the same research and breach data the attack was built from.
Re-establishing identity there with an authenticated document and a live biometric asks something the research cannot answer. That is where identity document verification touches this problem, and why synthetic and stolen identity controls matter for what the credentials are used for rather than for the message itself.
What defenses can’t do
Filtering cannot catch a one-off. There is no bulk pattern, and a compromised legitimate mailbox passes authentication because the message really is from that account.
Training lowers the rate, not the risk. Click rates fall with good training and one success is usually enough. Designing on the assumption nobody will ever click designs for a condition that will not hold.
Most MFA is relayable. Real-time proxy kits pass codes and push approvals through inside their validity window, and often capture the session token afterwards.
Reducing public information is largely impractical. Filings are mandatory, press releases are the point, and professional networks are how people work.
Frequently asked questions
What is the difference between phishing and spear phishing?
Phishing generally means messages sent at scale, succeeding on volume rather than quality. Spear phishing targets a named individual or small group using researched detail — their role, colleagues, current projects — which makes it far more convincing and effectively invisible to bulk filtering.
Why is spear phishing so hard to filter?
Because filtering largely works by recognizing that a message resembles many others. A researched message sent once to one person has no bulk signature, and if it comes from a compromised legitimate mailbox it passes sender authentication because it really is from that account.
Where does the research come from?
Public sources, mostly: company filings, press releases, professional networking profiles, out-of-office replies and conference agendas. Breach data adds internal email formats and personal details. None of it requires access to any system.
What actually defends against spear phishing?
Making the stolen credential useless. Authentication cryptographically bound to the real site’s origin cannot be relayed by a proxy, unlike codes and push approvals. Beyond that, the account recovery path needs to re-establish identity with evidence rather than with questions the attacker has already researched.
Related reading
- Phishing — the parent technique, and why most MFA no longer stops it
- Whaling — spear phishing aimed at executives, and how it differs from CEO fraud
- Account takeover fraud — where stolen credentials usually end up
- Smishing — the same technique on a channel where inspection is harder