← All terms

Spear Phishing

Spear phishing is a targeted phishing attack that uses personalized information about the victim to increase its effectiveness.

Spear phishing is a focused variant of phishing where the attacker researches a specific individual or small group and tailors the message to their role, projects, or relationships. The personalization makes spear phishing significantly harder to detect than mass-market phishing.

How it works

The attacker typically starts with open-source intelligence (OSINT):

  • LinkedIn reveals job titles, reporting lines, recent job changes, and technology stack.
  • Company websites and press releases provide project names, partner organizations, and executive names.
  • Social media offers personal details — travel plans, hobbies, recent events — that can be woven into a believable pretext.

Armed with this information, the attacker crafts a message that looks like routine work communication: a document from a colleague, a follow-up from a recent meeting, or a request from a manager. The email may reference real project names, use correct internal terminology, and spoof a trusted sender address. Generative AI has now industrialized this research-and-write loop, delivering spear-phishing-grade personalization at mass-campaign volume — our guide to AI-generated email attacks covers the evidence and the defense.

How to defend against it

Spear phishing bypasses most generic awareness heuristics ("check for spelling errors," "hover over links") because the messages are well-crafted. Defense requires:

  • Simulation testing at higher difficulty levels that replicate the personalization of real spear phishing. Generic simulations do not prepare employees for targeted attacks.
  • Role-based risk assessment. Employees with high-value access — finance, HR, IT admins, executives — face disproportionate spear phishing risk and need more frequent, harder simulations.
  • Strong identity verification procedures for sensitive requests: out-of-band confirmation for wire transfers, credential resets, and access changes.
  • Continuous monitoring of the Human Risk Score to identify which individuals are most susceptible to targeted pretexts.

Related terms

PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.WhalingWhaling is a spear phishing attack specifically targeting senior executives or high-value individuals within an organization.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo