Spear Phishing Explained: How Targeted Attacks Work and How to Stay Protected
Imagine receiving an email that appears to come from your manager, a business partner, your bank, or someone you know. The message uses your name, refers to something familiar, and asks you to take action quickly. Nothing immediately looks suspicious.
That is what makes spear phishing particularly dangerous.
Unlike broad phishing campaigns that send similar messages to large numbers of people, spear phishing focuses on a specific individual, organization, or small group. The message may be personalized to appear more trustworthy, increasing the chance that the recipient will respond without verifying it first.
Spear phishing can be used to steal credentials, obtain sensitive information, compromise accounts, or facilitate financial fraud. The FBI warns that spoofed communications can imitate trusted people or organizations and use small changes to addresses, URLs, or other details to deceive recipients.
In this guide, you’ll learn what spear phishing is, how targeted attacks work, common spear phishing examples, warning signs, how spear phishing differs from ordinary phishing, and practical ways to protect yourself and your organization.
What Is Spear Phishing?
Spear phishing is a targeted form of phishing that attempts to deceive a specific person, organization, or group.
The key difference is targeting.
Traditional phishing may send a generic message to thousands of people—for example, a fake account alert asking recipients to “verify” their information. Spear phishing is more focused. A message may be designed around a particular person’s role, organization, relationships, or circumstances.
Microsoft describes spear phishing as a targeted cyberattack that focuses on an individual or organization and may use personal details to make the deception more convincing.
Why is it called spear phishing?
The word “spear” refers to the targeted nature of the attack.
Think of the difference this way:
- Phishing: A broad net cast over many potential victims.
- Spear phishing: A targeted attempt aimed at a particular person or group.
This targeting can make spear phishing more difficult to recognize because the message may appear relevant to the recipient.
What makes spear phishing different?
| Feature | Regular Phishing | Spear Phishing |
|---|---|---|
| Target | Often broad | Specific person or group |
| Personalization | Usually limited | Often more tailored |
| Context | Generic | May reference familiar details |
| Research | Usually limited | May involve publicly available information |
| Main goal | Information or access | Information, access, or fraud |
MITRE ATT&CK categorizes phishing as electronically delivered social engineering and specifically identifies spearphishing as phishing directed at a particular individual, company, or industry.
How Does Spear Phishing Work?
Understanding the general process can help you recognize suspicious behavior without needing to know how to conduct an attack.
1. A target is selected
A person or organization may be targeted because of their role, access, relationships, or the type of information they handle.
Potentially attractive targets can include:
- Employees
- Managers
- Executives
- Finance teams
- IT administrators
- Business owners
- People with access to sensitive accounts
2. Information may be gathered
Attackers can sometimes use publicly available information to make fraudulent communication appear more relevant.
For example, information published on:
- Company websites
- Professional profiles
- Social-media accounts
- Public documents
- Organization pages
may reveal someone’s job title, workplace, professional relationships, or other contextual information.
The FBI warns that information people share online can provide scammers with details they may use to make impersonation attempts more convincing.
3. A believable story is created
The fraudulent message may appear to involve something familiar, such as:
- A work document
- An account notification
- An invoice
- A meeting
- A password issue
- A request from a colleague
- A security alert
The goal is to make the communication seem relevant rather than random.
4. The message reaches the target
Spear phishing traditionally involves email, but targeted social engineering can also appear through messaging services, social platforms, and voice communication.
MITRE ATT&CK currently categorizes spearphishing through attachments, links, services, and voice.
5. The recipient is pressured to act
The message may create:
- Urgency
- Fear
- Curiosity
- Trust
- Authority
- Financial pressure
The recipient might then be encouraged to provide information, follow a link, open a file, or approve an unusual request.
6. The attacker attempts to achieve their objective
Depending on the scam, the ultimate objective may involve account access, credential theft, financial fraud, or obtaining sensitive information.
The important lesson for users is simple:
Don’t let a personalized message replace independent verification.
How Attackers Make Spear Phishing Messages Look Convincing
A spear phishing message doesn’t necessarily need to look technically sophisticated. It may simply need to feel believable.
Personalization
A message may contain a person’s name, job role, company name, or another familiar detail.
Personalization can make recipients think:
“This message must be legitimate because it knows something about me.”
But knowing something about you doesn’t prove who sent the message.
Impersonation
Scammers may pretend to be:
- A manager
- A coworker
- A vendor
- A business partner
- A service provider
- A friend or family member
Urgency
A message may pressure you to act immediately.
For example, it could claim that a payment, account, document, or security issue requires immediate attention.
Authority
A request appearing to come from someone senior can be especially persuasive.
This is why employees should independently verify unusual requests—even when they appear to come from a manager or executive.
Familiar branding
Fraudulent messages may use familiar names, logos, terminology, or visual styles.
However, professional appearance is not proof of authenticity.
The FBI warns that spoofing may involve small changes to email addresses, sender names, phone numbers, or URLs that are intended to deceive recipients.
Common Types of Spear Phishing Attacks
Spear phishing can take several forms.
Spear phishing emails
These are targeted emails designed around a particular recipient or organization.
Spearphishing links
A message may direct the recipient toward a fraudulent website or other unsafe destination.
Spearphishing attachments
An unexpected file may be presented as an invoice, document, report, or other legitimate-looking content.
Spearphishing through services
Targeted phishing can occur through online services and social platforms rather than traditional email.
Spearphishing voice
Targeted social engineering can also use voice communication. This overlaps with the broader category of vishing, or voice phishing.
MITRE ATT&CK identifies these four spearphishing categories: attachments, links, services, and voice.
10 Spear Phishing Examples You Should Know
The following are fictionalized examples designed to illustrate warning signs.
1. Fake executive request
An employee receives a message appearing to come from a manager requesting an unusual action.
Red flags:
- Unexpected request
- Urgency
- Unusual communication channel
- Request that bypasses normal procedures
2. Fake vendor invoice
A supposed supplier sends a message about an invoice or payment.
Red flags:
- Unexpected invoice
- Changed payment details
- Pressure to act quickly
Financial requests should always be independently verified.
3. Fake password-reset message
A targeted employee receives a supposed security alert asking them to resolve an account issue.
Red flags:
- Unexpected password request
- Suspicious link
- Urgency
Instead of following the message’s link, access the service through its normal official website or app.
4. Fake HR document
A message claims that an important employment document requires immediate review.
Red flags:
- Unexpected attachment
- Pressure to open the file
- Sender doesn’t match normal HR communication
5. Fake IT support message
A supposed IT representative says the recipient’s account has a problem.
Red flags:
- Unexpected technical request
- Request for credentials or verification codes
- Pressure to act immediately
6. Fake meeting invitation
A targeted person receives an unexpected meeting request that requires additional login or account verification.
Red flags:
- Unexpected invitation
- Unfamiliar destination
- Request for account credentials
7. Fake shared document
A message claims someone shared a document that requires the recipient to sign in.
Red flags:
- Unexpected document
- Suspicious login request
- Sender cannot be independently verified
8. Fake business partner
A message appears to come from a familiar company or business contact.
Red flags:
- Unusual request
- Changed contact details
- New payment instructions
9. Fake account-security warning
A message claims that suspicious activity has been detected on an account.
Red flags:
- Fear-based language
- Immediate verification request
- Suspicious link
10. Social-media impersonation
Someone receives a message appearing to come from a person they know.
Red flags:
- New account or phone number
- Unusual request
- Request to move the conversation elsewhere
The FBI has warned about campaigns in which attackers impersonate trusted individuals through text and voice messages, reinforcing the importance of independently verifying unexpected communication.
Spear Phishing vs. Phishing: What’s the Difference?
The two terms are closely related, but targeting is the key distinction.
| Factor | Phishing | Spear Phishing |
|---|---|---|
| Target | Often broad | Specific |
| Personalization | Limited or generic | Often tailored |
| Intended audience | Large group | Individual or small group |
| Context | General | May be highly relevant |
| Example | Generic fake account alert | Personalized message aimed at a particular employee |
A useful rule is:
All spear phishing is phishing, but not all phishing is spear phishing.
Spear Phishing vs. Whaling vs. Business Email Compromise
These terms can overlap, but they aren’t identical.
Spear phishing
Targets a particular person, organization, or group.
Whaling
A particularly targeted form of phishing aimed at high-profile or senior individuals.
Business Email Compromise
Business email compromise, or BEC, involves deceptive or compromised business communications used to facilitate fraud or other harmful activity.
For example, an attacker might impersonate an executive or business partner and attempt to persuade an employee to take an unusual action.
The FBI identifies spoofing and phishing as important components of BEC scams.
Why Is Spear Phishing So Effective?
Spear phishing exploits something technology alone cannot completely eliminate: human trust.
It exploits familiarity
People naturally pay more attention to messages that appear relevant to their work or personal lives.
It uses context
A message referencing a real organization, project, or relationship may feel more believable.
It creates emotional pressure
Fear and urgency can discourage careful verification.
It targets people
Even organizations with strong security technology need employees who know how to recognize suspicious requests.
This is why cybersecurity awareness should complement technical controls.
How to Spot a Spear Phishing Email
Knowing the warning signs is one of the most effective ways to reduce your risk.
Look for:
- Unexpected requests
- Unusual urgency
- Suspicious sender addresses
- Slightly altered domains
- Unexpected attachments
- Suspicious links
- Requests for sensitive information
- Requests to bypass normal procedures
- Unexpected payment instructions
- Communication that doesn’t match normal patterns
- Requests to move the conversation to another platform
- Unusual requests from executives or vendors
Don’t rely on one clue.
A message with perfect grammar can still be fraudulent. A message with a typo can still be legitimate. Consider the whole context and independently verify important requests.
The FBI recommends carefully examining email addresses, URLs, and spelling because scammers can use subtle differences to make communications appear legitimate.
How Social Media Can Increase Spear Phishing Risk
Public information can sometimes make targeted scams more convincing.
People may publicly share:
- Job titles
- Employers
- Professional relationships
- Schools
- Events
- Family information
- Birthdays
- Work responsibilities
That doesn’t mean you should stop using social media. Instead, review what information is publicly visible and avoid sharing unnecessary sensitive details.
When someone suddenly contacts you using a new account, number, or platform, verify their identity through a channel you already trust.
How to Prevent Spear Phishing Attacks
Effective spear phishing prevention combines technology with good habits.
1. Verify unusual requests independently
If someone asks for money, sensitive information, credentials, or an unusual action, verify the request using a trusted contact method.
2. Enable multi-factor authentication
MFA provides an additional layer of account protection.
However, never share an MFA or one-time verification code with someone who asks for it unexpectedly. The FBI specifically warns that social engineering can be used to persuade victims to disclose these codes.
3. Use strong, unique passwords
Avoid using the same password across important accounts.
4. Keep software updated
Install security and software updates from trusted sources.
5. Be cautious with links and attachments
Don’t open unexpected attachments or follow suspicious links simply because a message appears to come from someone familiar.
6. Use email security controls
Organizations can use appropriate filtering and security tools to reduce exposure to suspicious messages.
7. Train employees
Security awareness training should teach employees to recognize unusual requests and verify them independently.
8. Establish payment verification procedures
Businesses should require independent confirmation for unusual payment instructions or changes to account details.
9. Limit unnecessary public information
Review what employees and organizations publish publicly.
10. Make reporting easy
Employees should know exactly how and where to report suspicious communication.
The FBI recommends MFA, caution with unsolicited messages and attachments, careful examination of sender information, and independent verification.
Spear Phishing Prevention for Businesses
Businesses face additional risks because one compromised account can potentially expose organizational information or relationships.
Organizations should establish clear procedures for:
- Payment requests
- Password resets
- Account changes
- Sensitive-information requests
- Vendor changes
- Executive requests
Train employees regularly
Employees should know:
- How to recognize suspicious messages
- How to verify unusual requests
- Where to report phishing
- What to do after clicking a suspicious link
Protect high-value accounts
Additional security controls should be considered for:
- Administrators
- Finance employees
- Executives
- IT personnel
- Other users with sensitive access
Create a response plan
Employees shouldn’t have to guess what to do after an incident.
A simple process might be:
Stop → Report → Secure → Review
The faster a suspicious incident is reported, the sooner an organization can investigate and respond.
What to Do If You Receive a Suspected Spear Phishing Message
Use a simple four-step process.
STOP
Don’t click, reply, download, or approve anything.
VERIFY
Contact the supposed sender through a trusted channel.
REPORT
Use your organization’s phishing-reporting system or the relevant reporting service.
DELETE
After reporting and following your organization’s procedures, remove the suspicious message.
The FBI advises people not to click links in unsolicited communications until the sender’s identity has been independently confirmed.
What to Do After Clicking a Spear Phishing Link
If you accidentally clicked a suspicious link, don’t panic. Take sensible defensive steps.
If you entered nothing
Stop interacting with the page and report the message.
If you entered a password
Change the password through the legitimate service and enable MFA. If you reused the password elsewhere, change those accounts too.
If financial information was exposed
Contact the relevant financial institution through an official channel and monitor the account.
If you downloaded something suspicious
Stop interacting with the file and follow trusted security guidance. If it’s a school or workplace device, notify the appropriate administrator or security team.
The most important thing is to act promptly rather than ignore the incident.
Spear Phishing in the Age of AI
Artificial intelligence is adding another challenge to the phishing landscape.
Fraudulent messages can increasingly appear polished and convincing, so grammar mistakes alone are no longer a reliable way to identify a scam.
The FBI has warned about impersonation campaigns involving text messages and AI-generated voice messages, emphasizing the importance of independently verifying identity.
This means readers should focus less on whether a message “sounds professional” and more on questions such as:
- Was I expecting this?
- Is the request normal?
- Does the sender’s identity check out?
- Is there unusual urgency?
- Can I verify the request independently?
In September 2026, the FBI also warned about targeted “consent phishing,” in which malicious links can be presented through impersonation and legitimate-looking file-sharing or application scenarios.
The broader lesson is clear: don’t trust a message simply because it looks sophisticated.
Spear Phishing Prevention Checklist
Use this quick checklist whenever you receive an unexpected message:
Before responding
- Do I recognize the sender?
- Was I expecting this message?
- Is the request unusual?
- Is there unnecessary urgency?
- Is sensitive information requested?
- Is there an unexpected link or attachment?
- Does the sender address look correct?
- Can I verify the request independently?
For businesses
- Is MFA enabled?
- Are employees regularly trained?
- Are payment changes independently verified?
- Is there a simple reporting process?
- Are important accounts protected with additional security controls?
Frequently Asked Questions About Spear Phishing
What is spear phishing in simple terms?
Spear phishing is a targeted phishing attempt designed around a particular person, organization, or group.
What is the difference between phishing and spear phishing?
Phishing often uses broad, generic messages, while spear phishing specifically targets an individual or smaller group and may use personalized context.
Why is spear phishing dangerous?
Personalization can make a fraudulent message appear more relevant and trustworthy, increasing the risk that someone will act without verifying it.
What are common spear phishing examples?
Common examples include fake executive requests, vendor impersonation, targeted password-reset messages, fraudulent invoices, fake IT notifications, and deceptive shared-document messages.
How can I prevent spear phishing?
Use MFA, strong unique passwords, software updates, careful handling of links and attachments, independent verification, security awareness training, and clear reporting procedures.
Is spear phishing only done through email?
No. MITRE ATT&CK identifies spearphishing through attachments, links, services, and voice. Targeted social engineering can also appear through messaging and other communication channels.
What should I do if I receive a spear phishing email?
Don’t interact with it. Independently verify the sender if necessary, report the message through the appropriate channel, and follow your organization’s security procedures.
Can MFA stop spear phishing?
MFA can significantly strengthen account security, but it doesn’t eliminate phishing. Attackers may still try to manipulate people into revealing authentication codes or approving fraudulent requests.
Final Takeaway: Think Before You Trust
Spear phishing is targeted phishing designed to exploit trust.
The most dangerous messages aren’t always the ones with obvious spelling mistakes or strange formatting. A targeted scam may look polished, use familiar names, and reference real-world information.
That’s why the most valuable security habit is simple:
Stop. Verify. Protect.
Don’t click unexpected links simply because a message looks professional. Don’t provide sensitive information because someone creates urgency. Don’t assume a familiar name or logo proves authenticity.
Instead, independently verify unusual requests, use MFA, maintain strong and unique passwords, keep software updated, and report suspicious messages.
For businesses, combine employee awareness with clear verification procedures and layered security controls.
Share this guide
Know someone who might benefit from learning how to recognize a targeted phishing attack?
Share this guide with your family, friends, classmates, coworkers, or business network. A few seconds spent verifying a suspicious message can prevent a much bigger security problem.
