Spear phishing is phishing aimed at a specific person. Ordinary phishing casts a wide net , the same generic message to thousands of addresses, hoping a fraction click. Spear phishing researches one target, crafts a message tailored to them, and is dramatically more effective for it. It is the technique behind most serious breaches that begin with a human, which is exactly why it belongs in any honest test of your defences.
Phishing vs. spear phishing, precisely
The difference is targeting, and it changes everything about how the attack looks and how well it works.
| Phishing | Spear phishing | |
|---|---|---|
| Target | Thousands, generic | One person, researched |
| Message | Same for everyone | Tailored to the individual |
| Pretext | “Your account is locked” | References a real project, colleague, or vendor |
| Success rate | Low per message | High per message |
| Effort | Minimal | Significant reconnaissance |
A generic phish is easy to spot , the misspelled bank, the address you do not bank with. A spear phish is an email that appears to come from your actual CFO, referencing an actual invoice, sent while they are actually travelling. The tailoring is what defeats the instinct that stops ordinary phishing.
How attackers build a spear phish
The message is the last step. The work happens first, and almost all of it uses information you have made public without thinking of it as exposure:
Reconnaissance (OSINT). LinkedIn gives roles, reporting lines, and who joined recently (new hires are prime targets , eager, unfamiliar with norms). Company pages name executives and vendors. Press releases reveal deals and partnerships. Social media reveals travel, events, and out-of-office windows. Data breaches supply email formats and passwords. None of this requires touching your systems.
Pretext construction. With that intelligence, the attacker builds a believable scenario: an email from a senior leader about a real initiative, a vendor invoice matching a real relationship, an IT request timed to a real system migration. The best pretexts exploit authority (a request from the boss), urgency (before end of day), and normality (exactly the kind of message this person receives daily).
Delivery and payload. The goal is one of three: harvest credentials via a convincing fake login page, deliver malware through an attachment or link, or drive a direct action , a wire transfer, a gift-card purchase, a change of banking details. The last category, business email compromise (BEC), needs no malware at all and causes some of the largest financial losses in cybercrime.
Whaling and BEC , the executive-focused variants
Whaling is spear phishing aimed at the biggest targets , executives, finance leaders, anyone who can authorise money or access. Business email compromise is the money-focused endgame: impersonate an executive or vendor and instruct a finance-team member to move funds or change payment details. Because BEC frequently uses a genuine (compromised) mailbox and contains no malicious link or file, it sails past technical filters. It is stopped by process , out-of-band verification of payment changes , not by software.
Why your people are the target, not your firewall
You have spent years hardening the perimeter. Attackers know this, so they do not attack it , they email someone who has already been let through. A single employee who enters a password on a convincing fake page hands over exactly what the firewall was protecting. This is why the human layer is not a footnote to security testing; for many organisations it is the most likely path to a breach, and the least tested.
How spear phishing is tested
You cannot know how your people respond to a tailored attack until one is run against them, safely and with authorisation. Social engineering penetration testing does exactly that:
- OSINT reconnaissance , the tester gathers the same public intelligence a real attacker would, which itself reveals how much of your organisation is exposed.
- Tailored campaign design , realistic pretexts built for real roles, not a generic template.
- Controlled execution , the campaign runs against agreed targets, measuring who clicks, who submits credentials, and , crucially , who reports it.
- Measured results , click rates, submission rates, and reporting rates broken down by department, benchmarked over time.
The reporting rate matters as much as the click rate. A workforce that clicks but also reports gives your security team the early warning that stops a real attack. A test measures both.
How to defend against it
Spear phishing is defended in layers, because no single control catches everything:
- Technical filtering , email authentication (SPF, DKIM, DMARC) to make spoofing harder, plus link and attachment analysis. This catches the crude attempts and forces attackers toward harder methods.
- Multi-factor authentication , so a harvested password alone is not enough. The single highest-value control against credential phishing , though be aware that adversary-in-the-middle attacks like Evilginx can bypass ordinary MFA by stealing session tokens, which is why phishing-resistant MFA (FIDO2 keys, passkeys) matters.
- Process controls for money and data , out-of-band verification for any payment change or unusual transfer. This is what defeats BEC, which no filter reliably catches.
- Trained, tested people , staff who recognise the patterns and, more importantly, know how and feel safe to report. Realistic simulation builds this far better than an annual slideshow.
- Least privilege , so a single compromised account reaches as little as possible, limiting the damage when a phish does succeed.
The short version
Spear phishing works because it is personal , built from public information into a message tailored to one target, defeating the instincts that stop generic phishing. Its worst form, business email compromise, moves money with no malware at all and slips past technical filters entirely. The defence is layered: MFA, email authentication, out-of-band verification for payments, and a workforce trained through realistic testing to recognise and report attacks. The only way to know how yours would respond is to run a controlled, authorised campaign.
Want to know how your team responds to a tailored attack , before a real attacker finds out? That is exactly what a social engineering penetration test measures. Scope one here.
Written by
Invadel Team
Senior penetration testers writing from real engagements — the same team that scopes, tests, and reports for our clients. About Invadel →