CyberGlossary

Attacks & Threats

Spear Phishing

Also known as: Targeted phishing

Definition

A targeted phishing attack tailored to a specific individual or organization using personal or professional details collected in advance.

Spear phishing is a focused social-engineering attack in which the attacker researches a victim — their role, colleagues, vendors, projects, recent activity — and crafts a message that is highly relevant and persuasive. Unlike mass phishing, the volume is small and the pretext is precise, which dramatically increases success rates. Common goals include credential theft, fraudulent wire transfers, deployment of malware, and initial access for intrusions. Defences include strong email authentication (DMARC, SPF, DKIM), phishing-resistant MFA, out-of-band verification for sensitive requests, and targeted training for high-risk roles.

Examples

  • An email impersonating a CFO sent to a specific accounts-payable clerk requesting an urgent vendor payment change.
  • A LinkedIn-themed message to a developer linking to a fake code-review site that delivers a backdoor.

Related terms