Skip to Main Content
Phishing

Phishing vs spear phishing: what's the difference?

Ordinary phishing is a net cast at millions. Spear phishing is a message written for you specifically, using real details about your life or work — which is why the usual detection advice fails against it.

Subash Poudel4 min read

The short answer

  1. Phishing is untargeted and sent in bulk; spear phishing is researched and written for one person or one small group.
  2. Spear phishing contains true details - your employer, a colleague's name, a real project - which is exactly why it defeats red-flag checklists.
  3. Whaling is spear phishing aimed at executives; business email compromise is the version that targets payments.
  4. Bulk phishing is caught by filters and by looking wrong; spear phishing is caught only by verifying through an independent channel.
  5. Reducing your public information footprint measurably raises the cost of targeting you.

Both are attempts to get you to hand over a credential, a payment or access. The difference is how many people received the same message — and that single variable changes almost everything else about the attack.

The comparison

PhishingSpear phishing
RecipientsThousands to millionsOne person, or a handful
PersonalisationGeneric, or a merged first nameReal, specific, verifiable details
Effort per targetEffectively zeroHours of research
Success rate neededA fraction of a percentHigh — there is only one attempt
Typical goalCredentials, card detailsA payment, privileged access, a foothold
Caught by filtersFrequentlyRarely
Caught by "looking wrong"OftenAlmost never

Why bulk phishing looks the way it does

When a list costs almost nothing, the campaign does not need to convince most people. It needs to convince a fraction of a percent, and it needs to do so at volume.

That economics produces the phishing everyone recognises: a generic greeting, a universally applicable pretext (a delivery, a password reset, a bank alert), and no detail that could contradict a particular recipient's circumstances. It is vague on purpose — specificity would make it wrong for most of the list.

The APWG recorded over a million phishing attacks in a single quarter in 2025. That number only makes sense at this end of the spectrum.

Why spear phishing defeats the checklist

The standard advice — check the sender, look for urgency, check the link, watch for errors — assumes the message contains something wrong. In a well-built spear phishing message, the details are right.

From: Daniel Okafor <d.okafor@[your-actual-supplier].com> Subject: RE: Q3 renewal — updated remittance

Hi — following up from Tuesday's call. Finance has moved us to a new account ahead of the renewal, updated details attached. Can you get this over before Friday's cut-off?

The supplier is real. The renewal is real. Tuesday's call happened. The sender's address may be genuine, because their mailbox was compromised first.

The named variants

Whaling — spear phishing aimed at executives. The pretext involves something only a senior person could authorise: an urgent acquisition payment, a confidential request, a legal matter. Executives are chosen because they have authority, are often travelling, and their teams are trained to act on their instructions without friction.

Business email compromise (BEC) — the payment-focused version, and one of the most financially damaging categories in fraud reporting generally. It is usually the invoice-and-changed-bank-details pattern, run from either a compromised or a convincingly similar mailbox. The APWG recorded wire transfer BEC attacks rising 33% quarter on quarter in early 2025.

Clone phishing — a real message you already received, resent with the link or attachment swapped. Because the original was legitimate, the copy inherits its credibility.

Where the research comes from

Very little of it is stolen. Most is published, or for sale:

  • Professional profiles: job title, reporting line, tenure, colleagues
  • Company sites: staff lists, supplier names, press releases
  • Social media: travel, absences, relationships, interests
  • Conference programmes and industry press
  • Data brokers: address history, household, purchases

This is the concrete link between privacy and security. Every published detail lowers the cost of writing a message you would believe.

What actually defends against each

Against bulk phishing, the ordinary defences work well: spam filtering, the four checks, a password manager that will not autofill on the wrong domain, and passkeys.

Against spear phishing, only two things reliably work.

  1. Verify high-stakes requests out of band, every time, regardless of how convincing they are. Not a reply to the email — a phone call to a number from your own records. The rule has to be unconditional, because a rule you apply only when suspicious is a rule that fails exactly when it matters.
  2. Make the category of request the trigger, not the message. Any change of bank details, any unusual payment, any credential request, any unusual confidentiality — verify by policy, not by instinct.

Reducing your public footprint helps too — not because it makes targeting impossible, but because it makes it expensive, and attacker effort is finite.

Try a targeted message

Our spear phishing scenario builds a message from information about you, so you can see exactly why the usual tells go missing.

Try it free

Frequently asked questions

What is the difference between phishing and spear phishing?
Phishing is sent in bulk to large lists with a generic pretext and needs only a tiny response rate to pay off. Spear phishing is aimed at a named individual, uses researched details that are genuinely true, and is written once for that person. The difference is targeting and effort, and it changes which defences work.
What is whaling?
Spear phishing aimed at senior executives — the "big fish". The pretext usually involves something only a senior person could authorise, such as an urgent payment or a confidential acquisition. Executives are targeted because they have authority, are frequently travelling, and their assistants are trained to act on their instructions quickly.
Why is spear phishing harder to detect?
Because the standard red flags are absent. The sender may be a real colleague whose account was compromised, the details are accurate, the tone matches your workplace, and there is often no link or attachment for a filter to inspect. Detection based on "does this look wrong" fails when nothing looks wrong.
How do attackers research spear phishing targets?
Public professional profiles, company websites, social media, conference programmes, press releases, and data broker records. Most of what makes a targeted message convincing is not stolen — it is published, or purchasable. That is why reducing your public footprint genuinely raises the cost of targeting you.

Sources

  1. Phishing Activity Trends Report, 1st Quarter 2025 Anti-Phishing Working Group, 2025
  2. 2025 Internet Crime Report FBI Internet Crime Complaint Center (IC3), 2026

About the author

Subash Poudel

Cybersecurity & Digital Literacy

Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.

  • Founder and engineer, SafeSurf IQ
  • Writes and reviews the platform's phishing, scam and privacy curriculum
  • Works from primary incident and fraud reporting, cited on every article

Last reviewed . Figures are checked against the primary sources listed above at each review.