Phishing vs spear phishing: what's the difference?
Ordinary phishing is a net cast at millions. Spear phishing is a message written for you specifically, using real details about your life or work — which is why the usual detection advice fails against it.
The short answer
- Phishing is untargeted and sent in bulk; spear phishing is researched and written for one person or one small group.
- Spear phishing contains true details - your employer, a colleague's name, a real project - which is exactly why it defeats red-flag checklists.
- Whaling is spear phishing aimed at executives; business email compromise is the version that targets payments.
- Bulk phishing is caught by filters and by looking wrong; spear phishing is caught only by verifying through an independent channel.
- Reducing your public information footprint measurably raises the cost of targeting you.
Both are attempts to get you to hand over a credential, a payment or access. The difference is how many people received the same message — and that single variable changes almost everything else about the attack.
The comparison
| Phishing | Spear phishing | |
|---|---|---|
| Recipients | Thousands to millions | One person, or a handful |
| Personalisation | Generic, or a merged first name | Real, specific, verifiable details |
| Effort per target | Effectively zero | Hours of research |
| Success rate needed | A fraction of a percent | High — there is only one attempt |
| Typical goal | Credentials, card details | A payment, privileged access, a foothold |
| Caught by filters | Frequently | Rarely |
| Caught by "looking wrong" | Often | Almost never |
Why bulk phishing looks the way it does
When a list costs almost nothing, the campaign does not need to convince most people. It needs to convince a fraction of a percent, and it needs to do so at volume.
That economics produces the phishing everyone recognises: a generic greeting, a universally applicable pretext (a delivery, a password reset, a bank alert), and no detail that could contradict a particular recipient's circumstances. It is vague on purpose — specificity would make it wrong for most of the list.
The APWG recorded over a million phishing attacks in a single quarter in 2025. That number only makes sense at this end of the spectrum.
Why spear phishing defeats the checklist
The standard advice — check the sender, look for urgency, check the link, watch for errors — assumes the message contains something wrong. In a well-built spear phishing message, the details are right.
From: Daniel Okafor
<d.okafor@[your-actual-supplier].com>Subject: RE: Q3 renewal — updated remittanceHi — following up from Tuesday's call. Finance has moved us to a new account ahead of the renewal, updated details attached. Can you get this over before Friday's cut-off?
The supplier is real. The renewal is real. Tuesday's call happened. The sender's address may be genuine, because their mailbox was compromised first.
The named variants
Whaling — spear phishing aimed at executives. The pretext involves something only a senior person could authorise: an urgent acquisition payment, a confidential request, a legal matter. Executives are chosen because they have authority, are often travelling, and their teams are trained to act on their instructions without friction.
Business email compromise (BEC) — the payment-focused version, and one of the most financially damaging categories in fraud reporting generally. It is usually the invoice-and-changed-bank-details pattern, run from either a compromised or a convincingly similar mailbox. The APWG recorded wire transfer BEC attacks rising 33% quarter on quarter in early 2025.
Clone phishing — a real message you already received, resent with the link or attachment swapped. Because the original was legitimate, the copy inherits its credibility.
Where the research comes from
Very little of it is stolen. Most is published, or for sale:
- Professional profiles: job title, reporting line, tenure, colleagues
- Company sites: staff lists, supplier names, press releases
- Social media: travel, absences, relationships, interests
- Conference programmes and industry press
- Data brokers: address history, household, purchases
This is the concrete link between privacy and security. Every published detail lowers the cost of writing a message you would believe.
What actually defends against each
Against bulk phishing, the ordinary defences work well: spam filtering, the four checks, a password manager that will not autofill on the wrong domain, and passkeys.
Against spear phishing, only two things reliably work.
- Verify high-stakes requests out of band, every time, regardless of how convincing they are. Not a reply to the email — a phone call to a number from your own records. The rule has to be unconditional, because a rule you apply only when suspicious is a rule that fails exactly when it matters.
- Make the category of request the trigger, not the message. Any change of bank details, any unusual payment, any credential request, any unusual confidentiality — verify by policy, not by instinct.
Reducing your public footprint helps too — not because it makes targeting impossible, but because it makes it expensive, and attacker effort is finite.
Try a targeted message
Our spear phishing scenario builds a message from information about you, so you can see exactly why the usual tells go missing.
Try it freeFrequently asked questions
- What is the difference between phishing and spear phishing?
- Phishing is sent in bulk to large lists with a generic pretext and needs only a tiny response rate to pay off. Spear phishing is aimed at a named individual, uses researched details that are genuinely true, and is written once for that person. The difference is targeting and effort, and it changes which defences work.
- What is whaling?
- Spear phishing aimed at senior executives — the "big fish". The pretext usually involves something only a senior person could authorise, such as an urgent payment or a confidential acquisition. Executives are targeted because they have authority, are frequently travelling, and their assistants are trained to act on their instructions quickly.
- Why is spear phishing harder to detect?
- Because the standard red flags are absent. The sender may be a real colleague whose account was compromised, the details are accurate, the tone matches your workplace, and there is often no link or attachment for a filter to inspect. Detection based on "does this look wrong" fails when nothing looks wrong.
- How do attackers research spear phishing targets?
- Public professional profiles, company websites, social media, conference programmes, press releases, and data broker records. Most of what makes a targeted message convincing is not stolen — it is published, or purchasable. That is why reducing your public footprint genuinely raises the cost of targeting you.
Sources
- Phishing Activity Trends Report, 1st Quarter 2025 — Anti-Phishing Working Group, 2025
- 2025 Internet Crime Report — FBI Internet Crime Complaint Center (IC3), 2026
About the author
Cybersecurity & Digital Literacy
Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
- Founder and engineer, SafeSurf IQ
- Writes and reviews the platform's phishing, scam and privacy curriculum
- Works from primary incident and fraud reporting, cited on every article
Last reviewed . Figures are checked against the primary sources listed above at each review.
Read next
- Phishing
What is phishing? How it works, and how to recognise it
Phishing is any attempt to trick you into handing over a credential, a payment or access by pretending to be someone you trust. The pretext changes constantly; the underlying request almost never does.
- Phishing
How phishing works: the anatomy of an attack
A phishing attack has five stages, and only one of them is the message you see. Understanding the other four explains why the messages look the way they do, and where the chain is easiest to break.
- Phishing
I clicked a phishing link. What should I do?
Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.