PhishingHigh Severity11 min read

Spear Phishing

Spear phishing is a targeted email attack that uses your personal information against you. Learn how it works, real cases, warning signs, and how to protect yourself.

Published: May 22, 2026

Overview

What is spear phishing?

Spear phishing is a highly targeted form of email fraud in which a scammer researches a specific individual — or a small group — and crafts a personalised message designed to deceive that exact person. Unlike mass phishing, which casts a wide net hoping for random victims, spear phishing is more like a precision strike: the attacker knows your name, your employer, your colleagues, your recent activity, and sometimes even your writing style before they ever contact you.

The result is an email that feels entirely authentic. It may reference a real project you are working on, appear to come from a colleague you trust, use your correct job title, or mention a meeting that actually happened. Because the message fits your life so precisely, it bypasses the instinctive suspicion most people apply to generic-looking emails.

Spear phishing is used against individuals, corporate employees, government officials, journalists, and executives alike. No professional background or level of technical literacy makes someone immune — the attack is designed around the specific person, not a general archetype. In 2024, attacks powered by AI made spear phishing dramatically faster and cheaper to execute, removing the barrier of time-intensive manual research.

Who is targeted: Employees with access to financial systems, executives, government officials, IT administrators, journalists, NGO workers, and anyone with high-value credentials or financial authority.

Why it works: The attack exploits familiarity and trust. When a message appears to come from someone you know, references real context from your life, and arrives in the flow of normal work communications, the psychological defences that would flag a stranger's suspicious email simply do not fire.

Scale & Statistics

How common is this scam?

Spear phishing is relatively rare in volume but catastrophic in impact. It accounts for a tiny fraction of all emails sent — yet it is responsible for the majority of serious data breaches.

  • Less than 0.1% of all emails are spear phishing attempts — yet they are responsible for 66% of all data breaches globally
  • 25% increase in spear phishing attacks was recorded in 2024 compared to the prior year
  • 55% of organisations that fell victim to spear phishing in 2023 had machines infected with malware or viruses as a result
  • 47% of spear phishing attacks led to the loss of sensitive or confidential data
  • 54% click-through rate — AI-generated spear phishing emails achieve this, compared to just 12% for generic phishing messages
  • $4.88 million is the average cost of a data breach initiated by a phishing or spear phishing attack (IBM, 2024)
  • €15.5 million was lost by Pepco Group, a major European retailer, in a single spear phishing attack in February 2024
  • 82.6% of phishing emails analysed between late 2024 and early 2025 contained AI-generated content

Spear phishing has historically been the domain of sophisticated nation-state actors and organised crime groups. AI tools have now democratised it: attacks that once required weeks of manual research can be assembled in minutes.

Sources: Verizon Data Breach Investigations Report 2025; IBM Cost of a Data Breach Report 2024; NordVPN Phishing Statistics 2025; BrightDefense Analysis 2024–2025; APWG Phishing Activity Trends Q4 2024

How It Works

How does it work?

A spear phishing attack follows four distinct stages — each more dangerous than the equivalent step in a mass phishing campaign.

  1. Reconnaissance — The attacker researches the target extensively. Sources include LinkedIn profiles, company websites, social media posts, press releases, data breach dumps, and even previous email threads obtained through prior breaches. AI tools now automate this process, building a detailed profile of the target within hours rather than weeks.

  2. Crafting the message — Using the intelligence gathered, the attacker writes a personalised email that references the target's name, role, colleagues, current projects, or recent events. The sender address is either spoofed to resemble a known contact or, in more advanced attacks, a genuinely compromised account is used — making sender authentication checks useless.

  3. Delivery and manipulation — The email is sent with a specific action in mind: clicking a link to a fake login page, opening a malware-laden attachment, approving a financial transfer, or sharing credentials. The message is timed and worded to feel routine — not alarming.

  4. Exploitation — Once the target complies, the attacker gains access to credentials, internal systems, financial accounts, or sensitive data. In corporate attacks, this initial foothold is often used to move laterally through networks for months before detection.

Platforms and channels used: Corporate email, LinkedIn messages, WhatsApp, Microsoft Teams, DocuSign impersonation, and compromised legitimate email accounts.

Recent evolutions in 2024–2025:

  • AI agents are now 24% more effective at spear phishing than skilled human attackers (SecurityWeek, March 2025)
  • Attackers are exploiting trusted platforms — DocuSign, SharePoint, Zoom — to send malicious links that bypass email security filters
  • Russian state-sponsored group Midnight Blizzard (APT29) used .rdp files in a large-scale spear phishing campaign in late 2024, granting attackers live access to victims' systems upon opening the file
  • Deepfake audio and video are increasingly used to reinforce spear phishing emails with fake voice or video calls

Psychological Tactics

What psychological tactics are used?

Spear phishing is more psychologically sophisticated than mass phishing precisely because it is personalised. Rather than triggering generic fear, it exploits specific trust relationships.

TacticHow it is used
FamiliarityUsing the target's real name, job title, colleagues' names, and current projects creates an immediate sense that the sender knows them — eliminating the baseline suspicion applied to strangers
AuthorityImpersonating a direct manager, CEO, CFO, or known vendor exploits the instinct to comply with requests from people in positions of power
Urgency"Wire transfer needed before market close," "The board needs this before the meeting" — artificial time pressure prevents the target from pausing to verify
NormalcyThe request is framed as routine — a supplier updating bank details, an IT department requesting a password reset — so it slots into the ordinary flow of work without triggering alarm
Social proofReferences to shared colleagues, ongoing projects, or real past interactions make the message feel legitimate: "As discussed with Sarah last week..."
Trust exploitationIn the most advanced attacks, a genuinely compromised email account is used — so the email actually comes from someone the target knows and trusts

The core reason spear phishing defeats even cautious people is that it attacks the very mechanisms we rely on to feel safe: recognition, familiarity, and context. When all of those signals say "this is normal," stepping back to question it feels unnecessary — and that is precisely what the attacker depends on.

Real-Life Example

A real-life case

Case: Pepco Group loses €15.5 million in spear phishing attack, February 2024

What happened: Pepco Group, one of Europe's largest discount retail chains operating across more than 20 countries, suffered a devastating financial loss in February 2024. Attackers crafted spear phishing emails that precisely impersonated the communications of legitimate Pepco employees — mimicking tone, formatting, and internal language with a level of accuracy that suggested significant prior research into the company's internal communications.

How it unfolded: The fraudulent emails targeted members of Pepco's finance department. The messages authorised wire transfers to what appeared to be legitimate accounts — consistent with normal financial operations. Because the emails closely resembled genuine internal correspondence and referenced plausible business contexts, finance staff processed the transfers without flagging them for additional verification. Investigators later concluded that AI tools were likely used to generate the deceptive content, which was free of the grammatical errors and tonal inconsistencies that traditionally signal fraud.

The outcome: Pepco Group confirmed a loss of approximately €15.5 million. The funds were transferred through multiple accounts and could not be recovered. The company launched an internal investigation and engaged law enforcement, but the attackers were not publicly identified. The case became a widely cited example of how AI-assisted spear phishing had crossed into routine corporate risk — no longer a threat reserved for high-profile targets or nation-state adversaries.

Source: Keepnet Labs, "10 Examples of Spear Phishing Attacks," 2024; Memcyco research cited in Keepnet analysis — keepnetlabs.com

Red Flags to Watch

Red flags to watch for

  • An email from a known colleague or manager requests an unusual action — a financial transfer, credential update, or access approval — without any preceding conversation or formal process
  • The message creates urgency around a financial or sensitive decision: "This needs to happen before end of day" or "The board is waiting"
  • A supplier or vendor unexpectedly requests a change to banking or payment details via email, without a phone confirmation
  • The email references real internal details (project names, colleagues, recent meetings) but the request itself feels off or out of character for the sender
  • You are asked to keep the communication confidential or to bypass normal approval processes
  • The sender's email address is slightly different from what you have on record — even one character changed in the domain
  • An attachment arrives described as a routine document (invoice, contract, resume, security update) from someone you were not expecting to hear from
  • A message arrives through an unusual channel — LinkedIn, WhatsApp, or Teams — requesting you open a link or file that is normally handled via official email

How to Identify

How to identify a spear phishing attempt

Spear phishing is harder to identify than mass phishing precisely because it is designed to look right. Verification must be active, not passive.

Ask yourself before acting:

  • Did this request follow the normal process — or is it asking me to skip a step?
  • Would this person normally contact me this way, through this channel?
  • Can I verify this by speaking to the sender directly — not by replying to this email?

Verification steps:

  1. Never verify a financial or access request by replying to the email in question — contact the sender through a separate, known channel (phone, in-person, or a fresh message to their known address)
  2. Check the sender's full email address character by character — display names can be copied, domains cannot be exactly duplicated
  3. For any request involving money, credentials, or sensitive data — apply a second-approval rule: no single email should be sufficient authorisation
  4. Search for the email address or domain in tools like MXToolbox or VirusTotal if you are uncertain
  5. If an attachment arrives unexpectedly, scan it at VirusTotal before opening — even if the sender appears familiar

Legitimate vs spear phishing — how to tell:

Legitimate communicationSpear phishing
Follows established internal processes and approval chainsRequests you bypass normal procedures, "just this once"
Sender can be confirmed through a separate channelSender cannot be reached by phone or gives evasive answers
Financial requests include formal documentationFinancial requests arrive by email alone, with urgency
Attachments were expected and discussed in advanceAttachments arrive without warning or prior context

How to Protect

How to protect yourself

For individuals:

  • Audit your public digital footprint — the less personal and professional information is publicly visible on LinkedIn, social media, and company websites, the less material a spear phisher has to work with
  • Enable multi-factor authentication (MFA) on all accounts — even if credentials are compromised, MFA prevents access
  • Treat any email requesting financial action or credential sharing as requiring phone-based verification, regardless of how legitimate it appears
  • Be cautious about sharing details of current projects, colleagues, or internal processes on public or semi-public platforms

For organisations:

  • Implement a strict two-person authorisation rule for all wire transfers and payment detail changes — no single email should be sufficient
  • Train staff to verify financial and access requests through a secondary channel before acting
  • Deploy email authentication protocols: DMARC, DKIM, and SPF reduce the effectiveness of domain spoofing
  • Run simulated spear phishing exercises — employees who have experienced a realistic simulation are significantly better at recognising real attacks
  • Security awareness training consistently reduces phishing susceptibility from an industry baseline of ~33% to under 5% (KnowBe4, 2025)

If you have already been targeted:

  1. Do not reply to or forward the suspicious email
  2. Report immediately to your IT or security team if in an organisational context
  3. Change credentials for any accounts you may have accessed or shared
  4. Contact your bank immediately if any financial transfer was initiated
  5. Preserve the original email with full headers for forensic investigation
  6. Report to your national cybercrime authority

Useful tools:

ToolWhat it doesCost
Proofpoint Email ProtectionEnterprise-grade spear phishing detection and filteringPaid
MXToolboxCheck email domain authentication (DMARC, SPF, DKIM)Free
VirusTotalScan suspicious attachments and URLsFree
KnowBe4Simulated phishing training for organisationsPaid

Video Lesson

Watch: Spear phishing explained

A practical walkthrough of how spear phishing attacks are constructed, what distinguishes them from generic phishing, and the specific signals to look for when evaluating a suspicious targeted email. Suitable for both individuals and employees without a technical background.

Further Reading

Further reading

Official resources

Research & reports

Investigative coverage

  • Keepnet Labs — "10 Examples of Spear Phishing Attacks" — documented real-world cases from 2023–2024 → keepnetlabs.com

Related articles on this platform