Spear Phishing
Spear phishing is a targeted email attack that uses your personal information against you. Learn how it works, real cases, warning signs, and how to protect yourself.
Overview
What is spear phishing?
Spear phishing is a highly targeted form of email fraud in which a scammer researches a specific individual — or a small group — and crafts a personalised message designed to deceive that exact person. Unlike mass phishing, which casts a wide net hoping for random victims, spear phishing is more like a precision strike: the attacker knows your name, your employer, your colleagues, your recent activity, and sometimes even your writing style before they ever contact you.
The result is an email that feels entirely authentic. It may reference a real project you are working on, appear to come from a colleague you trust, use your correct job title, or mention a meeting that actually happened. Because the message fits your life so precisely, it bypasses the instinctive suspicion most people apply to generic-looking emails.
Spear phishing is used against individuals, corporate employees, government officials, journalists, and executives alike. No professional background or level of technical literacy makes someone immune — the attack is designed around the specific person, not a general archetype. In 2024, attacks powered by AI made spear phishing dramatically faster and cheaper to execute, removing the barrier of time-intensive manual research.
Who is targeted: Employees with access to financial systems, executives, government officials, IT administrators, journalists, NGO workers, and anyone with high-value credentials or financial authority.
Why it works: The attack exploits familiarity and trust. When a message appears to come from someone you know, references real context from your life, and arrives in the flow of normal work communications, the psychological defences that would flag a stranger's suspicious email simply do not fire.
Scale & Statistics
How common is this scam?
Spear phishing is relatively rare in volume but catastrophic in impact. It accounts for a tiny fraction of all emails sent — yet it is responsible for the majority of serious data breaches.
- Less than 0.1% of all emails are spear phishing attempts — yet they are responsible for 66% of all data breaches globally
- 25% increase in spear phishing attacks was recorded in 2024 compared to the prior year
- 55% of organisations that fell victim to spear phishing in 2023 had machines infected with malware or viruses as a result
- 47% of spear phishing attacks led to the loss of sensitive or confidential data
- 54% click-through rate — AI-generated spear phishing emails achieve this, compared to just 12% for generic phishing messages
- $4.88 million is the average cost of a data breach initiated by a phishing or spear phishing attack (IBM, 2024)
- €15.5 million was lost by Pepco Group, a major European retailer, in a single spear phishing attack in February 2024
- 82.6% of phishing emails analysed between late 2024 and early 2025 contained AI-generated content
Spear phishing has historically been the domain of sophisticated nation-state actors and organised crime groups. AI tools have now democratised it: attacks that once required weeks of manual research can be assembled in minutes.
Sources: Verizon Data Breach Investigations Report 2025; IBM Cost of a Data Breach Report 2024; NordVPN Phishing Statistics 2025; BrightDefense Analysis 2024–2025; APWG Phishing Activity Trends Q4 2024
How It Works
How does it work?
A spear phishing attack follows four distinct stages — each more dangerous than the equivalent step in a mass phishing campaign.
-
Reconnaissance — The attacker researches the target extensively. Sources include LinkedIn profiles, company websites, social media posts, press releases, data breach dumps, and even previous email threads obtained through prior breaches. AI tools now automate this process, building a detailed profile of the target within hours rather than weeks.
-
Crafting the message — Using the intelligence gathered, the attacker writes a personalised email that references the target's name, role, colleagues, current projects, or recent events. The sender address is either spoofed to resemble a known contact or, in more advanced attacks, a genuinely compromised account is used — making sender authentication checks useless.
-
Delivery and manipulation — The email is sent with a specific action in mind: clicking a link to a fake login page, opening a malware-laden attachment, approving a financial transfer, or sharing credentials. The message is timed and worded to feel routine — not alarming.
-
Exploitation — Once the target complies, the attacker gains access to credentials, internal systems, financial accounts, or sensitive data. In corporate attacks, this initial foothold is often used to move laterally through networks for months before detection.
Platforms and channels used: Corporate email, LinkedIn messages, WhatsApp, Microsoft Teams, DocuSign impersonation, and compromised legitimate email accounts.
Recent evolutions in 2024–2025:
- AI agents are now 24% more effective at spear phishing than skilled human attackers (SecurityWeek, March 2025)
- Attackers are exploiting trusted platforms — DocuSign, SharePoint, Zoom — to send malicious links that bypass email security filters
- Russian state-sponsored group Midnight Blizzard (APT29) used
.rdpfiles in a large-scale spear phishing campaign in late 2024, granting attackers live access to victims' systems upon opening the file - Deepfake audio and video are increasingly used to reinforce spear phishing emails with fake voice or video calls
Psychological Tactics
What psychological tactics are used?
Spear phishing is more psychologically sophisticated than mass phishing precisely because it is personalised. Rather than triggering generic fear, it exploits specific trust relationships.
| Tactic | How it is used |
|---|---|
| Familiarity | Using the target's real name, job title, colleagues' names, and current projects creates an immediate sense that the sender knows them — eliminating the baseline suspicion applied to strangers |
| Authority | Impersonating a direct manager, CEO, CFO, or known vendor exploits the instinct to comply with requests from people in positions of power |
| Urgency | "Wire transfer needed before market close," "The board needs this before the meeting" — artificial time pressure prevents the target from pausing to verify |
| Normalcy | The request is framed as routine — a supplier updating bank details, an IT department requesting a password reset — so it slots into the ordinary flow of work without triggering alarm |
| Social proof | References to shared colleagues, ongoing projects, or real past interactions make the message feel legitimate: "As discussed with Sarah last week..." |
| Trust exploitation | In the most advanced attacks, a genuinely compromised email account is used — so the email actually comes from someone the target knows and trusts |
The core reason spear phishing defeats even cautious people is that it attacks the very mechanisms we rely on to feel safe: recognition, familiarity, and context. When all of those signals say "this is normal," stepping back to question it feels unnecessary — and that is precisely what the attacker depends on.
Real-Life Example
A real-life case
Case: Pepco Group loses €15.5 million in spear phishing attack, February 2024
What happened: Pepco Group, one of Europe's largest discount retail chains operating across more than 20 countries, suffered a devastating financial loss in February 2024. Attackers crafted spear phishing emails that precisely impersonated the communications of legitimate Pepco employees — mimicking tone, formatting, and internal language with a level of accuracy that suggested significant prior research into the company's internal communications.
How it unfolded: The fraudulent emails targeted members of Pepco's finance department. The messages authorised wire transfers to what appeared to be legitimate accounts — consistent with normal financial operations. Because the emails closely resembled genuine internal correspondence and referenced plausible business contexts, finance staff processed the transfers without flagging them for additional verification. Investigators later concluded that AI tools were likely used to generate the deceptive content, which was free of the grammatical errors and tonal inconsistencies that traditionally signal fraud.
The outcome: Pepco Group confirmed a loss of approximately €15.5 million. The funds were transferred through multiple accounts and could not be recovered. The company launched an internal investigation and engaged law enforcement, but the attackers were not publicly identified. The case became a widely cited example of how AI-assisted spear phishing had crossed into routine corporate risk — no longer a threat reserved for high-profile targets or nation-state adversaries.
Source: Keepnet Labs, "10 Examples of Spear Phishing Attacks," 2024; Memcyco research cited in Keepnet analysis — keepnetlabs.com
Red Flags to Watch
Red flags to watch for
- An email from a known colleague or manager requests an unusual action — a financial transfer, credential update, or access approval — without any preceding conversation or formal process
- The message creates urgency around a financial or sensitive decision: "This needs to happen before end of day" or "The board is waiting"
- A supplier or vendor unexpectedly requests a change to banking or payment details via email, without a phone confirmation
- The email references real internal details (project names, colleagues, recent meetings) but the request itself feels off or out of character for the sender
- You are asked to keep the communication confidential or to bypass normal approval processes
- The sender's email address is slightly different from what you have on record — even one character changed in the domain
- An attachment arrives described as a routine document (invoice, contract, resume, security update) from someone you were not expecting to hear from
- A message arrives through an unusual channel — LinkedIn, WhatsApp, or Teams — requesting you open a link or file that is normally handled via official email
How to Identify
How to identify a spear phishing attempt
Spear phishing is harder to identify than mass phishing precisely because it is designed to look right. Verification must be active, not passive.
Ask yourself before acting:
- Did this request follow the normal process — or is it asking me to skip a step?
- Would this person normally contact me this way, through this channel?
- Can I verify this by speaking to the sender directly — not by replying to this email?
Verification steps:
- Never verify a financial or access request by replying to the email in question — contact the sender through a separate, known channel (phone, in-person, or a fresh message to their known address)
- Check the sender's full email address character by character — display names can be copied, domains cannot be exactly duplicated
- For any request involving money, credentials, or sensitive data — apply a second-approval rule: no single email should be sufficient authorisation
- Search for the email address or domain in tools like MXToolbox or VirusTotal if you are uncertain
- If an attachment arrives unexpectedly, scan it at VirusTotal before opening — even if the sender appears familiar
Legitimate vs spear phishing — how to tell:
| Legitimate communication | Spear phishing |
|---|---|
| Follows established internal processes and approval chains | Requests you bypass normal procedures, "just this once" |
| Sender can be confirmed through a separate channel | Sender cannot be reached by phone or gives evasive answers |
| Financial requests include formal documentation | Financial requests arrive by email alone, with urgency |
| Attachments were expected and discussed in advance | Attachments arrive without warning or prior context |
How to Protect
How to protect yourself
For individuals:
- Audit your public digital footprint — the less personal and professional information is publicly visible on LinkedIn, social media, and company websites, the less material a spear phisher has to work with
- Enable multi-factor authentication (MFA) on all accounts — even if credentials are compromised, MFA prevents access
- Treat any email requesting financial action or credential sharing as requiring phone-based verification, regardless of how legitimate it appears
- Be cautious about sharing details of current projects, colleagues, or internal processes on public or semi-public platforms
For organisations:
- Implement a strict two-person authorisation rule for all wire transfers and payment detail changes — no single email should be sufficient
- Train staff to verify financial and access requests through a secondary channel before acting
- Deploy email authentication protocols: DMARC, DKIM, and SPF reduce the effectiveness of domain spoofing
- Run simulated spear phishing exercises — employees who have experienced a realistic simulation are significantly better at recognising real attacks
- Security awareness training consistently reduces phishing susceptibility from an industry baseline of ~33% to under 5% (KnowBe4, 2025)
If you have already been targeted:
- Do not reply to or forward the suspicious email
- Report immediately to your IT or security team if in an organisational context
- Change credentials for any accounts you may have accessed or shared
- Contact your bank immediately if any financial transfer was initiated
- Preserve the original email with full headers for forensic investigation
- Report to your national cybercrime authority
Useful tools:
| Tool | What it does | Cost |
|---|---|---|
| Proofpoint Email Protection | Enterprise-grade spear phishing detection and filtering | Paid |
| MXToolbox | Check email domain authentication (DMARC, SPF, DKIM) | Free |
| VirusTotal | Scan suspicious attachments and URLs | Free |
| KnowBe4 | Simulated phishing training for organisations | Paid |
Video Lesson
Watch: Spear phishing explained
A practical walkthrough of how spear phishing attacks are constructed, what distinguishes them from generic phishing, and the specific signals to look for when evaluating a suspicious targeted email. Suitable for both individuals and employees without a technical background.
Further Reading
Further reading
Official resources
- CISA (Cybersecurity & Infrastructure Security Agency) — Guidance on recognising and defending against targeted phishing → cisa.gov/topics/cyber-threats-and-advisories/phishing
- FBI Internet Crime Complaint Center (IC3) — Report spear phishing attempts and access annual cybercrime data → ic3.gov
- NCSC (UK National Cyber Security Centre) — Spear phishing guidance for organisations and individuals → ncsc.gov.uk/collection/phishing-scams
Research & reports
- IBM — "Cost of a Data Breach Report 2024" — financial impact data on phishing-initiated breaches → ibm.com/reports/data-breach
- Verizon — "Data Breach Investigations Report 2025" — industry breakdown of spear phishing as an initial attack vector → verizon.com/business/resources/reports/dbir
Investigative coverage
- Keepnet Labs — "10 Examples of Spear Phishing Attacks" — documented real-world cases from 2023–2024 → keepnetlabs.com
Related articles on this platform
- Phishing Email — the mass-volume form of phishing that spear phishing evolved from
- CEO Fraud / Business Email Compromise — spear phishing that targets executives for financial transfers
- Whaling Attack — spear phishing aimed specifically at C-suite executives