Overview
Direct Answer
Spear phishing is a highly targeted social engineering attack that uses personalised deceptive communications to manipulate specific individuals, teams, or organisations into disclosing sensitive information or granting system access. Unlike mass phishing campaigns, it exploits reconnaissance data about the victim to increase credibility and success rates.
How It Works
Attackers conduct detailed research on targets using public sources such as LinkedIn, company websites, and social media to gather names, roles, relationships, and business activities. They then craft messages that impersonate trusted contacts or organisations, referencing specific details that lower recipient suspicion and increase the likelihood of credential theft, malware installation, or wire fraud. The personalised nature of these communications makes them significantly harder to detect through automated filtering systems.
Why It Matters
Spear phishing poses substantial financial and reputational risk to organisations, often serving as the initial vector for data breaches, ransomware deployment, and insider threat facilitation. Regulatory compliance frameworks including GDPR and NIS2 require demonstrable security controls against such targeted attacks, making employee training and detection infrastructure critical investments.
Common Applications
Financial institutions face attacks targeting treasury and procurement staff to authorise fraudulent transfers. Healthcare organisations experience campaigns impersonating administrative personnel to access patient records. Enterprise security teams frequently observe phishing targeting executives and system administrators to compromise privileged accounts.
Key Considerations
Detection remains challenging because legitimate business communication patterns are exploited; organisational context and relationship verification become essential defences rather than purely technical controls. No single defensive mechanism addresses this threat comprehensively.
Cross-References(1)
More in Cybersecurity
Attack Vector
Offensive SecurityThe specific path, method, or scenario used by an attacker to gain unauthorised access to a system.
Incident Response Plan
Defensive SecurityA documented set of procedures for detecting, responding to, and recovering from cybersecurity incidents.
NIST Cybersecurity Framework
Security GovernanceA set of voluntary guidelines for managing and reducing cybersecurity risk developed by the US National Institute of Standards.
Breach and Attack Simulation
Offensive SecurityAutomated security testing that continuously simulates real-world attack scenarios against production environments to validate defensive controls and identify security gaps.
Data Loss Prevention
Data ProtectionTechnology and processes that prevent sensitive data from being lost, misused, or accessed by unauthorised users.
Secrets Management
Identity & AccessThe secure storage, distribution, rotation, and auditing of sensitive credentials such as API keys, tokens, passwords, and certificates used by applications and services.
Secure Access Service Edge
Network SecurityA cloud architecture that converges networking and security services including SD-WAN, firewall, and zero trust access into a unified cloud-delivered platform.
Cloud Security Posture Management
Security GovernanceAutomated tools that continuously assess cloud infrastructure configurations against security best practices and compliance requirements, identifying and remediating misconfigurations.