What is spear phishing?¶
Spear phishing is phishing tailored towards a particular person, role, organisation or group.
Avoid the dangerous assumption¶
The dangerous assumption is that personalisation proves the sender had inside knowledge or direct access to the victim.
The information may have come from public websites, social media, professional profiles, leaked data, previous correspondence, compromised accounts or another victim.
A spear-phishing message may refer to:
- the recipient’s name or role
- a current project
- a known colleague
- a supplier or customer
- a recent event
- an expected invoice
- an internal process
- a realistic document or meeting invitation.
The purpose of the personalisation is to make the request appear credible and reduce suspicion.
Investigators should identify which details were used and where they may have come from. This can reveal preparatory activity, prior compromise or links between incidents.
But avoid assuming that every accurate detail was obtained unlawfully. Much organisational information is publicly available or routinely shared.
Preserve the message, associated attachments and links, and compare similar communications received by other staff or organisations. Small variations may show that a template was adapted for different targets.
Ask whether a legitimate account was used. Messages sent from a compromised colleague or supplier account may appear especially convincing and may bypass simple warning signs.
The level of tailoring may help show targeting and planning. It does not necessarily identify the offender or prove that the target was selected for a specific personal reason.
A targeted message may still be part of a large automated campaign using collected data.
Operational takeaway¶
Treat spear phishing as tailored social engineering, identify how the personal details may have been obtained and avoid assuming that personalisation proves insider access or offender identity.