What is spear phishing?¶
Spear phishing is phishing that has been tailored to a particular person, role, organisation or small group.
The point of the tailoring is simple: make the message feel more believable to the target.
Personalisation can be very specific¶
A message might mention:
- the recipient's name;
- their manager;
- a supplier;
- a live project;
- an expected invoice;
- an internal system;
- a recent event.
For example:
That is more persuasive than a generic “your account is locked” message.
Accurate detail does not automatically mean insider access¶
The information may have come from:
- company websites;
- LinkedIn or social profiles;
- leaked data;
- previous messages;
- compromised accounts;
- public procurement material;
- earlier victims.
So if the lure contains correct internal-looking detail, ask where that information could realistically have come from.
Compare variants across targets¶
If several recipients received similar messages, compare:
- wording;
- links;
- attachment names;
- subject lines;
- personalisation fields;
- sending infrastructure;
- timing.
Automation can personalise hundreds of messages. Tailoring does not necessarily mean somebody researched each target manually.
Use tailoring as evidence of method¶
The fact that a message is highly personalised may tell you something useful about preparation and target selection.
It does not by itself identify the sender.
The practical point is: spear phishing is targeted social engineering. Preserve the personalisation and investigate where the information came from, but do not treat accurate detail as automatic proof of insider access.