Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is spear phishing?

Spear phishing is phishing that has been tailored to a particular person, role, organisation or small group.

The point of the tailoring is simple: make the message feel more believable to the target.

Personalisation can be very specific

A message might mention:

  • the recipient's name;
  • their manager;
  • a supplier;
  • a live project;
  • an expected invoice;
  • an internal system;
  • a recent event.

For example:

Example targeted lure
To: beth@northmere.exampleSubject: NorthNet renewal invoice - approval needed todayBody references: Finance team, supplier NorthNet, current renewal month

That is more persuasive than a generic “your account is locked” message.

Accurate detail does not automatically mean insider access

The information may have come from:

  • company websites;
  • LinkedIn or social profiles;
  • leaked data;
  • previous messages;
  • compromised accounts;
  • public procurement material;
  • earlier victims.

So if the lure contains correct internal-looking detail, ask where that information could realistically have come from.

Compare variants across targets

If several recipients received similar messages, compare:

  • wording;
  • links;
  • attachment names;
  • subject lines;
  • personalisation fields;
  • sending infrastructure;
  • timing.
Base lureSame attack themeInvoice, password reset, payment request.
Target detailName, role or projectMakes the lure feel specific.
DeliveryMessage sent to selected targetSame campaign can still operate at scale.

Automation can personalise hundreds of messages. Tailoring does not necessarily mean somebody researched each target manually.

Use tailoring as evidence of method

The fact that a message is highly personalised may tell you something useful about preparation and target selection.

It does not by itself identify the sender.

The practical point is: spear phishing is targeted social engineering. Preserve the personalisation and investigate where the information came from, but do not treat accurate detail as automatic proof of insider access.

Reference: CIM-031Cyber Incidents & Offender Methods