Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Reconnaissance helps attackers make spear-phishing feel personal: they gather names, contact details, roles, and other context, then use it to build a plausible pretext. It is an established part of targeted phishing, not a proven new or rapidly growing trend. A tailored message may be persuasive without being technically sophisticated; the information gathering, the lure, and any later credential theft or malware are separate stages.

How do attackers know enough to make a phishing message look real?

They can assemble useful details from publicly available information and organizational clues. Microsoft describes attackers surveying social media and other sources. CISA’s red team, in a three-month assessment conducted in 2022 and described in a 2023 report, researched potential targets, identified names and email addresses, and looked at a naming scheme that could help derive addresses. The team then sent tailored spear-phishing messages to seven targets. CISA’s assessment is a bounded example of the method, not a measure of how often it occurs.

Details such as a person’s job, colleagues, projects, or normal communication channels can help an attacker choose whom to contact and invent a credible reason to do so. A message that refers to a real role or relationship may look more relevant, but those details do not prove the sender is legitimate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where reconnaissance fits in a phishing attack

Reconnaissance is the preparation that informs targeting and pretext; it is not the phishing message itself and does not establish what happens after a target responds. The joint CISA, NSA, FBI, and MS-ISAC phishing guidance describes phishing as social engineering and discusses credential theft and malware deployment. Microsoft’s phishing investigation playbook describes possible downstream consequences including data exfiltration and lateral movement.

  1. Reconnaissance: Gather information that helps select targets and shape a plausible approach.
  2. Social engineering: Send a message or make contact designed to prompt a response, disclosure, click, or approval.
  3. Attempted compromise: Depending on the lure, seek credentials, deliver malware, or gain access through another action.
  4. Follow-on activity: If access succeeds, investigate for related identity or endpoint activity, data theft, or movement into other systems.

Not every campaign uses every stage, and a convincing pretext does not mean an account or device has been compromised.

Why targeted attacks can move between channels

Attackers are not limited to email. In a 2025 alert, the FBI described actors impersonating senior officials through SMS and AI-generated voice messages to establish rapport, then moving targets to another messaging platform and sending a malicious link. This is a reported example, not evidence that AI-enabled phishing has a particular prevalence or growth rate. Read the FBI alert.

In a separate 2024 advisory, the FBI assessed that AI can increase the speed, scale, and automation of existing schemes. That assessment does not quantify a rate of change. Read the FBI advisory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to protect an organization from targeted phishing

No single control covers every stage or channel. Combine user reporting, message defenses, and authentication protections, then investigate promptly when a lure gets through.

Control What it addresses Implementation consideration
Phishing-resistant MFA Can interrupt an attempt to use stolen credentials to access an account or system. Choose authentication that is genuinely phishing-resistant; not all MFA methods provide the same protection. Check that accounts and devices support the method. CISA recommends phishing-resistant MFA, and its red-team report records an MFA prompt preventing access to one sensitive business system.
Training and reporting Helps staff recognize suspicious approaches and get them to responders quickly. Make reporting easy to find and low-friction, and connect reports to a defined response process. CISA recommends awareness and training.
Email indicators and gateway filtering Helps users identify external messages and systems filter suspicious email. Configure and maintain controls; do not treat email filtering as protection against SMS, voice, or other channels.
Incident response across email, identity, and endpoints Checks whether a suspicious message led to credential use, malware, or other activity. Route reports for prompt investigation across relevant environments, rather than closing the case at the message itself. Microsoft’s playbook outlines this cross-environment approach.

CISA’s joint phishing guidance recommends phishing-resistant MFA, while its ransomware guide covers training and other controls for phishing and credential access. For teams considering a FIDO2 security key, treat it as one possible way to implement phishing-resistant authentication, not a universal fit: verify support for the organization’s accounts and devices before deployment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the CISA case does—and does not—show

CISA’s 2023 advisory documents a 2022 red-team exercise in which researchers sent tailored spear-phishing messages to seven targets after identifying names and email addresses. The report says an MFA prompt prevented access to one sensitive business system. That illustrates both targeted preparation and a control interrupting an access attempt; it does not establish how common reconnaissance-led phishing is, or that the same control will stop every attack.

Microsoft likewise describes reconnaissance as typical spear-phishing behavior, so “next evolution” is best understood as a headline framing rather than a claim that the practice is new. The cited material does not establish a representative prevalence or growth figure for reconnaissance-first phishing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.