What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Spear phishing is a targeted phishing attack tailored to a particular person or organization. The attacker uses details about the intended victim—often gathered from social media, company pages, or other public sources—to make an email, text, or other message look credible. The usual aim is to steal credentials, deliver malware, or persuade the recipient to disclose sensitive information or authorize a payment.

How spear phishing differs from ordinary phishing

Broad phishing campaigns send similar lures to many recipients. Spear phishing selects a target and customizes the message around that person, their role, their employer, or a current business context. Personalization is the defining feature; it does not guarantee advanced malware or an especially sophisticated technical attack.

Form Targeting Typical lure
Phishing Broad, often sent at scale A generic account alert or delivery notice
Spear phishing A selected individual or organization A message referring to the recipient’s role, supplier, project, or colleague
Whaling Senior executives An executive matter such as a wire transfer, legal issue, or confidential document
Smishing Any target, by text message A text asking the recipient to tap a link or call a number
Vishing Any target, by voice A caller impersonating a bank, help desk, supplier, or official
Business email compromise (BEC) A business and its payment or information workflows A spoofed or compromised account requesting money, account data, or a change in payment details

Spear phishing can be one route into a BEC incident, while whaling, smishing, and vishing describe the target or communication channel.

How a spear-phishing attack works

1. Reconnaissance

The attacker gathers useful context from public profiles, company websites, job listings, social posts, or previously exposed information. They may learn a person’s manager, suppliers, projects, travel, or software systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Impersonation and pretext

The attacker poses as a familiar person or organization: a manager, vendor, colleague, bank, cloud service, or support team. A display name can look correct even when the underlying address is not.

3. A tailored request

The message may ask the recipient to sign in, update an account, open a document, share a password, transfer money, or provide other sensitive information. Urgency and authority are commonly used to discourage checking.

4. Credential theft or malware delivery

A link can lead to a counterfeit sign-in page, while an attachment or download can install malware. Microsoft notes that malware may provide remote control and create an entry point for follow-on activity.

5. Follow-on activity

Stolen credentials can be used to access mail or other services, impersonate the victim, search for additional targets, or continue a payment or data-theft scheme. The first message may therefore be only the entry point.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Concrete examples

Vendor account update

An employee receives a message that appears to come from a regular supplier. It refers to the supplier’s normal business relationship and asks the employee to update a billing or business account through a provided link. The link leads to a fake sign-in page designed to capture credentials.

Boss requests a password

A message that looks like it is from a manager says an urgent issue requires the employee’s network password. A request for a password by email is unsafe even when the sender appears familiar; legitimate administrators should provide a separate, approved process.

Historical Office-attachment case

A 2018 CISA advisory described actors researching organizations with public information and sending tailored attachments that used legitimate Microsoft Office functionality to retrieve remote content. The technique could expose a credential hash. This is a historical case study, not proof that every current spear-phishing attachment uses the same method.

How to recognize a spear-phishing message

  • Unexpected action: the message asks you to sign in, change payment details, open a document, reveal a password, or provide sensitive information.
  • Urgency or secrecy: pressure to act immediately or avoid normal approval channels.
  • Imitated sender: a display name or address that resembles a legitimate person or business but contains a different domain, spelling, or reply address.
  • Link mismatch: the text describes one destination while the actual link points somewhere else. On a computer, inspect the destination without opening it; on a phone, use an approved alternative verification method.
  • Suspicious attachment: an unexpected Office file, archive, executable, or document that asks you to enable content or macros.
  • Personal details used as proof: the message mentions your job, coworkers, or recent activity. Such details may have been collected publicly and do not establish authenticity.

Do not judge a message solely by grammar. Carefully written language can be generated or copied, and a genuine-looking brand, signature, or conversation thread can be spoofed or taken over.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do before responding

  1. Stop. Do not click the message’s link, open its attachment, call its phone number, or reply with information.
  2. Verify the request through a separate, previously trusted channel. Call a known number, use an existing chat or ticket, or speak to the person in person—not contact details supplied in the suspicious message.
  3. For a service account, open the known official website by typing its address or using a trusted bookmark instead of following the message link.
  4. Use your organization’s normal approval process for payments, password resets, access changes, and confidential data.
  5. Report the message through the established IT or security channel so others can be warned and the message can be investigated.

Never send a password by email. The FTC specifically advises staff not to provide passwords or sensitive information in response to an email, even when it appears to come from a manager.

If you clicked, opened a file, or entered credentials

Treat the event as a potential security incident and report it promptly through your organization’s established IT or security process. Include what you clicked or opened, when it happened, what information you entered, and any unusual symptoms. Do not conceal the event because rapid reporting can limit further access.

Follow your organization’s instructions for isolating a device, changing credentials, revoking sessions, preserving evidence, and notifying affected parties. The correct sequence depends on the systems and account involved; a generic checklist cannot replace the organization’s incident-response procedure.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Layered defenses for individuals and organizations

No single control guarantees protection. Use layers that address account access, message delivery, potential blast radius, and human decision-making.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Defense layer What it reduces Practical implementation
Account protection Damage from stolen passwords Use unique, strong passwords stored in a password manager and enable multifactor authentication (MFA), especially for email, administrator, and financial accounts.
Email and cloud controls Delivery of obvious or known malicious lures Use provider anti-phishing protections, attachment and link scanning, domain-authentication controls, and reporting mechanisms available in the mail system.
Reduced blast radius Spread after an account or endpoint is compromised Separate email systems from critical assets where practical, limit privileges, segment important networks, and require additional approval for sensitive actions.
Staff readiness Successful social engineering Provide recurring training, teach separate-channel verification, make reporting easy, and assess readiness with authorized phishing simulations or campaigns.

CISA discusses password managers, MFA, cloud email protections, separation from critical assets, and phishing campaign assessments. The FTC recommends regular employee training because tactics change. These measures work together rather than serving as substitutes for one another.

Questions to ask when designing a response plan

  • Which accounts and systems are most valuable, and do they require MFA?
  • How will staff verify an unusual payment, password, or access request?
  • Where should a suspicious message be reported, and who can act on it?
  • Can a compromised mailbox or workstation reach critical systems?
  • How will the organization reset credentials, revoke sessions, preserve evidence, and communicate after a report?

Microsoft’s spear-phishing guidance was reported as updated on August 7, 2026. Attackers’ methods change, but the central test remains stable: an unexpected request that uses personal context should be verified independently before any action is taken.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.