What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Spear phishing is a targeted phishing attack tailored to a particular person or organization. The attacker uses details about the intended victim—often gathered from social media, company pages, or other public sources—to make an email, text, or other message look credible. The usual aim is to steal credentials, deliver malware, or persuade the recipient to disclose sensitive information or authorize a payment.
How spear phishing differs from ordinary phishing
Broad phishing campaigns send similar lures to many recipients. Spear phishing selects a target and customizes the message around that person, their role, their employer, or a current business context. Personalization is the defining feature; it does not guarantee advanced malware or an especially sophisticated technical attack.
| Form | Targeting | Typical lure |
|---|---|---|
| Phishing | Broad, often sent at scale | A generic account alert or delivery notice |
| Spear phishing | A selected individual or organization | A message referring to the recipient’s role, supplier, project, or colleague |
| Whaling | Senior executives | An executive matter such as a wire transfer, legal issue, or confidential document |
| Smishing | Any target, by text message | A text asking the recipient to tap a link or call a number |
| Vishing | Any target, by voice | A caller impersonating a bank, help desk, supplier, or official |
| Business email compromise (BEC) | A business and its payment or information workflows | A spoofed or compromised account requesting money, account data, or a change in payment details |
Spear phishing can be one route into a BEC incident, while whaling, smishing, and vishing describe the target or communication channel.
How a spear-phishing attack works
1. Reconnaissance
The attacker gathers useful context from public profiles, company websites, job listings, social posts, or previously exposed information. They may learn a person’s manager, suppliers, projects, travel, or software systems.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
2. Impersonation and pretext
The attacker poses as a familiar person or organization: a manager, vendor, colleague, bank, cloud service, or support team. A display name can look correct even when the underlying address is not.
3. A tailored request
The message may ask the recipient to sign in, update an account, open a document, share a password, transfer money, or provide other sensitive information. Urgency and authority are commonly used to discourage checking.
4. Credential theft or malware delivery
A link can lead to a counterfeit sign-in page, while an attachment or download can install malware. Microsoft notes that malware may provide remote control and create an entry point for follow-on activity.
5. Follow-on activity
Stolen credentials can be used to access mail or other services, impersonate the victim, search for additional targets, or continue a payment or data-theft scheme. The first message may therefore be only the entry point.
Concrete examples
Vendor account update
An employee receives a message that appears to come from a regular supplier. It refers to the supplier’s normal business relationship and asks the employee to update a billing or business account through a provided link. The link leads to a fake sign-in page designed to capture credentials.
Boss requests a password
A message that looks like it is from a manager says an urgent issue requires the employee’s network password. A request for a password by email is unsafe even when the sender appears familiar; legitimate administrators should provide a separate, approved process.
Historical Office-attachment case
A 2018 CISA advisory described actors researching organizations with public information and sending tailored attachments that used legitimate Microsoft Office functionality to retrieve remote content. The technique could expose a credential hash. This is a historical case study, not proof that every current spear-phishing attachment uses the same method.
How to recognize a spear-phishing message
- Unexpected action: the message asks you to sign in, change payment details, open a document, reveal a password, or provide sensitive information.
- Urgency or secrecy: pressure to act immediately or avoid normal approval channels.
- Imitated sender: a display name or address that resembles a legitimate person or business but contains a different domain, spelling, or reply address.
- Link mismatch: the text describes one destination while the actual link points somewhere else. On a computer, inspect the destination without opening it; on a phone, use an approved alternative verification method.
- Suspicious attachment: an unexpected Office file, archive, executable, or document that asks you to enable content or macros.
- Personal details used as proof: the message mentions your job, coworkers, or recent activity. Such details may have been collected publicly and do not establish authenticity.
Do not judge a message solely by grammar. Carefully written language can be generated or copied, and a genuine-looking brand, signature, or conversation thread can be spoofed or taken over.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhat to do before responding
- Stop. Do not click the message’s link, open its attachment, call its phone number, or reply with information.
- Verify the request through a separate, previously trusted channel. Call a known number, use an existing chat or ticket, or speak to the person in person—not contact details supplied in the suspicious message.
- For a service account, open the known official website by typing its address or using a trusted bookmark instead of following the message link.
- Use your organization’s normal approval process for payments, password resets, access changes, and confidential data.
- Report the message through the established IT or security channel so others can be warned and the message can be investigated.
Never send a password by email. The FTC specifically advises staff not to provide passwords or sensitive information in response to an email, even when it appears to come from a manager.
If you clicked, opened a file, or entered credentials
Treat the event as a potential security incident and report it promptly through your organization’s established IT or security process. Include what you clicked or opened, when it happened, what information you entered, and any unusual symptoms. Do not conceal the event because rapid reporting can limit further access.
Follow your organization’s instructions for isolating a device, changing credentials, revoking sessions, preserving evidence, and notifying affected parties. The correct sequence depends on the systems and account involved; a generic checklist cannot replace the organization’s incident-response procedure.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Layered defenses for individuals and organizations
No single control guarantees protection. Use layers that address account access, message delivery, potential blast radius, and human decision-making.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsBest Value
| Defense layer | What it reduces | Practical implementation |
|---|---|---|
| Account protection | Damage from stolen passwords | Use unique, strong passwords stored in a password manager and enable multifactor authentication (MFA), especially for email, administrator, and financial accounts. |
| Email and cloud controls | Delivery of obvious or known malicious lures | Use provider anti-phishing protections, attachment and link scanning, domain-authentication controls, and reporting mechanisms available in the mail system. |
| Reduced blast radius | Spread after an account or endpoint is compromised | Separate email systems from critical assets where practical, limit privileges, segment important networks, and require additional approval for sensitive actions. |
| Staff readiness | Successful social engineering | Provide recurring training, teach separate-channel verification, make reporting easy, and assess readiness with authorized phishing simulations or campaigns. |
CISA discusses password managers, MFA, cloud email protections, separation from critical assets, and phishing campaign assessments. The FTC recommends regular employee training because tactics change. These measures work together rather than serving as substitutes for one another.
Questions to ask when designing a response plan
- Which accounts and systems are most valuable, and do they require MFA?
- How will staff verify an unusual payment, password, or access request?
- Where should a suspicious message be reported, and who can act on it?
- Can a compromised mailbox or workstation reach critical systems?
- How will the organization reset credentials, revoke sessions, preserve evidence, and communicate after a report?
Microsoft’s spear-phishing guidance was reported as updated on August 7, 2026. Attackers’ methods change, but the central test remains stable: an unexpected request that uses personal context should be verified independently before any action is taken.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

