Glossary
What is spear-phishing?
Spear-phishing is a targeted form of phishing aimed at a specific person, team or organisation.
- Also known as
- Targeted phishing
- Channel
- Mostly email; also chat apps and phone
- Typical goal
- Access to a specific account, system or payment
- Related term
- Business email compromise
How it works
Researched, tailored,
timed.
- 01
Pick a target
Someone with the access the attacker wants: finance, HR, IT admins, executives or their assistants.
- 02
Research
Public profiles, company news and supplier lists give names, projects and language to borrow.
- 03
Tailor
The message references real context, such as a current deal, a colleague or an upcoming event.
- 04
Strike
A single well-timed message asks for a login, a file, a code or a payment.
How to spot it
Familiar details are
not proof of identity.
Spear-phishing feels safe because it knows things about you. That familiarity is the tactic.
Warning signs
- Personal details used to build instant trust
- Sender address differs from the colleague’s usual one
- Request to sign in, share a file or pay
- Tight deadline tied to a real event
- Asks you to keep it confidential or skip the usual process
Verify through a known contact, then report.
Questions buyers ask
Frequently asked questions.
What is the difference between phishing and spear-phishing?
Phishing is usually generic and sent to many people. Spear-phishing is tailored to a specific person or group using researched details.
Who is most often targeted by spear-phishing?
People with access to money, data or systems, such as finance teams, HR, IT administrators, executives and their assistants.
What is whaling?
Whaling is spear-phishing aimed at senior executives, often using business-critical pretexts such as legal matters or acquisitions.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo