What Is Spear Phishing?
Spear phishing is a targeted social-engineering attack tailored to a specific person, role, or organization.
Attackers research relationships, projects, suppliers, and writing patterns to create a credible request. The message may steal credentials, deliver malware, obtain data, or redirect a payment.
Key Takeaways
- Executive and employee impersonation is a central category or capability.
- Reliable assessment requires identity, timing, source, and operational context.
- Detection should correlate external, identity, device, network, and cloud evidence.
- Response should preserve evidence and remove every reusable access path.

How Spear Phishing Works
The sequence above provides a practical operating model. Individual stages may overlap, repeat, or involve different people and services, so analysts should validate each step against the available evidence.
Attackers research relationships, projects, suppliers, and writing patterns to create a credible request. The message may steal credentials, deliver malware, obtain data, or redirect a payment.
Common Types and Techniques
- Executive and employee impersonation
- Vendor and partner pretexts
- Credential and session phishing
- Malicious attachments and cloud links
Security and Business Risks
- Account takeover and data theft
- Business email compromise
- Malware and ransomware delivery
- Financial fraud and reputational damage

Warning Signs and Detection
Check sender and reply-to domains, thread history, link ownership, unusual requests, new sessions, OAuth grants, mailbox rules, and follow-on financial activity.
Prevention and Response
Use phishing-resistant MFA, email authentication, domain monitoring, safe attachment controls, independent verification, staff reporting, and rapid session revocation.
How SOCRadar Can Help
SOCRadar combines external visibility, threat intelligence, Dark Web monitoring, brand protection, vulnerability context, and indicator enrichment to help teams investigate exposure connected to spear phishing.
Explore SOCRadar Brand Protection or request a demo to strengthen threat-informed prevention and response.
Frequently Asked Questions
What Is Spear Phishing and How Does It Differ from General Phishing?
Spear phishing is a targeted social-engineering attack tailored to a specific person, role, or organization. Unlike mass phishing, it uses researched details such as names, projects, suppliers, and writing patterns to make a request look credible. The objective is usually to steal credentials, deliver malware, obtain data, or redirect a payment.
Why Do Attackers Research Their Targets Before Sending a Spear Phishing Email?
Personalization dramatically increases the chance that a recipient trusts the message. Attackers pull relationships, project names, vendor details, and writing style from public sources, breached data, and social media so the request blends into normal workflows. This preparation also helps the email slip past filters tuned to catch generic spam.
What Are the Most Common Spear Phishing Techniques?
Common techniques include executive and employee impersonation, vendor and partner pretexts, credential and session phishing, and malicious attachments or cloud links. Attackers often combine them, for example by spoofing a CEO to request an urgent wire transfer or imitating a supplier with a revised invoice and a hosted document link.
Which Roles Face the Highest Spear Phishing Risk?
Finance, HR, and IT teams are frequent targets because they move money, hold sensitive data, and control access. Executives are heavily impersonated because their authority pressures employees into fast action. Anyone with privileged credentials or payment approval should be treated as a high-risk target.
How Can I Recognize a Spear Phishing Message Before Clicking?
Check the sender and reply-to domains, thread history, and link ownership, and ask whether the request is unusual for that relationship. Urgent payment changes, credential requests, and unexpected attachments or OAuth prompts should be verified independently through a known channel before any action is taken.
What Should I Do Immediately After Falling for a Spear Phishing Email?
Report it to IT or the security team right away and preserve the original message as evidence. Revoke active sessions, reset affected credentials, and review mailbox rules and OAuth grants for attacker changes. Monitor follow-on financial activity, since attackers often move to payment fraud within hours.
How Does Spear Phishing Lead to Business Email Compromise and Financial Fraud?
A single compromised mailbox gives attackers access to real thread history, letting them impersonate the victim and insert fraudulent payment instructions into legitimate conversations. From there they can redirect invoices, request wire transfers, and target the victim’s customers and partners, multiplying the financial and reputational damage.
What Controls Most Effectively Prevent Spear Phishing Attacks?
Prioritize phishing-resistant MFA, email authentication such as SPF, DKIM, and DMARC, domain monitoring, and safe attachment controls. Pair these with independent verification of financial requests, a culture of staff reporting, and the ability to revoke sessions rapidly when account takeover is suspected.
How Should Organizations Detect Spear Phishing Beyond Email Filtering?
Correlate external, identity, device, network, and cloud evidence instead of relying on the email gateway alone. Watch for new sessions, unexpected OAuth grants, mailbox rule changes, lookalike domains, and unusual financial activity, and validate identity, timing, source, and operational context for every alert.
