What Is Spear Phishing? A Targeted Attack Guide for Business
Spear phishing is a targeted form of phishing attack crafted specifically for the recipient, using personal information to appear legitimate. Unlike mass phishing campaigns, spear phishing targets a named individual using their role, relationships and current context. It is harder to spot, more likely to succeed and the entry point for the most damaging attacks on UK businesses.
Nathan Hill-Haimes
Technical Director
It is the entry point for the most damaging attacks on UK businesses, and the single biggest reason phishing remains the dominant breach type year after year. Phishing was identified as the cause by 85% of businesses and 86% of charities that suffered a breach in the 2025 survey (UK Government, Cyber Security Breaches Survey 2025). Spear phishing is the sharp end of that statistic.
How is spear phishing different from regular phishing?
Standard phishing blasts the same generic message to thousands of recipients and hopes a few bite. Spear phishing targets one named individual, researched in advance, with an email built around their real role, colleagues and current work. That personalisation is exactly what makes it convincing — and dangerous.
Generic phishing reads like a template: "Your account has been suspended", "You have a package waiting", "Verify your password". A spear phishing email reads like a message from someone you actually know, about something you are plausibly involved in. The result looks legitimate because it is built from real information about a real person.
| Factor | Standard phishing | Spear phishing |
|---|---|---|
| Target | Thousands at random | One named individual |
| Research | None | Hours of reconnaissance |
| Content | Generic template | Personalised to role and context |
| Volume | Bulk send | Single or low volume |
| Filter evasion | Often caught | Frequently bypasses filters |
| Typical payoff | Low per victim | Very high (BEC, fund transfer) |
How do attackers research their targets?
Reconnaissance is systematic, and AI tooling has made it fast. An attacker spending an hour can map a target's reporting lines, current projects and likely concerns — enough to craft a highly convincing email. They pull from public sources most businesses never think to lock down.
Common intelligence sources include:
- LinkedIn — role, responsibilities, who they report to, recent activity and connections
- Company website — team pages, recent news, client announcements and case studies
- Social media — X, Instagram and Facebook activity, both personal and professional
- Previous data breaches — leaked email and password pairs that confirm a live address
- Public company records — Companies House filings, press releases and procurement notices
The NCSC notes that attackers routinely combine open-source detail like this to make a message land (NCSC phishing guidance). The less your senior staff expose publicly, the harder this first step becomes.
What are the most common spear phishing scams?
Four patterns account for most of the damage: business email compromise, IT help desk impersonation, vendor invoice fraud and whaling. Each exploits trust and urgency rather than a technical flaw, which is why they slip past tools that only look for malicious links or attachments.
Business Email Compromise (BEC)
The most financially damaging variant. The attacker impersonates a senior executive — CEO or Finance Director — and emails a finance team member with an urgent request to move funds to a new account. The message references real context, such as "for the acquisition I mentioned on our call last week", and uses pressure to discourage verification. Over £4 million was stolen from UK law firms alone through BEC-style fraud in a single reporting year (UK market data, 2025); financial services, professional services and larger commercial organisations are equally targeted.
IT help desk impersonation
The attacker poses as your IT support team and references a specific tool or system the target genuinely uses. The email asks them to confirm credentials, install a "security update" or click a link to "resolve an urgent account issue". Strong phishing protection and a clear internal reporting route blunt this one quickly.
Vendor and invoice fraud
The attacker impersonates a known supplier and sends a revised invoice with new banking details, referencing real recent interactions. Without a telephone check of the change, payment lands in the attacker's account. A single mandatory callback procedure prevents almost all of these.
Whaling
Whaling is spear phishing aimed squarely at senior executives — the "whales". These attacks take more effort but the payoff is higher: executives control financial transactions, hold sensitive data, and lend credibility to follow-on attacks against their own staff.
Why is spear phishing so hard to stop?
Standard email filters are excellent at catching bulk phishing — known bad domains, mass-send patterns, generic content. Spear phishing sidesteps those controls because it is low-volume, contextual, and sometimes carries no malicious payload at all. There is nothing technical for a signature-based filter to flag.
Specifically, spear phishing evades many defences because:
- It is sent individually or in small batches, avoiding bulk-send reputation triggers
- It may originate from compromised legitimate accounts or lookalike domains that pass SPF
- The content reads as relevant and contextual, not generic and suspicious
- Pure BEC attacks contain no link or attachment — only social engineering
This is why behavioural email security, which models writing style, sender-recipient history and contextual anomalies, outperforms signature-based filtering against spear phishing. It is also why email protection should connect into your wider Microsoft 365 security posture rather than sit in isolation.
How do you defend against spear phishing?
Defence is layered: technical controls to detect impersonation, and process controls to make fraudulent requests fail even when an email gets through. Neither is sufficient alone. The businesses that get hit hardest are those relying on a single filter and staff goodwill.
Technical controls
- AI-based impersonation detection — Microsoft Defender for Business and equivalent platforms analyse metadata, writing patterns and sender relationships to flag impersonation even when technical indicators are absent
- DMARC with a reject policy — stops attackers exactly spoofing your domain, so staff cannot receive "CEO" emails sent from your own address
- External-sender and display-name banners — flag messages that come from outside but display an internal or executive name
- Multi-factor authentication — prevents stolen credentials from being used to send spear phishing from a legitimate mailbox
Process controls
- Payment verification procedure — any request to change supplier bank details or make an urgent transfer must be confirmed by phone to a known number, never by replying to the email
- A callback culture — make verifying unexpected requests by phone the expected norm, not an insult; it is a professional control
- Targeted training — generic awareness training does not prepare people for personalised attacks; use realistic scenarios that mirror how spear phishing actually reads
When an attack does land, fast containment matters. A defined incident response plan and continuous managed detection and response are what turn a near-miss into a non-event rather than a headline.
Could Your Team Spot a Spear Phishing Email?
AMVIA's spear phishing simulation uses personalised, realistic scenarios to test your team's awareness — providing the data you need to target training where it matters most.
Frequently Asked Questions
Spear phishing targets any specific individual using personalised information. Whaling is a subset that targets senior executives — CEOs, CFOs and board members — because they control financial transactions and sensitive data. Whaling attacks are usually more heavily researched and more convincing than general spear phishing, reflecting the larger potential payoff.
Standard anti-spam filters are far less effective against spear phishing because the attacks are low-volume, contextually relevant, and often carry no malicious link or attachment. Behavioural email security that analyses sender-recipient history, writing-style anomalies and unusual urgency markers detects these attacks far better than signature or reputation-based filtering alone.
Do not click links, open attachments or reply. If it claims to come from a colleague or known contact, verify the request by phone using a number you already hold — not one in the email. Report it to your IT team or security provider, who can check whether others received it and block the sending domain. The NCSC also publishes UK reporting routes for suspicious emails.
DMARC with a reject policy stops attackers exactly spoofing your domain, such as ceo@yourcompany.co.uk. It does not stop lookalike domains (ceo@your-company.co.uk) or display-name spoofing, where a different domain is labelled "Sarah Jones, CEO". DMARC is necessary but not sufficient — impersonation detection and display-name banners cover the remaining gaps.
AI lets attackers scale personalisation, generating individual emails for hundreds of targets by pulling in LinkedIn, website and social data. It can mimic a person's vocabulary and tone to make impersonation more convincing, and AI-generated deepfake audio has been used in voice phishing that impersonates executives by phone. The reconnaissance that once took an hour now takes minutes.
Related Reading
Phishing Protection for UK Businesses | AMVIA Guide
The technical and training controls that protect against both generic phishing and targeted spear phishing.
Email Encryption for Business | AMVIA Guide
How email encryption works alongside anti-phishing controls for comprehensive email security.
Cybersecurity for Legal Firms | UK Law Firm Security Guide
Spear phishing and BEC are the leading cyber threats for UK law firms — this guide covers the specific defences needed.
Protect your business → Get Cybersecurity Assessment