What Is Spear Phishing and How Does It Differ from Regular Phishing?
Spear phishing is a targeted email attack aimed at one named person, using personal details - their job title, manager, supplier names, recent projects - to look legitimate.
Written by Nathan Hill-Haimes, Co-Founder, AMVIA
Quick answer
Spear phishing is a targeted email attack aimed at one named person, using personal details - their job title, manager, supplier names, recent projects - to look legitimate. Unlike mass phishing blasted to thousands, it is hand-built for a single victim, which is why it slips past filters and trained staff alike. Defending against it needs layered controls and one accountable provider.
Key Points
What you need to know.
The Short Answer
Phishing is the number one attack type - 85% of businesses that experienced a breach identified phishing as the cause (DSIT 2025).
For UK Businesses
Phishing was rated the most disruptive attack type by 69% of businesses that experienced one (DSIT 2025/26).
Cost Considerations
93% of incidents meeting the legal definition of cyber crime were phishing-based (DSIT 2025).
Next Steps
35% of businesses that experienced breaches reported impersonation of the organisation or staff.
Quick Comparison
| Feature | Option A | Option B |
|---|
Last updated: 27 June 2026.
What Does Spear Phishing Mean in Plain English?
Spear phishing is a precision con. The attacker researches a specific individual, then sends a message that references real people, real systems, or a real deal in progress so the request feels routine. Mass phishing plays the numbers; spear phishing plays the person.
The difference matters because the defences differ. Generic phishing is mostly caught by spam filters and basic awareness. Spear phishing is written to pass both. According to the UK Government's Cyber Security Breaches Survey 2025, 85% of businesses that experienced a breach identified phishing as the cause - the single most common attack vector. Targeted variants account for a disproportionate share of the breaches that actually cause damage.
To see where ordinary phishing ends and the targeted version begins, read our explainer on what phishing is, then come back here for the targeted threat. Both sit under our managed cybersecurity approach for UK SMEs.
How Is Spear Phishing Different from Mass Phishing?
The core difference is targeting and effort. Mass phishing is one template sent to thousands and costs the attacker almost nothing. Spear phishing is researched, personalised, and sent to one or a handful of people - higher effort, far higher hit rate, and much harder for filters to flag.
| Feature | Mass phishing | Spear phishing |
|---|---|---|
| Target | Thousands, untargeted | One named individual or small group |
| Personalisation | Generic ("Dear customer") | Real names, roles, suppliers, projects |
| Research | None | LinkedIn, company site, social media |
| Filter evasion | Often caught by spam filters | Frequently bypasses standard filters |
| Typical goal | Credential harvesting at scale | Wire fraud, data theft, account takeover |
| Success rate | Low per message | High per message |
Mass phishing is a volume business. Spear phishing is a sniper shot. That is why a single accountable provider running layered email, identity, and endpoint controls beats a stack of disconnected point products.
Who Do Spear Phishers Actually Target?
Attackers go where the money and access live: finance teams, senior executives (CEO and CFO), HR, and IT administrators. These roles can move funds, release sensitive data, or grant system access - so a single successful message can pay off immediately.
Business email compromise (BEC) is the most expensive form of spear phishing, where an attacker impersonates a director or supplier to authorise a fraudulent payment. Cybercrime losses are climbing: total losses reported to the FBI's Internet Crime Complaint Center rose 33% in 2024 versus 2023 (FBI IC3 2024 Annual Report). Impersonation is common too: 35% of businesses that experienced breaches reported others impersonating their organisation in emails or online (DSIT 2025).
Common spear phishing targets and why:
- Finance and accounts payable - can authorise and release payments.
- CEO / CFO and their EAs - high authority, often quoted in "urgent" requests.
- HR - holds payroll data and can be tricked into changing bank details.
- IT administrators - control accounts, MFA resets, and privileged access.
If your finance or exec teams are exposed, our email security and phishing protection hardens the inbox before a fake invoice ever lands.
How Does AI Make Spear Phishing Worse?
AI has collapsed the cost and time of producing convincing targeted emails. Attackers now generate grammatically perfect, on-brand messages at scale, mimic a known person's writing style, automate reconnaissance from public data, and even clone voices for follow-up phone calls (vishing).
The old advice - "look for spelling mistakes" - is dead. AI-written spear phishing reads exactly like a genuine internal email. The UK's National Cyber Security Centre is clear that organisations should assume some phishing will always reach inboxes and build layers that catch what slips through, rather than relying on staff to spot every fake.
This is why detection now matters as much as prevention. Our managed detection and response service watches for the account takeover that follows a successful spear phish, so a stolen credential does not become a full breach.
How do attackers research their targets?
Reconnaissance is systematic, and AI tooling has made it fast. An attacker spending an hour can map a target's reporting lines, current projects and likely concerns - enough to craft a highly convincing email. They pull from public sources most businesses never think to lock down.
Common intelligence sources include:
- LinkedIn - role, responsibilities, who they report to, recent activity and connections
- Company website - team pages, recent news, client announcements and case studies
- Social media - X, Instagram and Facebook activity, both personal and professional
- Previous data breaches - leaked email and password pairs that confirm a live address
- Public company records - Companies House filings, press releases and procurement notices
The NCSC notes that attackers routinely combine open-source detail like this to make a message land (NCSC phishing guidance). The less your senior staff expose publicly, the harder this first step becomes.
What are the most common spear phishing scams?
Four patterns account for most of the damage: business email compromise, IT help desk impersonation, vendor invoice fraud and whaling. Each exploits trust and urgency rather than a technical flaw, which is why they slip past tools that only look for malicious links or attachments.
Business Email Compromise (BEC)
The most financially damaging variant. The attacker impersonates a senior executive - CEO or Finance Director - and emails a finance team member with an urgent request to move funds to a new account. The message references real context, such as "for the acquisition I mentioned on our call last week", and uses pressure to discourage verification. Over £4 million was stolen from UK law firms alone through BEC-style fraud in a single reporting year (UK market data, 2025); financial services, professional services and larger commercial organisations are equally targeted.
IT help desk impersonation
The attacker poses as your IT support team and references a specific tool or system the target genuinely uses. The email asks them to confirm credentials, install a "security update" or click a link to "resolve an urgent account issue". Strong phishing protection and a clear internal reporting route blunt this one quickly.
Vendor and invoice fraud
The attacker impersonates a known supplier and sends a revised invoice with new banking details, referencing real recent interactions. Without a telephone check of the change, payment lands in the attacker's account. A single mandatory callback procedure prevents almost all of these.
Whaling
Whaling is spear phishing aimed squarely at senior executives - the "whales". These attacks take more effort but the payoff is higher: executives control financial transactions, hold sensitive data, and lend credibility to follow-on attacks against their own staff.
Can Email Filters Stop Spear Phishing on Their Own?
No. Standard spam filters miss most spear phishing because the emails are individually crafted, sent from legitimate-looking or genuinely compromised domains, and often contain no malware or obvious links - just a plausible request. Filters are necessary but never sufficient.
The realistic defence is layered, and identity is the weakest link in most UK businesses. "Only 47% of UK businesses have two-factor authentication in place (DSIT 2025/26)" - which means a stolen password is often the only thing standing between an attacker and a mailbox. Multi-factor authentication, conditional access, and anomaly detection close that gap.
What actually reduces spear phishing risk:
- Multi-factor authentication everywhere - even a phished password fails without the second factor.
- Advanced email security - AI-driven anomaly detection on top of spam filtering.
- Payment verification rules - out-of-band confirmation for any bank-detail or payment change.
- Targeted awareness training - for finance, exec, HR, and IT roles specifically.
- 24/7 detection - so a compromised account is caught in minutes, not weeks.
If turning on MFA properly across your tenant is the gap, follow our guide to setting up MFA across Microsoft 365. And if you suspect an account is already compromised, our incident response team can contain it. One provider, security-first, Microsoft-certified - so prevention, detection, and response are not three different phone calls.
Frequently Asked Questions
Spear phishing is a phishing attack aimed at one specific person, built from real details about them - their name, role, colleagues, or current work - so the message looks genuine. Unlike mass phishing sent to thousands, it is personalised to a single target, which is exactly why it is harder to spot and more likely to succeed.
Finance teams, senior executives (CEO and CFO), HR staff, and IT administrators are the most frequent targets because they control funds, sensitive data, or system access. Attackers research targets using LinkedIn, company websites, and social media before sending a tailored message that references real people or projects to lower the victim's guard.
AI lets attackers generate highly personalised, grammatically correct emails at scale. It can mimic a colleague's writing style, automate reconnaissance from public data, and even produce deepfake voice messages for follow-up phone scams. The traditional warning signs - bad grammar, odd phrasing - no longer apply, so layered technical controls matter far more than spotting typos.
Standard spam filters often miss spear phishing because the emails are individually crafted, sent from legitimate-seeming domains, and may contain no malware or suspicious links. Advanced email security with AI-powered anomaly detection improves detection, but MFA and out-of-band payment verification are essential because no filter catches every targeted message.
Whaling is a sub-type of spear phishing that targets only the most senior people - board members, the CEO, the CFO - usually to authorise large payments or release sensitive data. All whaling is spear phishing, but not all spear phishing is whaling; spear phishing also hits finance clerks, HR, and IT admins lower down the organisation.
Combine layers: enforce multi-factor authentication, deploy advanced email security with anomaly detection, set out-of-band verification for any payment or bank-detail change, train high-risk roles, and run 24/7 detection so a compromised account is caught fast. Using one accountable provider keeps prevention, detection, and response joined up rather than scattered across vendors.
Related Questions
What Is Phishing?
The broader phishing landscape - and how spear phishing differs from mass phishing campaigns.
Email Security and Phishing Protection
Advanced email filtering with anti-phishing controls that detect targeted spear phishing attempts.
Cybersecurity Guide for UK SMEs
How to defend against spear phishing and other targeted attacks as part of a layered security programme.
Cybersecurity for UK Legal Firms
Why law firms are prime spear-phishing targets - conveyancing fraud, client-account attacks and the defences that work.
Protect your business → Get Cybersecurity Assessment