Cybersecurity

What Is Spear Phishing? A Targeted Attack Guide for Business

Spear phishing is a targeted form of phishing attack crafted specifically for the recipient, using personal information to appear legitimate. Unlike mass phishing campaigns, spear phishing targets a named individual using their role, relationships and current context. It is harder to spot, more likely to succeed and the entry point for the most damaging attacks on UK businesses.

NH

Nathan Hill-Haimes

Technical Director

8 min read·Mar 2026

It is the entry point for the most damaging attacks on UK businesses, and the single biggest reason phishing remains the dominant breach type year after year. Phishing was identified as the cause by 85% of businesses and 86% of charities that suffered a breach in the 2025 survey (UK Government, Cyber Security Breaches Survey 2025). Spear phishing is the sharp end of that statistic.

How is spear phishing different from regular phishing?

Standard phishing blasts the same generic message to thousands of recipients and hopes a few bite. Spear phishing targets one named individual, researched in advance, with an email built around their real role, colleagues and current work. That personalisation is exactly what makes it convincing — and dangerous.

Generic phishing reads like a template: "Your account has been suspended", "You have a package waiting", "Verify your password". A spear phishing email reads like a message from someone you actually know, about something you are plausibly involved in. The result looks legitimate because it is built from real information about a real person.

FactorStandard phishingSpear phishing
TargetThousands at randomOne named individual
ResearchNoneHours of reconnaissance
ContentGeneric templatePersonalised to role and context
VolumeBulk sendSingle or low volume
Filter evasionOften caughtFrequently bypasses filters
Typical payoffLow per victimVery high (BEC, fund transfer)

How do attackers research their targets?

Reconnaissance is systematic, and AI tooling has made it fast. An attacker spending an hour can map a target's reporting lines, current projects and likely concerns — enough to craft a highly convincing email. They pull from public sources most businesses never think to lock down.

Common intelligence sources include:

  • LinkedIn — role, responsibilities, who they report to, recent activity and connections
  • Company website — team pages, recent news, client announcements and case studies
  • Social media — X, Instagram and Facebook activity, both personal and professional
  • Previous data breaches — leaked email and password pairs that confirm a live address
  • Public company records — Companies House filings, press releases and procurement notices

The NCSC notes that attackers routinely combine open-source detail like this to make a message land (NCSC phishing guidance). The less your senior staff expose publicly, the harder this first step becomes.

What are the most common spear phishing scams?

Four patterns account for most of the damage: business email compromise, IT help desk impersonation, vendor invoice fraud and whaling. Each exploits trust and urgency rather than a technical flaw, which is why they slip past tools that only look for malicious links or attachments.

Business Email Compromise (BEC)

The most financially damaging variant. The attacker impersonates a senior executive — CEO or Finance Director — and emails a finance team member with an urgent request to move funds to a new account. The message references real context, such as "for the acquisition I mentioned on our call last week", and uses pressure to discourage verification. Over £4 million was stolen from UK law firms alone through BEC-style fraud in a single reporting year (UK market data, 2025); financial services, professional services and larger commercial organisations are equally targeted.

IT help desk impersonation

The attacker poses as your IT support team and references a specific tool or system the target genuinely uses. The email asks them to confirm credentials, install a "security update" or click a link to "resolve an urgent account issue". Strong phishing protection and a clear internal reporting route blunt this one quickly.

Vendor and invoice fraud

The attacker impersonates a known supplier and sends a revised invoice with new banking details, referencing real recent interactions. Without a telephone check of the change, payment lands in the attacker's account. A single mandatory callback procedure prevents almost all of these.

Whaling

Whaling is spear phishing aimed squarely at senior executives — the "whales". These attacks take more effort but the payoff is higher: executives control financial transactions, hold sensitive data, and lend credibility to follow-on attacks against their own staff.

Why is spear phishing so hard to stop?

Standard email filters are excellent at catching bulk phishing — known bad domains, mass-send patterns, generic content. Spear phishing sidesteps those controls because it is low-volume, contextual, and sometimes carries no malicious payload at all. There is nothing technical for a signature-based filter to flag.

Specifically, spear phishing evades many defences because:

  • It is sent individually or in small batches, avoiding bulk-send reputation triggers
  • It may originate from compromised legitimate accounts or lookalike domains that pass SPF
  • The content reads as relevant and contextual, not generic and suspicious
  • Pure BEC attacks contain no link or attachment — only social engineering

This is why behavioural email security, which models writing style, sender-recipient history and contextual anomalies, outperforms signature-based filtering against spear phishing. It is also why email protection should connect into your wider Microsoft 365 security posture rather than sit in isolation.

How do you defend against spear phishing?

Defence is layered: technical controls to detect impersonation, and process controls to make fraudulent requests fail even when an email gets through. Neither is sufficient alone. The businesses that get hit hardest are those relying on a single filter and staff goodwill.

Technical controls

  • AI-based impersonation detectionMicrosoft Defender for Business and equivalent platforms analyse metadata, writing patterns and sender relationships to flag impersonation even when technical indicators are absent
  • DMARC with a reject policy — stops attackers exactly spoofing your domain, so staff cannot receive "CEO" emails sent from your own address
  • External-sender and display-name banners — flag messages that come from outside but display an internal or executive name
  • Multi-factor authentication — prevents stolen credentials from being used to send spear phishing from a legitimate mailbox

Process controls

  • Payment verification procedure — any request to change supplier bank details or make an urgent transfer must be confirmed by phone to a known number, never by replying to the email
  • A callback culture — make verifying unexpected requests by phone the expected norm, not an insult; it is a professional control
  • Targeted training — generic awareness training does not prepare people for personalised attacks; use realistic scenarios that mirror how spear phishing actually reads

When an attack does land, fast containment matters. A defined incident response plan and continuous managed detection and response are what turn a near-miss into a non-event rather than a headline.

Could Your Team Spot a Spear Phishing Email?

AMVIA's spear phishing simulation uses personalised, realistic scenarios to test your team's awareness — providing the data you need to target training where it matters most.

Frequently Asked Questions