
Spear phishing is a phishing message written for one person or a small group, built from details the attacker found about them: their role, vendors, projects and who approves payments. The FBI calls it a directed attempt to trick a specific user into clicking a link or opening an attachment. It works because it reads like normal business.
The defenses are a mix of mail settings, sign-in methods and habits. Our email security services turn on impersonation protection for the people whose names can move money, and our security awareness training runs targeted simulations for finance staff and executives. This guide covers how targets are chosen, what the messages look like and what stops them.
What is spear phishing?
Ordinary phishing goes to thousands of inboxes and hopes a few people bite. Spear phishing picks the target first. MITRE ATT&CK, the public catalog of attacker techniques, describes spearphishing as phishing in which a specific individual, company or industry is targeted. Microsoft notes that attackers often build these messages from social media profiles, company websites and directories, so the email mentions real names, real meetings and real work.
The goal is usually a password typed into a fake sign-in page, malware from a link or attachment, or a payment. The joint CISA, NSA, FBI and MS-ISAC phishing guidance notes that attackers use freely available tools to run spearphishing campaigns with specific and convincing lures, so this is not reserved for large companies.
Spear phishing vs. phishing, whaling and business email compromise
| Attack | Who it targets | How it is built | What it usually wants |
|---|---|---|---|
| Phishing | Large lists of people | One generic message sent widely | Passwords, card numbers or a malware install |
| Spear phishing | One person, one company or one industry | Researched details about the target and their work | A password, a malware install or a payment |
| Whaling | Owners, executives and other senior decision-makers | Spear phishing aimed at the top, often posing as a trusted colleague, vendor or legal authority | Large payments or confidential data |
| Business email compromise | Staff who handle payments and transfers | A compromised or spoofed business mailbox, often inside a real thread | A transfer of funds to the attacker |
The terms overlap. Spear phishing is often how business email compromise starts: one targeted message steals a mailbox password, and the attacker then sends invoices from the real account. Microsoft has documented phishing campaigns that did exactly that. Our glossary entry on business email compromise has the definition, and how business email compromise hits small businesses walks through how it unfolds.
How do attackers research a small business?
Mostly from public pages. MITRE lists searching social media, news sites and pages about hiring or contracts as standard reconnaissance. For a small business, the usual sources are:
- Your website. Team pages give names, titles and the format of your email addresses; case studies and news posts name clients, vendors and projects.
- LinkedIn and other profiles. Who joined recently, who works in accounts payable and who reports to whom. New hires make useful targets because they are still learning how requests normally arrive.
- Job postings and vendor lists. A posting for a bookkeeper hints at your accounting software; a supplier's customer list or a public contract award names your vendors.
- Out-of-office replies. An auto-reply that says the owner is traveling until Monday tells an attacker when a fake urgent request from the owner is least likely to be checked.
- Earlier phishing. MITRE also describes phishing for information: friendly messages sent only to collect details for the real attack.
The FBI's advice to individuals applies to businesses too: limit what you post about people and keep profiles private where you can. Trim titles and direct lines from public pages if nobody outside needs them, and keep auto-replies vague about dates and who is away.
What does spear phishing look like? Illustrative examples
These three examples are mock-ups written for this page. They show the pattern, not real messages or real incidents.
The new bookkeeper
Two weeks after a new hire announces the job on LinkedIn, an email arrives under the owner's name from a free email account: Welcome aboard. Before Friday's payroll, please update your direct deposit details through the link below. HR needs it today. The tell: a payroll change requested by email from an address that is not your company's. The check: ask the owner and HR in person or by phone.
The owner who is traveling
The owner's auto-reply says she is at a trade show until Monday. Accounts payable gets: Boarding now. We need to wire the deposit to the new supplier before end of day or we lose the slot. Details attached. I will be offline, so just handle it. The tell: a new payee, a deadline and a sender who cannot be reached. The check: no wire to a new payee without a call to a known number, whoever asks.
The real project
Your website shows a renovation you just finished. An email from a domain one letter away from your architect's says: Revised as-built drawings for the [project] job are ready. Sign in to view them before the closeout meeting. The tell: a sign-in link from a lookalike domain. The check: compare the address with an older email from that firm, and open the file share from your own bookmark.
What stops spear phishing?
- Impersonation protection. Microsoft Defender for Office 365 can flag mail that imitates people you choose to protect and domains that look like yours or your vendors'. Microsoft notes that no senders are protected by default, so someone has to add the owner, finance staff and key vendors; each policy holds up to 350 protected users. The feature comes with Plan 1, which is included in Microsoft 365 Business Premium, and our email security work configures it.
- Phishing-resistant MFA. CISA and its partners recommend FIDO-based or PKI-based MFA because it holds up against fake sign-in pages, and number matching wherever push approvals are still used. Start with administrators and anyone who can reach financial data.
- Callback verification for money. Confirm any new payee or change of bank details by phone at a number already on file, as the FBI's IC3 advises. Write it down as a rule so nobody has to decide under pressure.
- DMARC at reject. CISA recommends a DMARC policy of reject for mail sent from your domain, so attackers cannot send as you. It does not stop lookalike domains, which is why impersonation protection still matters.
- Targeted simulations. Send practice lures to finance, executives and anyone who approves payments, built on details an attacker could find about them. Our security awareness training includes targeted campaigns for those roles.
Frequently asked questions
Is spear phishing the same as business email compromise?
No. Spear phishing describes how a message is aimed: at a specific person, using researched details. Business email compromise describes the fraud: using a compromised or spoofed business mailbox to redirect payments. A spear phishing email often opens the door, and the business email compromise follows from the stolen mailbox.
Can AI write spear phishing emails?
Yes. The FBI warned in December 2024 that criminals use generative AI to write believable text for spear phishing and to remove the grammar and spelling errors that used to signal fraud. That makes checking the request, the sender and the payment details more important than judging the writing.
What is whaling?
Whaling is spear phishing aimed at owners and senior executives. Microsoft describes it as a subset of spear phishing that targets high-profile people with the authority to move money or release data. In a small business, it can mean impersonating the owner to the person who pays the bills.
What should I do with a suspected spear phishing email?
Do not reply, click or call any number in it. Report it with Outlook's Report button so your IT team sees it, then confirm the request with the supposed sender through a phone number or channel you already use. If you entered a password, change it and tell IT so they can end active sessions; if money moved, call your bank immediately.
Sources and further reading
- FBI IC3: Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (December 3, 2024): includes the FBI's definition of spear phishing.
- MITRE ATT&CK T1566: Phishing, T1593: Search Open Websites/Domains and T1598: Phishing for Information.
- Microsoft Security: What is spear phishing?, including phishing vs. spear phishing vs. whaling.
- CISA, NSA, FBI and MS-ISAC: Phishing Guidance: Stopping the Attack Cycle at Phase One (October 2023).
- FBI IC3: Business Email Compromise PSA (September 11, 2024).
- Microsoft: AiTM phishing sites as an entry point to financial fraud (July 12, 2022).
- Microsoft Learn: Anti-phishing policies, including user and domain impersonation protection.
- Microsoft Defender for Office 365 service description: which plan comes with which subscription.
Related reading
CybersecurityQuishing: QR Code Phishing Now Targets Small Business
Read Article
CybersecurityPhishing Email Examples: 12 Lures Hitting Small Businesses and the Tell in Each
Read Article
CybersecurityLookalike Domains: How Scammers Impersonate Your Business
Read ArticleAlso on this topic: AI Phishing Attacks: Why the Typos Are Gone and Clicks Are Up · Deepfake CFO Fraud Is Here: The $25M Video Call That Fooled Finance
Discuss security awareness & phishing training for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
