HomeBlogCybersecurity

What Is Spear Phishing? How Small Businesses Get Targeted

Pixel-art illustration of a robot on a pirate ship's deck raising a glowing blue shield against red, bug-shaped malware over a stormy sea

Spear phishing is a phishing message written for one person or a small group, built from details the attacker found about them: their role, vendors, projects and who approves payments. The FBI calls it a directed attempt to trick a specific user into clicking a link or opening an attachment. It works because it reads like normal business.

The defenses are a mix of mail settings, sign-in methods and habits. Our email security services turn on impersonation protection for the people whose names can move money, and our security awareness training runs targeted simulations for finance staff and executives. This guide covers how targets are chosen, what the messages look like and what stops them.

What is spear phishing?

Ordinary phishing goes to thousands of inboxes and hopes a few people bite. Spear phishing picks the target first. MITRE ATT&CK, the public catalog of attacker techniques, describes spearphishing as phishing in which a specific individual, company or industry is targeted. Microsoft notes that attackers often build these messages from social media profiles, company websites and directories, so the email mentions real names, real meetings and real work.

The goal is usually a password typed into a fake sign-in page, malware from a link or attachment, or a payment. The joint CISA, NSA, FBI and MS-ISAC phishing guidance notes that attackers use freely available tools to run spearphishing campaigns with specific and convincing lures, so this is not reserved for large companies.

Spear phishing vs. phishing, whaling and business email compromise

AttackWho it targetsHow it is builtWhat it usually wants
PhishingLarge lists of peopleOne generic message sent widelyPasswords, card numbers or a malware install
Spear phishingOne person, one company or one industryResearched details about the target and their workA password, a malware install or a payment
WhalingOwners, executives and other senior decision-makersSpear phishing aimed at the top, often posing as a trusted colleague, vendor or legal authorityLarge payments or confidential data
Business email compromiseStaff who handle payments and transfersA compromised or spoofed business mailbox, often inside a real threadA transfer of funds to the attacker

The terms overlap. Spear phishing is often how business email compromise starts: one targeted message steals a mailbox password, and the attacker then sends invoices from the real account. Microsoft has documented phishing campaigns that did exactly that. Our glossary entry on business email compromise has the definition, and how business email compromise hits small businesses walks through how it unfolds.

How do attackers research a small business?

Mostly from public pages. MITRE lists searching social media, news sites and pages about hiring or contracts as standard reconnaissance. For a small business, the usual sources are:

  • Your website. Team pages give names, titles and the format of your email addresses; case studies and news posts name clients, vendors and projects.
  • LinkedIn and other profiles. Who joined recently, who works in accounts payable and who reports to whom. New hires make useful targets because they are still learning how requests normally arrive.
  • Job postings and vendor lists. A posting for a bookkeeper hints at your accounting software; a supplier's customer list or a public contract award names your vendors.
  • Out-of-office replies. An auto-reply that says the owner is traveling until Monday tells an attacker when a fake urgent request from the owner is least likely to be checked.
  • Earlier phishing. MITRE also describes phishing for information: friendly messages sent only to collect details for the real attack.

The FBI's advice to individuals applies to businesses too: limit what you post about people and keep profiles private where you can. Trim titles and direct lines from public pages if nobody outside needs them, and keep auto-replies vague about dates and who is away.

What does spear phishing look like? Illustrative examples

These three examples are mock-ups written for this page. They show the pattern, not real messages or real incidents.

The new bookkeeper

Two weeks after a new hire announces the job on LinkedIn, an email arrives under the owner's name from a free email account: Welcome aboard. Before Friday's payroll, please update your direct deposit details through the link below. HR needs it today. The tell: a payroll change requested by email from an address that is not your company's. The check: ask the owner and HR in person or by phone.

The owner who is traveling

The owner's auto-reply says she is at a trade show until Monday. Accounts payable gets: Boarding now. We need to wire the deposit to the new supplier before end of day or we lose the slot. Details attached. I will be offline, so just handle it. The tell: a new payee, a deadline and a sender who cannot be reached. The check: no wire to a new payee without a call to a known number, whoever asks.

The real project

Your website shows a renovation you just finished. An email from a domain one letter away from your architect's says: Revised as-built drawings for the [project] job are ready. Sign in to view them before the closeout meeting. The tell: a sign-in link from a lookalike domain. The check: compare the address with an older email from that firm, and open the file share from your own bookmark.

What stops spear phishing?

  1. Impersonation protection. Microsoft Defender for Office 365 can flag mail that imitates people you choose to protect and domains that look like yours or your vendors'. Microsoft notes that no senders are protected by default, so someone has to add the owner, finance staff and key vendors; each policy holds up to 350 protected users. The feature comes with Plan 1, which is included in Microsoft 365 Business Premium, and our email security work configures it.
  2. Phishing-resistant MFA. CISA and its partners recommend FIDO-based or PKI-based MFA because it holds up against fake sign-in pages, and number matching wherever push approvals are still used. Start with administrators and anyone who can reach financial data.
  3. Callback verification for money. Confirm any new payee or change of bank details by phone at a number already on file, as the FBI's IC3 advises. Write it down as a rule so nobody has to decide under pressure.
  4. DMARC at reject. CISA recommends a DMARC policy of reject for mail sent from your domain, so attackers cannot send as you. It does not stop lookalike domains, which is why impersonation protection still matters.
  5. Targeted simulations. Send practice lures to finance, executives and anyone who approves payments, built on details an attacker could find about them. Our security awareness training includes targeted campaigns for those roles.

Frequently asked questions

Is spear phishing the same as business email compromise?

No. Spear phishing describes how a message is aimed: at a specific person, using researched details. Business email compromise describes the fraud: using a compromised or spoofed business mailbox to redirect payments. A spear phishing email often opens the door, and the business email compromise follows from the stolen mailbox.

Can AI write spear phishing emails?

Yes. The FBI warned in December 2024 that criminals use generative AI to write believable text for spear phishing and to remove the grammar and spelling errors that used to signal fraud. That makes checking the request, the sender and the payment details more important than judging the writing.

What is whaling?

Whaling is spear phishing aimed at owners and senior executives. Microsoft describes it as a subset of spear phishing that targets high-profile people with the authority to move money or release data. In a small business, it can mean impersonating the owner to the person who pays the bills.

What should I do with a suspected spear phishing email?

Do not reply, click or call any number in it. Report it with Outlook's Report button so your IT team sees it, then confirm the request with the supposed sender through a phone number or channel you already use. If you entered a password, change it and tell IT so they can end active sessions; if money moved, call your bank immediately.

Sources and further reading

Security Awareness & Phishing Training

Discuss security awareness & phishing training for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore Security Awareness & Phishing Training 845-203-3914