The attacker adapts the message, sender identity, timing, or requested action using information about the target to increase credibility. Targeting distinguishes spear phishing from broad campaigns; it does not require email, a malicious attachment, malware, or a particular level of technical sophistication.
Delivery can occur through email, collaboration services, social platforms, or other digital channels. The request may seek credentials, payment, confidential information, execution of content, or a change to an established process, and it may continue across several channels.
Key points
Targeting cluesReferences to a current project, colleague, supplier, role, travel plan, or internal terminology can indicate research, but accurate details do not prove that the sender is genuine.
Protective controlsUse phishing-resistant multi-factor authentication, protected communication domains, filtering, least privilege, and independent approval for sensitive or changed instructions.
Investigation prioritiesPreserve the message and headers, inspect destinations and attachments safely, check related sign-ins or mailbox rules, and identify other recipients of the same campaign.
Important limitationPersonalization alone does not make a message spear phishing, and an untailored-looking message can still be targeted; classification depends on campaign context as well as visible wording.