# What is Spear Phishing?

> Spear phishing is phishing deliberately tailored to a specific person, team, organization, or narrowly defined group.

- Canonical URL: https://yellowcube.eu/glossary/spear-phishing/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The attacker adapts the message, sender identity, timing, or requested action using information about the target to increase credibility. Targeting distinguishes spear phishing from broad campaigns; it does not require email, a malicious attachment, malware, or a particular level of technical sophistication.

Delivery can occur through email, collaboration services, social platforms, or other digital channels. The request may seek credentials, payment, confidential information, execution of content, or a change to an established process, and it may continue across several channels.

### Key points

- **Targeting clues:** References to a current project, colleague, supplier, role, travel plan, or internal terminology can indicate research, but accurate details do not prove that the sender is genuine.
- **Protective controls:** Use phishing-resistant multi-factor authentication, protected communication domains, filtering, least privilege, and independent approval for sensitive or changed instructions.
- **Investigation priorities:** Preserve the message and headers, inspect destinations and attachments safely, check related sign-ins or mailbox rules, and identify other recipients of the same campaign.
- **Important limitation:** Personalization alone does not make a message spear phishing, and an untailored-looking message can still be targeted; classification depends on campaign context as well as visible wording.

### Related terms

[Phishing](<https://yellowcube.eu/glossary/phishing/>) · [Social engineering](<https://yellowcube.eu/glossary/social-engineering/>) · [Whaling](<https://yellowcube.eu/glossary/whaling/>) · [Business email compromise (BEC)](<https://yellowcube.eu/glossary/business-email-compromise/>) · [Email spoofing](<https://yellowcube.eu/glossary/email-spoofing/>)

### Sources

[NIST glossary: Spear Phishing](https://csrc.nist.gov/glossary/term/spear_phishing) · [MITRE ATT&CK: Phishing](https://attack.mitre.org/techniques/T1566/) · [Canadian Centre for Cyber Security: Social engineering](https://www.cyber.gc.ca/en/guidance/social-engineering-itsap00166)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

