Social Engineering & FraudMANIPULATIVE

Spear-Phishing

What it is

A targeted phishing message crafted for a specific person or small group using details harvested from public sources, prior breaches, or the target's own social media, so that the request arrives looking like ordinary business.

How it works

Bulk phishing succeeds by volume; spear-phishing succeeds by fit. The attacker studies the target's role, colleagues, vendors, travel, and writing conventions, then composes a message that matches what the target already expects to receive: an invoice from a real supplier, a document from a real project, a note from the boss who really is travelling this week. Personalization removes the mismatch signals that normally trigger scrutiny, and it recruits liking and social proof, because the message appears to come from inside the target's own network. Jagatic and colleagues demonstrated the effect at Indiana University in 2005: a phishing email that appeared to come from a friend captured credentials from 72 percent of recipients, against 16 percent for the same message from a stranger. Oliveira and colleagues found in a 21-day field study that different people are vulnerable to different levers, with older adults most susceptible to reciprocation and younger adults to scarcity, which is why a tailored lure outperforms a generic one.

Real-world examples

  • The 2011 RSA breach began with an email titled "2011 Recruitment Plan" sent to a handful of employees; the attached spreadsheet exploited a then-unknown Flash flaw and ultimately compromised the SecurID tokens used by defense contractors.
  • Attackers who study a company's organization chart on LinkedIn time their message to coincide with a real executive's publicly announced travel, so a request for an urgent transfer fits the calendar.
  • The 2020 Twitter compromise combined phone spear-phishing of employees with a fake internal help-desk pretext, giving attackers control of accounts belonging to Barack Obama, Elon Musk, Bill Gates, and Apple.
  • The Russian group known as Fancy Bear used near-identical Google-alert lures against the U.S. Democratic National Committee in 2016 and Emmanuel Macron's En Marche campaign in 2017; the technique is indifferent to the politics of the target.

Ethical guidelines

  • Spear-phishing is fraud; the only lawful use is an authorized penetration test with a signed scope and rules of engagement.
  • Even in authorized tests, pretexts that impersonate a real colleague or invoke a personal emergency inflict real distress and should be avoided.
  • Organizations should treat the information employees post publicly (job titles, vendors, travel) as part of the attack surface and reduce what is exposed by default.

How to defend against it

  • Verify any request that changes where money goes or who has access by a channel the message did not supply: call the sender on a number you already have, or walk to their desk.
  • Notice when a message fits your week suspiciously well; a lure that references your real project or real boss is more dangerous, not less, and the fit is the tell that someone did their homework.
  • Hover over or long-press links to see the true destination before clicking, and open attachments only after confirming by another channel that the sender meant to send them.
  • Reduce your footprint: trim public job details, disable read receipts and out-of-office replies that name colleagues, and ask vendors to notify you of banking changes by phone.
  • Enable phishing-resistant MFA (FIDO2 security keys or passkeys) on email and financial systems; it defeats even a perfectly tailored credential lure because the key will not sign in to a counterfeit domain.

From the Defense Playbook

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Jagatic, T. N., Johnson, N. A., Jakobsson, M., & Menczer, F. (2007). Social Phishing. Communications of the ACM, 50(10), 94-100 · link
    Field experiment in which phishing from an apparent friend succeeded with 72 percent of targets versus 16 percent for a stranger.
  2. Oliveira, D., Rocha, H., Yang, H., Ellis, D., Dommaraju, S., Muradoglu, M., Weir, D., Soliman, A., Lin, T., & Ebner, N. (2017). Dissecting Spear Phishing Emails for Older vs Young Adults: On the Interplay of Weapons of Influence and Life Domains in Predicting Susceptibility to Phishing. Proceedings of the 2017 CHI Conference on Human Factors in Computing Systems · link
    21-day field study showing age-specific susceptibility to different influence levers (reciprocation for older adults, scarcity for younger).
  3. Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social engineering attacks. Journal of Information Security and Applications, 22, 113-122 · link
    Taxonomy of social-engineering attack channels and the role of publicly available information in targeted attacks.
Last reviewed
Suggest a correction

Detect Spear-Phishing in any text

Paste any message, email, or article into our free Manipulation Detector to see if Spear-Phishing or other techniques are being used on you.

Related Articles