Spear-Phishing
What it is
A targeted phishing message crafted for a specific person or small group using details harvested from public sources, prior breaches, or the target's own social media, so that the request arrives looking like ordinary business.
How it works
Real-world examples
- •The 2011 RSA breach began with an email titled "2011 Recruitment Plan" sent to a handful of employees; the attached spreadsheet exploited a then-unknown Flash flaw and ultimately compromised the SecurID tokens used by defense contractors.
- •Attackers who study a company's organization chart on LinkedIn time their message to coincide with a real executive's publicly announced travel, so a request for an urgent transfer fits the calendar.
- •The 2020 Twitter compromise combined phone spear-phishing of employees with a fake internal help-desk pretext, giving attackers control of accounts belonging to Barack Obama, Elon Musk, Bill Gates, and Apple.
- •The Russian group known as Fancy Bear used near-identical Google-alert lures against the U.S. Democratic National Committee in 2016 and Emmanuel Macron's En Marche campaign in 2017; the technique is indifferent to the politics of the target.
Ethical guidelines
- ●Spear-phishing is fraud; the only lawful use is an authorized penetration test with a signed scope and rules of engagement.
- ●Even in authorized tests, pretexts that impersonate a real colleague or invoke a personal emergency inflict real distress and should be avoided.
- ●Organizations should treat the information employees post publicly (job titles, vendors, travel) as part of the attack surface and reduce what is exposed by default.
How to defend against it
- ►Verify any request that changes where money goes or who has access by a channel the message did not supply: call the sender on a number you already have, or walk to their desk.
- ►Notice when a message fits your week suspiciously well; a lure that references your real project or real boss is more dangerous, not less, and the fit is the tell that someone did their homework.
- ►Hover over or long-press links to see the true destination before clicking, and open attachments only after confirming by another channel that the sender meant to send them.
- ►Reduce your footprint: trim public job details, disable read receipts and out-of-office replies that name colleagues, and ask vendors to notify you of banking changes by phone.
- ►Enable phishing-resistant MFA (FIDO2 security keys or passkeys) on email and financial systems; it defeats even a perfectly tailored credential lure because the key will not sign in to a counterfeit domain.
From the Defense Playbook
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Jagatic, T. N., Johnson, N. A., Jakobsson, M., & Menczer, F. (2007). Social Phishing. Communications of the ACM, 50(10), 94-100 · linkField experiment in which phishing from an apparent friend succeeded with 72 percent of targets versus 16 percent for a stranger.
- Oliveira, D., Rocha, H., Yang, H., Ellis, D., Dommaraju, S., Muradoglu, M., Weir, D., Soliman, A., Lin, T., & Ebner, N. (2017). Dissecting Spear Phishing Emails for Older vs Young Adults: On the Interplay of Weapons of Influence and Life Domains in Predicting Susceptibility to Phishing. Proceedings of the 2017 CHI Conference on Human Factors in Computing Systems · link21-day field study showing age-specific susceptibility to different influence levers (reciprocation for older adults, scarcity for younger).
- Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social engineering attacks. Journal of Information Security and Applications, 22, 113-122 · linkTaxonomy of social-engineering attack channels and the role of publicly available information in targeted attacks.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.