AEO Answer

What Is Spear Phishing and How Does It Differ from Regular Phishing?

Spear phishing is a targeted email attack aimed at one named person, using personal details — their job title, manager, supplier names, recent projects — to look legitimate.

Quick answer

Spear phishing is a targeted email attack aimed at one named person, using personal details — their job title, manager, supplier names, recent projects — to look legitimate. Unlike mass phishing blasted to thousands, it is hand-built for a single victim, which is why it slips past filters and trained staff alike. Defending against it needs layered controls and one accountable provider.

Key Points

What you need to know.

The Short Answer

Phishing is the number one attack type — 85% of businesses that experienced a breach identified phishing as the cause (DSIT 2025).

For UK Businesses

Phishing was the most disruptive breach for 65% of businesses.

Cost Considerations

93% of cyber crimes against businesses were phishing-based.

Next Steps

35% of businesses that experienced breaches reported impersonation of the organisation or staff.

Quick Comparison

Feature
Option A
Option B

Last updated: 27 June 2026.

What Does Spear Phishing Mean in Plain English?

Spear phishing is a precision con. The attacker researches a specific individual, then sends a message that references real people, real systems, or a real deal in progress so the request feels routine. Mass phishing plays the numbers; spear phishing plays the person.

The difference matters because the defences differ. Generic phishing is mostly caught by spam filters and basic awareness. Spear phishing is written to pass both. According to the UK Government's Cyber Security Breaches Survey 2025, 85% of businesses that experienced a breach identified phishing as the cause — the single most common attack vector. Targeted variants account for a disproportionate share of the breaches that actually cause damage.

To see where ordinary phishing ends and the targeted version begins, read our explainer on what phishing is, then come back here for the targeted threat. Both sit under our managed cybersecurity approach for UK SMEs.

How Is Spear Phishing Different from Mass Phishing?

The core difference is targeting and effort. Mass phishing is one template sent to thousands and costs the attacker almost nothing. Spear phishing is researched, personalised, and sent to one or a handful of people — higher effort, far higher hit rate, and much harder for filters to flag.

FeatureMass phishingSpear phishing
TargetThousands, untargetedOne named individual or small group
PersonalisationGeneric ("Dear customer")Real names, roles, suppliers, projects
ResearchNoneLinkedIn, company site, social media
Filter evasionOften caught by spam filtersFrequently bypasses standard filters
Typical goalCredential harvesting at scaleWire fraud, data theft, account takeover
Success rateLow per messageHigh per message

Mass phishing is a volume business. Spear phishing is a sniper shot. That is why a single accountable provider running layered email, identity, and endpoint controls beats a stack of disconnected point products.

Who Do Spear Phishers Actually Target?

Attackers go where the money and access live: finance teams, senior executives (CEO and CFO), HR, and IT administrators. These roles can move funds, release sensitive data, or grant system access — so a single successful message can pay off immediately.

Business email compromise (BEC) is the most expensive form of spear phishing, where an attacker impersonates a director or supplier to authorise a fraudulent payment. Cybercrime losses are climbing: total losses reported to the FBI's Internet Crime Complaint Center rose 33% in 2024 versus 2023 (FBI IC3 2024 Annual Report). Impersonation is common too: 35% of businesses that experienced breaches reported others impersonating their organisation in emails or online (DSIT 2025).

Common spear phishing targets and why:

  • Finance and accounts payable — can authorise and release payments.
  • CEO / CFO and their EAs — high authority, often quoted in "urgent" requests.
  • HR — holds payroll data and can be tricked into changing bank details.
  • IT administrators — control accounts, MFA resets, and privileged access.

If your finance or exec teams are exposed, our email security and phishing protection hardens the inbox before a fake invoice ever lands.

How Does AI Make Spear Phishing Worse?

AI has collapsed the cost and time of producing convincing targeted emails. Attackers now generate grammatically perfect, on-brand messages at scale, mimic a known person's writing style, automate reconnaissance from public data, and even clone voices for follow-up phone calls (vishing).

The old advice — "look for spelling mistakes" — is dead. AI-written spear phishing reads exactly like a genuine internal email. The UK's National Cyber Security Centre is clear that organisations should assume some phishing will always reach inboxes and build layers that catch what slips through, rather than relying on staff to spot every fake.

This is why detection now matters as much as prevention. Our managed detection and response service watches for the account takeover that follows a successful spear phish, so a stolen credential does not become a full breach.

Can Email Filters Stop Spear Phishing on Their Own?

No. Standard spam filters miss most spear phishing because the emails are individually crafted, sent from legitimate-looking or genuinely compromised domains, and often contain no malware or obvious links — just a plausible request. Filters are necessary but never sufficient.

The realistic defence is layered, and identity is the weakest link in most UK businesses. "Only 40% of UK businesses have MFA enabled (DSIT 2025)" — which means a stolen password is often the only thing standing between an attacker and a mailbox. Multi-factor authentication, conditional access, and anomaly detection close that gap.

What actually reduces spear phishing risk:

  • Multi-factor authentication everywhere — even a phished password fails without the second factor.
  • Advanced email security — AI-driven anomaly detection on top of spam filtering.
  • Payment verification rules — out-of-band confirmation for any bank-detail or payment change.
  • Targeted awareness training — for finance, exec, HR, and IT roles specifically.
  • 24/7 detection — so a compromised account is caught in minutes, not weeks.

If turning on MFA properly across your tenant is the gap, follow our guide to setting up MFA across Microsoft 365. And if you suspect an account is already compromised, our incident response team can contain it. One provider, security-first, Microsoft-certified — so prevention, detection, and response are not three different phone calls.

Frequently Asked Questions

Need More Detail?

Speak to an AMVIA expert for advice tailored to your business.