What Is Spear Phishing and How Does It Differ from Regular Phishing?
Spear phishing is a targeted email attack aimed at one named person, using personal details — their job title, manager, supplier names, recent projects — to look legitimate.
Quick answer
Spear phishing is a targeted email attack aimed at one named person, using personal details — their job title, manager, supplier names, recent projects — to look legitimate. Unlike mass phishing blasted to thousands, it is hand-built for a single victim, which is why it slips past filters and trained staff alike. Defending against it needs layered controls and one accountable provider.
Key Points
What you need to know.
The Short Answer
Phishing is the number one attack type — 85% of businesses that experienced a breach identified phishing as the cause (DSIT 2025).
For UK Businesses
Phishing was the most disruptive breach for 65% of businesses.
Cost Considerations
93% of cyber crimes against businesses were phishing-based.
Next Steps
35% of businesses that experienced breaches reported impersonation of the organisation or staff.
Quick Comparison
| Feature | Option A | Option B |
|---|
Last updated: 27 June 2026.
What Does Spear Phishing Mean in Plain English?
Spear phishing is a precision con. The attacker researches a specific individual, then sends a message that references real people, real systems, or a real deal in progress so the request feels routine. Mass phishing plays the numbers; spear phishing plays the person.
The difference matters because the defences differ. Generic phishing is mostly caught by spam filters and basic awareness. Spear phishing is written to pass both. According to the UK Government's Cyber Security Breaches Survey 2025, 85% of businesses that experienced a breach identified phishing as the cause — the single most common attack vector. Targeted variants account for a disproportionate share of the breaches that actually cause damage.
To see where ordinary phishing ends and the targeted version begins, read our explainer on what phishing is, then come back here for the targeted threat. Both sit under our managed cybersecurity approach for UK SMEs.
How Is Spear Phishing Different from Mass Phishing?
The core difference is targeting and effort. Mass phishing is one template sent to thousands and costs the attacker almost nothing. Spear phishing is researched, personalised, and sent to one or a handful of people — higher effort, far higher hit rate, and much harder for filters to flag.
| Feature | Mass phishing | Spear phishing |
|---|---|---|
| Target | Thousands, untargeted | One named individual or small group |
| Personalisation | Generic ("Dear customer") | Real names, roles, suppliers, projects |
| Research | None | LinkedIn, company site, social media |
| Filter evasion | Often caught by spam filters | Frequently bypasses standard filters |
| Typical goal | Credential harvesting at scale | Wire fraud, data theft, account takeover |
| Success rate | Low per message | High per message |
Mass phishing is a volume business. Spear phishing is a sniper shot. That is why a single accountable provider running layered email, identity, and endpoint controls beats a stack of disconnected point products.
Who Do Spear Phishers Actually Target?
Attackers go where the money and access live: finance teams, senior executives (CEO and CFO), HR, and IT administrators. These roles can move funds, release sensitive data, or grant system access — so a single successful message can pay off immediately.
Business email compromise (BEC) is the most expensive form of spear phishing, where an attacker impersonates a director or supplier to authorise a fraudulent payment. Cybercrime losses are climbing: total losses reported to the FBI's Internet Crime Complaint Center rose 33% in 2024 versus 2023 (FBI IC3 2024 Annual Report). Impersonation is common too: 35% of businesses that experienced breaches reported others impersonating their organisation in emails or online (DSIT 2025).
Common spear phishing targets and why:
- Finance and accounts payable — can authorise and release payments.
- CEO / CFO and their EAs — high authority, often quoted in "urgent" requests.
- HR — holds payroll data and can be tricked into changing bank details.
- IT administrators — control accounts, MFA resets, and privileged access.
If your finance or exec teams are exposed, our email security and phishing protection hardens the inbox before a fake invoice ever lands.
How Does AI Make Spear Phishing Worse?
AI has collapsed the cost and time of producing convincing targeted emails. Attackers now generate grammatically perfect, on-brand messages at scale, mimic a known person's writing style, automate reconnaissance from public data, and even clone voices for follow-up phone calls (vishing).
The old advice — "look for spelling mistakes" — is dead. AI-written spear phishing reads exactly like a genuine internal email. The UK's National Cyber Security Centre is clear that organisations should assume some phishing will always reach inboxes and build layers that catch what slips through, rather than relying on staff to spot every fake.
This is why detection now matters as much as prevention. Our managed detection and response service watches for the account takeover that follows a successful spear phish, so a stolen credential does not become a full breach.
Can Email Filters Stop Spear Phishing on Their Own?
No. Standard spam filters miss most spear phishing because the emails are individually crafted, sent from legitimate-looking or genuinely compromised domains, and often contain no malware or obvious links — just a plausible request. Filters are necessary but never sufficient.
The realistic defence is layered, and identity is the weakest link in most UK businesses. "Only 40% of UK businesses have MFA enabled (DSIT 2025)" — which means a stolen password is often the only thing standing between an attacker and a mailbox. Multi-factor authentication, conditional access, and anomaly detection close that gap.
What actually reduces spear phishing risk:
- Multi-factor authentication everywhere — even a phished password fails without the second factor.
- Advanced email security — AI-driven anomaly detection on top of spam filtering.
- Payment verification rules — out-of-band confirmation for any bank-detail or payment change.
- Targeted awareness training — for finance, exec, HR, and IT roles specifically.
- 24/7 detection — so a compromised account is caught in minutes, not weeks.
If turning on MFA properly across your tenant is the gap, follow our guide to setting up MFA across Microsoft 365. And if you suspect an account is already compromised, our incident response team can contain it. One provider, security-first, Microsoft-certified — so prevention, detection, and response are not three different phone calls.
Frequently Asked Questions
Spear phishing is a phishing attack aimed at one specific person, built from real details about them — their name, role, colleagues, or current work — so the message looks genuine. Unlike mass phishing sent to thousands, it is personalised to a single target, which is exactly why it is harder to spot and more likely to succeed.
Finance teams, senior executives (CEO and CFO), HR staff, and IT administrators are the most frequent targets because they control funds, sensitive data, or system access. Attackers research targets using LinkedIn, company websites, and social media before sending a tailored message that references real people or projects to lower the victim's guard.
AI lets attackers generate highly personalised, grammatically correct emails at scale. It can mimic a colleague's writing style, automate reconnaissance from public data, and even produce deepfake voice messages for follow-up phone scams. The traditional warning signs — bad grammar, odd phrasing — no longer apply, so layered technical controls matter far more than spotting typos.
Standard spam filters often miss spear phishing because the emails are individually crafted, sent from legitimate-seeming domains, and may contain no malware or suspicious links. Advanced email security with AI-powered anomaly detection improves detection, but MFA and out-of-band payment verification are essential because no filter catches every targeted message.
Whaling is a sub-type of spear phishing that targets only the most senior people — board members, the CEO, the CFO — usually to authorise large payments or release sensitive data. All whaling is spear phishing, but not all spear phishing is whaling; spear phishing also hits finance clerks, HR, and IT admins lower down the organisation.
Combine layers: enforce multi-factor authentication, deploy advanced email security with anomaly detection, set out-of-band verification for any payment or bank-detail change, train high-risk roles, and run 24/7 detection so a compromised account is caught fast. Using one accountable provider keeps prevention, detection, and response joined up rather than scattered across vendors.
Related Questions
What Is Phishing?
The broader phishing landscape — and how spear phishing differs from mass phishing campaigns.
Email Security and Phishing Protection
Advanced email filtering with anti-phishing controls that detect targeted spear phishing attempts.
Cybersecurity Guide for UK SMEs
How to defend against spear phishing and other targeted attacks as part of a layered security programme.
Protect your business → Get Cybersecurity Assessment