Industrial designers at the office discussing project on the computer.

What is spear phising?

Spear phishing is a targeted form of phishing in which an attacker researches a specific person or role, then sends a personalised message built to look like it came from someone the recipient already trusts. 

For Australian organisations, this is now an everyday operational risk rather than an edge case. In 2024–25, business email compromise fraud accounted for 15% of cybercrimes reported by Australian businesses, with a further 19% involving email compromise without direct financial loss (ASD/ACSC)

Phishing also remained at elevated levels, with APWG reporting 1,003,924 phishing attacks in the first quarter of 2025, the largest number since late 2023 (APWG).

This guide explains what spear phishing is, how an attack unfolds, the common types and examples, and the controls that reduce the risk.

Key takeaways

  • Spear phishing is a targeted, researched attack aimed at a specific individual or role, unlike bulk phishing blasted to thousands.
  • Phishing remains one of the most common attack actions, appearing in 14% of breaches, while stolen credentials are the single most common way in (Verizon, 2025 DBIR).
  • People, not technology, are usually the way in: a human element features in around 60% of breaches (Verizon, 2025 DBIR), so technical controls alone are not enough.
  • The strongest defences are layered: awareness training, multi-factor authentication, out-of-band verification, email filtering, and authentication protocols (SPF, DKIM, DMARC).
  • Nexon helps Australian organisations reduce this risk through managed detection and response, cyber awareness programs, and penetration testing that probes beyond the inbox.

How a spear phishing attack works

A spear phishing attack works through precision: the attacker studies the target first, then builds a message tailored enough to pass as routine. Most campaigns move through five stages.

  • Reconnaissance. The attacker gathers details from public sources such as social media, company websites, conference talks, and breached datasets, including job title, reporting lines, current projects, and writing style.
  • Pretext and crafting. Using that detail, they construct a believable scenario, often impersonating a manager or a known supplier, and add a reason to act quickly.
  • Delivery. The message reaches the target by email, a link, an attachment, or a trusted external service. MITRE ATT&CK categorises these tactics as spear phishing attachments, spear phishing links, spear phishing via services, and related social engineering techniques.
  • The action. The target clicks through to a fake login page, opens a malicious attachment, or replies with sensitive information. 
  • Exploitation. With a stolen credential, token, or foothold, the attacker pursues the real objective: financial fraud, data theft, ransomware, or deeper network access.

This pattern explains why people are often the entry point rather than the technology. Verizon reports that the human element is involved in about 60% of breaches, which is why effective defence requires both user-focused training and technical controls.

Types of spear phishing attacks and why they’re so effective

Spear phishing takes several forms, distinguished by how the lure is delivered, but they all share the same goal: to appear to be something the target was expecting. MITRE ATT&CK catalogues targeted phishing techniques such as spear phishing attachments, spear phishing links, spear phishing via services, and spear phishing voice.

  • Spear phishing attachment. A malicious file, disguised as an invoice, CV, or report, that installs malware or executes code when opened.
  • Spear phishing link. A link to a fake login page or a drive-by download. The email appears routine; the destination is malicious.
  • Spear phishing via service. The lure arrives through a trusted third-party platform, such as a file-sharing service, recruitment portal, or survey tool, rather than corporate email. Because these channels may receive less scrutiny than email, phishing through services bypass standard filtering and monitoring.
  • Spear phishing voice (vishing). A phone call that pressures the target into approving a login or reading back a security code, sometimes amplified by AI-generated audio.

What makes these attacks effective is that they remove the cues people use to spot fraud. Personalisation based on real detail, such as job title, current projects, and known contacts, makes the message feel routine. A familiar sender, such as a manager or regular supplier, lowers suspicion, and urgency pushes quick action ahead of verification. Generative AI has made some of these lures more polished and even harder to distinguish, making spear phishing a real and current threat to organisations.

Real-world spear phishing examples

Real-world incidents show how spear phishing plays out and how much it can cost. The cases below are all publicly documented, and each follows the same logic: a message that fits the target’s expectations and is intended for someone who can act on it.

Credential harvesting campaigns

Credential harvesting tricks the target into entering their username and password on a fake login page. The best-documented example is the March 2016 attack on Clinton campaign chairman John Podesta, who received an email disguised as a Google security alert that led to an attacker-controlled page that captured his Gmail credentials. His emails were later published online, and the United States Department of Justice went on to indict 12 Russian military intelligence officers over the wider campaign. 

Invoice and payment fraud schemes

Invoice fraud involves sending a real-looking payment to the wrong account. Between 2013 and 2015, Evaldas Rimasauskas defrauded Google and Facebook of more than US$100 million by impersonating Quanta Computer, a hardware supplier both companies genuinely used. He registered a look-alike company and sent fake invoices and contracts that matched standard procurement procedures, so the payments went through. He pleaded guilty to wire fraud in 2019 and was sentenced to five years. 

Vendor and supplier impersonation attacks

Vendor impersonation exploits the trust between an organisation and its suppliers. In 2019, a European subsidiary of Toyota Boshoku, a Toyota parts maker, was persuaded to change its supplier payment details and to wire about US$37 million to an account controlled by criminals. Because the request matched an expected supplier payment, it passed through finance without challenge. 

Executive impersonation scenarios

Executive impersonation uses apparent authority to rush a payment. In January 2016, the Austrian aerospace parts manufacturer FACC lost about €42 million after a finance employee received an email that appeared to be from the chief executive, instructing an urgent transfer for an acquisition. The company later dismissed both the employee and the chief executive. The approach works because a request from a senior leader feels important and time-critical, which discourages the recipient from checking.

Malware delivery through targeted emails

Spear phishing is also a delivery method for malware. On 23 December 2015, attackers cut power to about 225,000 customers in Ukraine after gaining access via spear phishing emails containing malicious Microsoft Office attachments that installed the BlackEnergy malware, giving them a foothold in the electricity distributors’ networks. The United States Cybersecurity and Infrastructure Security Agency documented the intrusion. It shows how a single opened attachment can be the first step toward a much larger compromise, rather than the end of the attack.

How to mitigate a spear phishing attack

No single control stops spear phishing because it targets people and technology simultaneously. Effective defence is layered, so that when one measure misses, another catches the attempt.

Conduct security awareness and phishing training

Ongoing cyber security employee training and simulated phishing help staff recognise and report targeted messages before they act on them. Training does not remove the risk, but it improves vigilance and speeds up reporting when a live attempt appears. In Verizon’s 2025 Data Breach Investigations Report, employees with recent training reported simulated phishing at about 21%, compared with a 5% base rate.

Enable multi-factor authentication (MFA)

MFA adds a second check beyond the password, so a stolen credential alone is not enough to open an account. It is one of the mitigations in the Australian Cyber Security Centre’s Essential Eight, but phishing-resistant methods are preferable where possible, as attackers can still attempt to capture or relay one-time codes in real time.

Verify requests for sensitive information through secondary channels

Out-of-band verification is one of the most reliable defences against payment and data-transfer fraud. Before acting on an emailed request to change bank details, move funds, or release sensitive information, employees should confirm it through a separate, known channel.

Deploy advanced email security and anti-phishing controls

Secure email gateways, link rewriting, attachment sandboxing, and anomaly detection reduce the number of targeted emails that reach an inbox. Although these technical safeguards are important, they are not foolproof, as cybercriminals can often bypass them by delivering malicious lures via compromised accounts or reputable external platforms.

Implement email authentication protocols (SPF, DKIM, and DMARC)

SPF, DKIM, and DMARC make it harder for attackers to spoof an organisation’s domain. They reduce exact-domain impersonation, but they do not stop look-alike domains or a genuinely compromised account, so they should be used alongside the other controls.

What to do after falling victim to a spear phishing attack

Speed matters after a spear phishing attack because the gap between a click and containment is when most of the damage is done. The steps below help limit the impact and support recovery, whether an employee entered their credentials, approved a payment, or opened an attachment.

1. Contain the threat immediately

Disconnect the affected device from the network and suspend any compromised accounts to cut off the attacker’s access. Preserve evidence by keeping the original email, logs, and related files for investigation.

2. Reset credentials and revoke access

Reset the exposed credentials, revoke active sessions and tokens, and check for any mailbox rules, recovery details, or authentication methods the attacker may have changed. Re-enable or strengthen MFA where needed.

3. Scan systems for malware

Check affected devices and connected systems for malware or persistence. Use endpoint security tools to identify anything the attacker may have installed, and rebuild compromised systems if necessary.

4. Notify internal stakeholders

Alert security, IT, leadership, and finance if payment activity was involved. Australian organisations should also assess whether the incident meets the reporting threshold under the Notifiable Data Breaches scheme and consider reporting it through ReportCyber.

5. Conduct a post-incident review

Once contained, review how the attacker got in and what control failed. Use the findings to improve training, technical controls, and response procedures so the same attack is less likely to succeed again.

Nexon’s cyber security checklist is a practical starting point for tightening the controls that reduce the chance of a repeat.

Spear phishing vs other phishing attacks

Spear phishing is one type of phishing, distinguished by its precision: it targets a specific person or role with a message tailored to them. This contrasts with ordinary phishing, which is sent in bulk to as many people as possible. Several related terms describe variations on the same social engineering method, differing mainly in who they target and how the message is delivered. The table below compares the most common forms.

 

Attack type
Who targets it
Personalisation
Typical Goal
Phishing

Large, untargeted groups

Low, generic templates

Steal credentials or spread malware at scale

Spear phishing

A named individual or specific role

High, based on research about the target

Credential theft, fraud, or network access

Whaling

Senior executives and decision-makers

High, tailored to the executive

Large transfers, sensitive data, or strategic access

Business email compromise (BEC)

Finance, payroll, or staff who authorise payments

High, often impersonating a trusted colleague or supplier

Fraudulent payments or data transfers

Smishing and vishing

Individuals by SMS or phone

Varies, often personalised

Credentials, one-time codes, or payment approval

The common thread is trust. Whatever the channel, these attacks work by impersonating someone the target expects to hear from. Spear phishing simply involves more research and personalisation, making it harder to spot than bulk phishing. In practice, the categories often overlap: business email compromise, for example, may use spear phishing-style lures to trick staff into approving payments or sharing access.

How Nexon helps organisations defend against spear phishing

Nexon helps organisations defend against spear phishing by combining cyber awareness training, Essential Eight-aligned controls, Australian-based 24/7 monitoring, and penetration testing across the full security lifecycle, from strengthening staff vigilance and email defences to detecting and responding to the attacks that get through.

Ready to close the gaps? Explore our cyber security solutions or contact us today to discuss a tailored solution for your organisation.

FAQs

What is the difference between phishing and spear phishing?

Phishing is sent in bulk to many people with generic messages, while spear phishing targets a specific person or role using details about them. That personalisation is what makes spear phishing more convincing and harder to spot.

They work because they use real detail, appear to come from someone the target trusts, and add a sense of urgency so the person acts before checking. The personalisation removes the usual signs that would mark a message as a scam.

Anyone can be targeted, but attackers favour people with access to money or data, such as staff in finance, payroll, and HR, as well as executives. Newer employees are also common targets, as they may be less familiar with internal processes and more likely to comply with an apparent authority.

Yes. The same targeted method is used over SMS (smishing), phone and voice calls (vishing), and messages sent through trusted third-party or collaboration platforms, not only email.

Disconnect the device from the network, notify your IT or security team immediately, and do not enter any further information. If you entered a password, change it and any reused passwords, then enable or re-check multi-factor authentication on the affected accounts.

Yes. Targeted phishing is one of the common ways attackers gain initial access that later leads to ransomware. Verizon found ransomware present in 44% of the breaches it analysed in 2025.

AI can help attackers write more fluent and personalised messages at scale and support voice cloning and deepfake-based scams. That makes targeted lures harder to spot and easier to trust.

References

More articles to explore

Security
nexon_business_solutions_crm_hero_v1
Remote-Team-Building-Activities-in-2021