Insights on Crypto Payments, Infrastructure, and Operations

Spear Phishing

Pronunciation: SPEER FISH-ing

Definition

Spear Phishing is a targeted phishing attack tailored to a specific person, role, team, or organization using information that makes the message or request appear credible. Unlike broad phishing campaigns, spear phishing selects victims and adapts the pretext, sender identity, timing, or requested action. It should be interpreted alongside Phishing, which may affect the same workflow without representing the same control, event, or risk. It can lead to credential theft, malware execution, fraudulent payment approval, sensitive-data disclosure, account takeover, and compromise of trusted business relationships.

Overview

Spear Phishing is a targeted phishing attack tailored to a specific person, role, team, or organization using information that makes the message or request appear credible. Unlike broad phishing campaigns, spear phishing selects victims and adapts the pretext, sender identity, timing, or requested action. It should be interpreted alongside Phishing, which may affect the same workflow without representing the same control, event, or risk.

It can lead to credential theft, malware execution, fraudulent payment approval, sensitive-data disclosure, account takeover, and compromise of trusted business relationships.

Organizations should use phishing-resistant MFA, sender and domain protections, contextual verification, safe-link controls, staff exercises, privileged-action confirmation, and rapid reporting channels.

Retain the original message, headers, domains, attachments, clicked URLs, authentication events, affected accounts, user report, containment actions, and campaign indicators.

Operational review of Spear Phishing should reconstruct a targeted phishing attack tailored to a specific person, role, team, or organization using information that makes the message or request appear credible using the identities, communications, devices, and transaction records available for the affected case. Investigators should separate confirmed facts from hypotheses about role, team, and request appear credible, preserve the original evidence, and document why the event was cleared, escalated, or treated as a loss. Containment, recovery, and customer communication for the Spear Phishing context should match the harm indicated by role, team, and request appear credible.

Quality review for Spear Phishing should compare expected and actual outcomes involving role, team, and request appear credible, then track false positives, repeat attempts, linked losses, and unresolved remediation.

Key Takeaway

Spear Phishing is a targeted phishing attack tailored to a specific person, role, team, or organization using information that makes the message or request appear credible.

Sources

  1. Avoiding Social Engineering and Phishing Attacks — CISA (2026-08-03)
  2. Digital Identity Guidelines, SP 800-63-4 — NIST (2026-08-03)
  3. MITRE ATT&CK: Drive-by Compromise — MITRE (2026-08-03)