Safety Instinct

Navigation


Articles · Phishing · 2 min read

What is spear phishing?

Spear phishing is a phishing attack built for one person — a scam message tailored with real details about you so it feels legitimate. It works in four steps:

Illustration of a phishing email stealing credentials
1

The research

They learn who you are

Before a word is written, they gather your name, your job, your colleagues, your recent activity — pulled from social media posts and leaked data. Ordinary phishing goes out to thousands of strangers; this one is built around you.

2

The tailored message

It names real people

An email or direct message that mentions real colleagues and references real events. Nothing feels off, because everything in it is true — the details make a stranger read like someone who belongs in your world.

3

The believable ask

A request that fits

The request matches your day: an invoice from a supplier you actually use, a file from your "boss", a password reset you were half-expecting. It asks for exactly what you'd expect to hand over.

4

The payoff

Caution never triggers

Because the message is personal and plausible, it slips past the doubt a generic scam would trigger — and you act before you question it. The more a message knows about you, the more it deserves a second check — confirm the request another way, using contact details you already trust.

Ordinary phishing casts a wide, generic net and hopes someone bites. Spear phishing skips the net and aims at you. When a message feels tailor-made, slow down and verify it.

Also worth knowing

Illustration of a phishing email stealing credentials

Phishing · 2 min

What is phishing?