Navigation
Articles · Phishing · 2 min read
Spear phishing is a phishing attack built for one person — a scam message tailored with real details about you so it feels legitimate. It works in four steps:

They learn who you are
Before a word is written, they gather your name, your job, your colleagues, your recent activity — pulled from social media posts and leaked data. Ordinary phishing goes out to thousands of strangers; this one is built around you.
It names real people
An email or direct message that mentions real colleagues and references real events. Nothing feels off, because everything in it is true — the details make a stranger read like someone who belongs in your world.
A request that fits
The request matches your day: an invoice from a supplier you actually use, a file from your "boss", a password reset you were half-expecting. It asks for exactly what you'd expect to hand over.
Caution never triggers
Because the message is personal and plausible, it slips past the doubt a generic scam would trigger — and you act before you question it. The more a message knows about you, the more it deserves a second check — confirm the request another way, using contact details you already trust.
Ordinary phishing casts a wide, generic net and hopes someone bites. Spear phishing skips the net and aims at you. When a message feels tailor-made, slow down and verify it.

Phishing · 2 min
What is phishing?