Attack technique

Spear Phishing

A targeted phishing attack that uses personalized details about a specific individual or organization to make a fraudulent message far more convincing.

Definition

Spear phishing is a form of phishing in which an attacker crafts a fraudulent message tailored to a specific person, role, or organization. Unlike broad, generic phishing campaigns sent to large lists, spear phishing relies on reconnaissance: the attacker gathers details such as the target's name, job title, employer, colleagues, recent projects, or vendor relationships, then weaves these into a message that feels authentic and contextually relevant. The goal is typically to harvest credentials, trick the recipient into authorizing a payment, or deliver malware, and the personalization sharply increases the odds that the target will comply.

A spear phishing attack usually begins with open-source intelligence gathering. Attackers mine LinkedIn, corporate websites, social media, press releases, and data from prior breaches to build a profile of the target and the people they trust. They then impersonate a believable sender, often a manager, a finance colleague, an IT administrator, or a known supplier, and reference real context such as an ongoing deal, an invoice, or an internal system. Because the message aligns with what the recipient expects to receive, it bypasses the mental filters that catch obvious spam.

A common example is an email that appears to come from a company's CFO, addressed to a specific accounts-payable clerk by name, referencing a genuine vendor and requesting an urgent change to banking details before a payment runs. Another is a message that looks like an internal IT notice asking a named employee to re-authenticate on a fake login page that mirrors the organization's real portal. The narrow targeting and accurate detail are what separate spear phishing from mass phishing.

Spear phishing matters because it is the entry point for many of the costliest security incidents, including business email compromise, ransomware deployment, and large-scale data theft. A single convincing message to the right person can give an attacker a foothold inside an organization. For regulated institutions in Indonesia, such as banks and government bodies subject to OJK and UU PDP requirements, a successful spear phishing attack can lead to financial loss, regulatory exposure, and reportable personal data breaches. Technical controls help, but the decisive factor is usually whether the targeted human recognizes and reports the attempt.

At a glance

Severity
High
Prevalence
Targeted / less common than mass phishing
Primary targets
Specific employees with access to money, data, or systems (finance, HR, IT)

How it works

  1. 1

    Reconnaissance: the attacker gathers details about the target from LinkedIn, company sites, social media, and prior breach data.

  2. 2

    Profiling: they identify who the target trusts, such as a manager, finance colleague, IT administrator, or known supplier.

  3. 3

    Message crafting: the attacker writes a message referencing real context, like an ongoing deal, invoice, or internal system, to feel authentic.

  4. 4

    Delivery: the tailored message is sent, often appearing to come from someone the target already works with.

  5. 5

    Exploitation: because it matches what the recipient expects, it bypasses the mental filters that catch obvious spam, leading to credential theft, fraud, or malware installation.

Warning signs

  • A message referencing accurate but sensitive details, like a real project or vendor
  • An urgent request from what looks like a manager or colleague, especially about banking details
  • A sender address that mimics a real person but is subtly altered
  • Requests to re-authenticate on a login page you did not expect
  • Pressure to bypass normal approval or verification steps

How to defend

  • Verify unusual or urgent requests through a separate, known channel
  • Be cautious with messages referencing internal details, even if accurate
  • Confirm any change to banking or payment instructions by phone
  • Use phishing-resistant multi-factor authentication on all accounts
  • Report tailored or suspicious messages, even if you did not act on them

Real-world example

An accounts-payable clerk at an Indonesian manufacturing firm receives an email that appears to come from the CFO by name, referencing a real ongoing vendor contract and requesting an urgent change to that vendor's bank account before the next payment. The detail feels convincing enough that only a phone call to the vendor prevents the fraudulent transfer.

How Claro helps

Claro helps organizations measure and reduce spear phishing risk by running realistic, personalized phishing simulations that mirror how real attackers research and target specific employees and roles. Rather than testing staff with generic bait, Claro can model role-aware scenarios, then feed the results into per-user and per-department risk scoring so security teams see exactly who is vulnerable. When an employee clicks or submits credentials, just-in-time awareness and micro-module training are triggered automatically, and reporting metrics show whether targeted users are getting better at spotting and reporting tailored lures over time.

Frequently asked questions

How is spear phishing different from whaling?

Spear phishing targets a specific individual or role using researched detail, and can be aimed at anyone in an organization. Whaling is a subset of spear phishing that specifically targets senior executives and other high-value individuals.

Why is spear phishing more dangerous than regular phishing?

The personalization makes the message feel authentic and expected, so it slips past the skepticism that catches generic phishing. It also tends to target people with access to money, data, or systems, so a single success can cause outsized damage.

How do attackers gather information for spear phishing?

Common sources include LinkedIn profiles, company websites, press releases, social media posts, and data exposed in prior breaches. Attackers combine these to build a believable pretext referencing real names, projects, or vendor relationships.

Can technical controls alone stop spear phishing?

No. Because spear phishing messages are crafted to look legitimate and often contain no malware or obvious links, technical filters catch only some of them. Verification habits and a trained, vigilant workforce are the decisive defense.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo