Spear Phishing: When the Email Is Written for You
Spear phishing uses research about you, your job and your colleagues to craft a believable message. How it works, real-world patterns, and how individuals and teams defend against it.

Most phishing is a numbers game. Spear phishing is personal. The attacker researches you, your role, your colleagues and your projects, then writes a message that fits your day so well that nothing seems wrong.
What makes it convincing
- Your name, title and team.
- Real colleagues, suppliers or clients mentioned by name.
- Current events in your work: a conference, a project, a new hire, a merger.
- Your writing style or your manager's, copied from public posts or leaked emails.
See how attackers research their targets.
Common goals
- Stealing a work login to reach email, files or systems.
- Getting a payment approved. See phishing aimed at finance teams.
- Installing malware as a foothold for bigger attacks.
Defences that work
- Verify out of band: confirm unusual requests by phone or in person.
- Protect sign-in with passkeys or security keys. See passkeys vs phishing.
- Limit public detail about roles, reporting lines and processes.
- Make reporting easy and quick. See report buttons.
Received an email that knows a lot about you? Paste it into CyberWatch AI Scan for a free check.
For all the types of phishing, read our complete guide.
Frequently asked questions
How is spear phishing different from normal phishing?
Normal phishing is sent to many people with a generic message. Spear phishing is tailored to a specific person or small group, using details about them.
Who gets targeted?
People with access to money, data or systems: finance staff, executives, HR, IT administrators and assistants, as well as anyone whose account can be used to reach them.
What is the best defence?
Verification processes for payments and access requests, phishing-resistant sign-in, and a culture where checking is expected.
Sources
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
- Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency
- Small business guide: cyber security, UK National Cyber Security Centre


