Spear phishing is a phishing attack tailored to a specific person, role, or organization using researched personal or contextual detail, so the lure reads as genuinely coming from a known, trusted source. Where mass phishing trades precision for volume, spear phishing trades volume for precision: the attacker invests in a small number of targets, drawing on org charts, social media, press releases, out-of-office replies, and prior breaches to build a message that fits the target’s world.
It may reference a real project, a real colleague, a genuine upcoming event, or your actual name, title, and reporting line. That specificity is the whole point — personalization is a powerful credibility cue, and a message that “knows” you defeats the generic-greeting tell that catches bulk phishing. The executive-focused variant is called whaling. Because each message is bespoke and low-volume, it often slips past signature-based filters as a plausible one-off.
The defining feature — and the recognition hook — is a message that is unusually personalized and credible yet still asks for something off the normal channel: a login, a payment, a credential, an attachment, or secrecy, routed through the message rather than through your established process. It is the delivery mechanism behind targeted intrusion, business email compromise, and espionage access.