S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.3
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Spear Phishing

Digital Lure · Targeted, Personalized Phishing · Common
Red Flag
How It WorksSEC 01

Spear phishing is a phishing attack tailored to a specific person, role, or organization using researched personal or contextual detail, so the lure reads as genuinely coming from a known, trusted source. Where mass phishing trades precision for volume, spear phishing trades volume for precision: the attacker invests in a small number of targets, drawing on org charts, social media, press releases, out-of-office replies, and prior breaches to build a message that fits the target’s world.

It may reference a real project, a real colleague, a genuine upcoming event, or your actual name, title, and reporting line. That specificity is the whole point — personalization is a powerful credibility cue, and a message that “knows” you defeats the generic-greeting tell that catches bulk phishing. The executive-focused variant is called whaling. Because each message is bespoke and low-volume, it often slips past signature-based filters as a plausible one-off.

The defining feature — and the recognition hook — is a message that is unusually personalized and credible yet still asks for something off the normal channel: a login, a payment, a credential, an attachment, or secrecy, routed through the message rather than through your established process. It is the delivery mechanism behind targeted intrusion, business email compromise, and espionage access.

Warning SignsSEC 02
  • Well-informed but off-channel. Unusually accurate about you or your work, yet asking through a channel it shouldn't.
  • Deviant request. Credentials, payment, gift cards, banking changes, or an attachment that breaks the normal process, however plausible.
  • Subtle domain mismatch. A reply-to or sender domain that differs slightly from the real one.
  • Secrecy or urgency. "Handle this directly with me," "before the board call" — pressure to move fast and quiet.
  • Anomalous action, familiar thread. The history looks genuine; the requested action is the anomaly.
  • Suspicious timing. The ask matches a real public event or deal a little too neatly.
Frequently Paired WithSEC 03
  • Phishing · T14.2
    Bulk parent technique
  • Business Email Compromise · T14.10
    The payment-redirect payload
  • Authority Impersonation · T14.7
    Impersonates a named executive
  • Fake Support Portals · T14.22
    The credential-harvest landing page
How the Attack UnfoldsSEC 04
  • Stage 01 · Research
    The attacker mines org charts, social media, press releases, out-of-office replies, and prior breaches to learn the target's world.
  • Stage 02 · Tailor
    A bespoke, low-volume message references a real project, colleague, or event so it reads as genuinely from a known source.
  • Stage 03 · Divert
    Buried in the credibility is an off-channel ask — a login, wire, banking change, or attachment — often with a reason for secrecy or speed.
Counter-ProtocolSEC 05
Defense: Authenticate the request, not the apparent relationship — personalization is no proof.
  • Verify directly. For any payment, banking change, credential, or sensitive-data request, confirm via a contact you already have — never the one in the message.
  • Limit your footprint. Tighten social-media and org-chart exposure; watch what out-of-office and vendor pages reveal.
  • Enforce dual control. Require callback verification and dual authorization on payments and banking changes.
  • Harden auth. Use phishing-resistant MFA so a harvested password alone fails.
  • Normalize the challenge. Make verifying an executive's unusual request expected, not insubordinate.