Spear phishing is a targeted social engineering attack where an attacker crafts highly personalized messages to a specific individual or team, increasing the likelihood of trust and interaction.
Attackers research the target using public data, breached information, or internal context, then send tailored emails or messages containing malicious links, attachments, or credential-harvesting pages.
Because of its precision and legitimacy, spear phishing often bypasses user suspicion and security controls, leading to credential theft, unauthorized access, lateral movement, or targeted ransomware deployment.
Microsoft warned of sophisticated phishing campaigns targeting energy firms that began with spear-phishing emails from compromised accounts linking to fake SharePoint login portals, which harvested credentials and enabled persistent access.
SourceGet our entire attack repository in a single, offline-ready PDF guide, featuring 25+ real-world attacks.
See how organizations gained 442% ROI and major efficiency improvements with Endpoint Central.
Read moreDiscover how Endpoint Central’s antivirus earned recognition through rigorous, real-world security validation in just eight months.
Read moreGet a clear, practical guide to understanding threats and strengthening your organization’s security.
Read more