HomeGlossarySpear Phishing

Spear Phishing

MITRE ATTACK layer: Initial Access

Spear phishing is a targeted social engineering attack where an attacker crafts highly personalized messages to a specific individual or team, increasing the likelihood of trust and interaction.

How is Spear Phishing abused

Attackers research the target using public data, breached information, or internal context, then send tailored emails or messages containing malicious links, attachments, or credential-harvesting pages.

Why Spear Phishing matters

Because of its precision and legitimacy, spear phishing often bypasses user suspicion and security controls, leading to credential theft, unauthorized access, lateral movement, or targeted ransomware deployment.

Real-world example

Credential Theft via SharePoint Phishing

Microsoft warned of sophisticated phishing campaigns targeting energy firms that began with spear-phishing emails from compromised accounts linking to fake SharePoint login portals, which harvested credentials and enabled persistent access.

Source

Get the full attack repository

Get our entire attack repository in a single, offline-ready PDF guide, featuring 25+ real-world attacks.

Please enter a valid email.Please enter a email.
By clicking 'Download EBOOK', you agree to processing of personal data according to the Privacy Policy.

Additional Resources

Achieve 442% ROI and reduce patching time by 95% — Forrester TEI Report

See how organizations gained 442% ROI and major efficiency improvements with Endpoint Central.

Read more
Experience enterprise-grade protection proven in real-world tests — AV-Comparatives Report

Discover how Endpoint Central’s antivirus earned recognition through rigorous, real-world security validation in just eight months.

Read more
Simplify endpoint security and build cyber resilience — Endpoint Security For Dummies

Get a clear, practical guide to understanding threats and strengthening your organization’s security.

Read more

Trusted by