Home > Threat Library > Spear Phishing
๐ŸŽฏ

Spear Phishing

Critical Severity65% of known attack groups use spear phishing as their primary infection vector

Spear phishing is a targeted form of phishing where attackers research specific individuals and craft personalized emails using details about the victim's role, relationships, and activities.

How it works

  1. Attackers research the target via LinkedIn, company websites, and social media
  2. Emails reference real projects, colleagues, or events to build trust
  3. The "sender" is often a spoofed colleague, boss, or business partner
  4. Attachments or links deliver malware or credential-harvesting pages

Red flags to watch for

  • Email references a real project but with an unusual request
  • Colleague asking you to bypass normal procedures "just this once"
  • Unexpected attachment from someone who usually doesn't send files
  • Slight variations in the sender's email (john.sm1th vs john.smith)
  • Requests to wire money, change payment details, or share credentials

Real-world example

Subject: Re: Q4 Budget Review โ€” Updated figures
From: sarah.johnson@companynamee.com
โ€œHi Mike, attached are the updated Q4 budget figures you asked about in our meeting yesterday. Can you review and approve the wire transfer to the new vendor by end of day? Sarahโ€

How to protect yourself

  • Verify unusual requests through a separate communication channel (phone call, Slack)
  • Check email domains character by character for subtle misspellings
  • Be suspicious of urgency, especially around financial transactions
  • Use SiftMail's anomaly detection to catch domain-similar senders

How SiftMail detects this

SiftMail's Business tier includes anomaly detection that uses Levenshtein distance to catch domain-similar addresses and homoglyph detection to identify character substitution attacks.

Stop spear phishing before they reach your inbox

SiftMail scores every incoming email and automatically quarantines threats. Free plan available, setup takes 30 seconds.

Protect My Inbox FreeCheck a Suspicious Email

Related threats

๐ŸŽฃPhishing Emails๐Ÿ’ผBusiness Email Compromise (BEC)๐Ÿ‘”CEO Fraud๐ŸงพInvoice & Payment Scams