EN - FR - DE - ES - IT - PT -

LexiconDream

🎯 Spear Phishing

A targeted phishing attack aimed at a specific individual or group.

Spear Phishing

Spear phishing targets a specific person or group. Generic phishing casts a wide net. Spear phishing does research. The attacker learns names, roles, projects, and relationships. Then they craft a message that fits. A finance manager gets an invoice from a known vendor. An engineer gets a GitHub notification about a repository they actually work on. A new employee gets an onboarding email from HR. The message looks real because it is built on real details.

Spear phishing is harder to detect than generic phishing. The language is correct. The sender may be a compromised account of someone the target knows. The link may point to a legitimate-looking login page. Email filters struggle because the message does not match known bad patterns. The 2016 Democratic National Committee breach started with a spear-phishing email to John Podesta. The attackers pretended to be Google notifying him about a password change. He clicked. They got his credentials. Defense requires more than filters. It requires verification habits. Check the sender's actual address, not the display name. Hover over links before clicking. Confirm unusual requests through a separate channel. Spear phishing works because it is personalized. Verification habits work because they are not.

Spear phishing characteristics

Spear phishing is the attacker doing their homework. The defense is the target doing theirs.

Comments

No comments yet. Be the first to share a thought.

Leave a comment