Back to the glossary
    Social engineering & phishingCybersecurity glossary

    Spear phishing

    Phishing aimed at a specific person, built with real data about their role, company and tools. Far more effective than mass campaigns.

    Full definition

    Spear phishing is a phishing attack aimed at a specific person or organization, built with real information about the victim: their role, their projects, their vendors, the tools they use. That personalization makes the message look legitimate and multiplies the chance the victim falls for it.

    Attackers gather context from public sources (OSINT), previous data breaches or compromised mailboxes inside the same organization. A message that mentions a real project, imitates a real vendor and arrives at the expected moment looks nothing like mass phishing with spelling mistakes.

    This is why training with generic simulations falls short: if the real attack is personalized, the simulation that measures and trains behavior must be personalized too, with scenarios that combine role, department and the company's actual tool stack.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.