Spear phishing
Phishing aimed at a specific person, built with real data about their role, company and tools. Far more effective than mass campaigns.
Full definition
Spear phishing is a phishing attack aimed at a specific person or organization, built with real information about the victim: their role, their projects, their vendors, the tools they use. That personalization makes the message look legitimate and multiplies the chance the victim falls for it.
Attackers gather context from public sources (OSINT), previous data breaches or compromised mailboxes inside the same organization. A message that mentions a real project, imitates a real vendor and arrives at the expected moment looks nothing like mass phishing with spelling mistakes.
This is why training with generic simulations falls short: if the real attack is personalized, the simulation that measures and trains behavior must be personalized too, with scenarios that combine role, department and the company's actual tool stack.
Related terms
Phishing
An attack that impersonates a trusted sender, such as a bank, a colleague or a vendor, to steal credentials, data or money, or install malware.
Whaling
Spear phishing aimed at executives with signing power or privileged access. It goes after payments, strategic information or the executive's own mailbox.
Business email compromise (BEC)
Fraud where the attacker poses as an executive or vendor from a legitimate or spoofed mailbox to divert payments or data. It usually carries no malware.
OSINT
Intelligence built from public sources: websites, social media, records. The same information serves defense and attack preparation.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.