Unlike regular phishing that sends millions of identical emails, spear phishing is a targeted and personalized attack. The hacker knows you — or pretends to.

What is spear phishing?

Spear phishing is an attack where the fraudster personalizes their message using information about you: your name, employer, colleagues, recent projects. The goal is to make the email so credible that you have no reason to be suspicious.

How do hackers collect this information?

  • LinkedIn: Job title, employer, colleagues, projects
  • Facebook/Instagram: Interests, frequented places, events
  • Data breaches: Compromised databases available on the dark web
  • Company website: Org chart, executive names, generic email
⚠️ Real example: "Hi [Your name], following our Monday meeting with [real colleague's name], please validate this HR document before 5pm." — This type of message comes from an address mimicking your company's domain.

How to protect yourself?

  • Always verify the sender's full email address (not just the displayed name)
  • When in doubt, contact the sender through another channel (phone, message)
  • Limit public information on your professional profiles
  • Enable 2FA to limit damage if compromised
  • Be wary of urgent requests involving money transfers or sensitive data

Spear phishing warning signs

  • The email uses your first name and precise personal information
  • It creates urgency: "before 5pm", "within the hour"
  • It requests an unusual action (transfer, confidential data)
  • The email address looks like your company's but isn't exact