Free security assessment — no obligation Get a Proposal
← All insights
Phishing

Phishing vs spear phishing: what's the difference?

Published Updated

You're probably hearing about phishing everywhere — and for good reason. Research by KnowBe4 has found that the large majority of breaches involve phishing. One especially effective variant is spear phishing. Here's the difference between the two, and how to protect your business from each.

What's the difference between phishing and spear phishing?

Phishing is a more generic attack that uses emails or messages sent to large groups. Spear phishing is highly targeted, aimed at a single individual or a small group inside a company. Spear phishing attacks are more sophisticated and seek a particular outcome.

Whatever form it takes, the attacker's goal is the same: get the target to click a link, download a file, enter credentials, share information, or take some other harmful action.

Traditional phishing

Phishing is the general term for any malicious email or message designed to get someone to take a harmful action. These attacks are usually blasted to large lists in the hope that someone falls for it — by some estimates, billions of phishing emails are sent every day.

Phishing isn't new — the term dates to the mid-1990s. Since then most people have learned to recognize obvious phishing, so when attackers target a specific company they usually switch to spear phishing against a select group. These messages are carefully planned to look legitimate, often asking the victim to open a file or log into a portal.

Common characteristics of spear phishing

Not all of these traits are unique to spear phishing, but they show up often:

It creates emotion

People respond out of logic or emotion, and phishing tries to trigger the latter. Spear phishing messages usually provoke a subtle emotional reaction — fear, excitement, deference to authority, sympathy, or ego.

It appears to come from a trusted sender

Spear phishing usually looks like it's from someone you know or have dealt with. Attackers gather that context using OSINT (open-source intelligence) from social media, websites, and public records — and may even ask you to do something routine, with only tiny clues giving it away.

Most spear phishing emails carry a malicious link or attachment used to gain initial access and then pivot deeper into your network. Occasionally the message simply asks you to wire money or change payment details.

A quick case study

Targeted phishing is remarkably effective. On engagements, we've seen high click rates and have obtained employee credentials across social engineering tests. A typical flow: extensive reconnaissance surfaces a recent company announcement and a separate secure-email portal; the attacker registers a look-alike domain, configures SPF and DMARC to pass filters, and clones the portal's sign-in page; a small, plausible pretext then convinces targets to "log in," handing over credentials — after which the attacker can work to bypass 2FA.

How to protect against spear phishing (and phishing)

The best defense is training employees to identify and report suspicious messages. Attackers keep changing tactics, but well-trained employees stop the majority of them. A few more steps:

  • Security awareness training. Run it regularly — ideally monthly — and include simulated phishing so the lessons stick.
  • Email authentication. SPF, DKIM, and DMARC tell receiving servers who may send mail for your domain and what to do with fakes.
  • Out-of-band verification. When a message looks off or asks for something unusual, verify through another channel — call the person at a number you already know.

Conclusion

Phishing and spear phishing are similar; the key difference is that spear phishing is highly targeted and sent to a much smaller group. The precautions above will meaningfully improve your organization's resilience to both.

More insights