Blog
Guide 2026-07-21 8 min read

Spear Phishing and Whaling: The Tailored Attack

A mass campaign counts on a fraction of a percent of clicks. Spear phishing needs one. We explain where attackers get their knowledge of your company, and why a payment procedure protects you better than vigilance.

The biggest mistake in thinking about spear phishing is treating it as better phishing. It is a different attack. A mass campaign plays the odds. A targeted one goes after a specific person and a specific transfer. A filter catches the first through repetition. The second has nothing to repeat.

What is spear phishing?

Spear phishing targets a specific individual or a small group. Instead of a thousand identical messages, the attacker sends one, written after days or weeks of collecting information about the victim.

The result is that classic warning signs stop being useful. The message has no language errors. It references a project that is genuinely running. It comes from someone the victim really works with, at a moment when that makes sense. The whole mechanism comes down to context. In the wider picture it is one of the variants covered in our guide to types of phishing, but for businesses it is the most expensive one.

What it costs

Spear phishing rarely ends at a stolen password. Usually it ends at a payment. The FBI IC3 report for 2025 gives concrete numbers for BEC, meaning business email compromise:

  • $3.046 billion in reported losses in 2025 alone, up from $2.77 billion the year before
  • Over $122,000 in average loss per reported incident
  • 86% of stolen funds move by wire transfer or ACH
  • Over $30 million in losses attributed to attacks with a confirmed AI component

Worth pairing that with another figure from the same report. Phishing and spoofing complaints stayed roughly flat year on year, but losses rose 208%. Attackers are no longer optimising for the number of victims, only for the value of each one.

How it differs from mass phishing

Both techniques share a goal but have completely different economics and risk profiles:

  • Scale: a mass campaign reaches thousands, spear phishing reaches one person
  • Preparation: anywhere from a few minutes to several weeks of reconnaissance
  • Personalisation: an off-the-shelf template versus content referencing the victim's real business
  • Detection: mass campaigns give themselves away through repetition, targeted attacks have nothing to repeat
  • Stakes: a stolen password versus a payment approved by someone with authority

Whaling: when the board is the target

Whaling is spear phishing aimed at the most senior roles. CEO, CFO, board member. The name refers to the size of the prize, because that account carries access to strategic information and authority nobody below has.

Leadership is more exposed than the rest of the organisation, for reasons that are hard to remove. Their details are public in press releases and company registries. They work under time pressure, often outside standard procedure. And subordinates rarely question an instruction from the CEO. That last point matters most, because the attack does not need to compromise an account at all. It only needs the message to look right.

How a targeted attack unfolds

Phase 1

Target reconnaissance

The attacker builds a profile: role, responsibilities, managers, current projects, writing style, travel plans. Almost all of it is public.

Phase 2

Building the pretext

A scenario gets built around the victim's reality. A reference to a live transaction, an urgent invoice approval, a message supposedly sent from an airport before takeoff.

Phase 3

Contact and compromise

The message reaches the target, usually from a lookalike address. More and more often a call or text follows, to lend the request credibility.

Phase 4

Achieving the objective

At the end there is a payment to the criminal's account, exfiltrated documents, or lasting mailbox access used later for further attacks inside the company.

What attackers already know about your company

Reconnaissance rarely requires a breach. What the organisation publishes itself is usually enough:

  • Professional networks: org structure, roles, personnel changes
  • Company website: email format, names, departmental contacts
  • Registries and filings: board members, ownership links, financial position
  • Social media: travel, conferences, photos of badges and screens
  • Previous breaches: passwords and addresses leaked from other services
  • Job postings: technologies, internal systems, sometimes the security tooling by name

Warning signs

Since a targeted attack is linguistically polished, attention has to move from the form to the nature of the request:

  • The request bypasses standard procedure, for example "don't involve finance, let's handle this directly"
  • Pressure for confidentiality set alongside pressure of time
  • A changed account number in an ongoing matter, even if the thread looks familiar
  • Replies route to a different address than the message appeared to come from
  • An instruction from someone who does not normally handle such things
  • A difference in the sender domain: a swapped letter, another suffix, an added hyphen

KEY TAKEAWAYS

  • 1
    One well-prepared message is more dangerous than a thousand generic ones, because it evades filters built on repetition
  • 2
    Reconnaissance uses open sources, so limit what you publish about company structure
  • 3
    The board needs its own training programme, not the same one as everyone else
  • 4
    Verify on a return channel: call a number from your own records, do not reply to the message
  • 5
    The payment procedure has to work even when the request looks authentic

How to defend

Defence rests on processes that urgency and authority cannot bypass:

  • Require two-person approval for payments above a defined threshold
  • Confirm every account number change by phone, using a number from your own records rather than the message
  • Cover executives and their assistants with spear phishing simulations built on real reconnaissance instead of a stock template
  • Deploy hardware keys for accounts with elevated privileges
  • Tag external messages with a visible warning in the mail client
  • Limit organisational detail published on your website and in job listings
  • Let leadership raise doubts without worrying about looking naive
  • Benchmark your procedures against the Social Engineering Report 2026

Conclusion

Spear phishing exploits something you cannot switch off: trust in familiar names, and willingness to move fast when a manager asks. A defence based on spotting fake messages will eventually fail, because these messages are good. What works is a procedure that demands confirmation regardless of how convincing the request sounds.

If your procedure only works when you spot the fraud, it is not a procedure. It is a lottery.

Test the board before someone else does

We build spear phishing simulations from real reconnaissance of your organisation, the same way an attacker would. No stock templates, and a report showing exactly where the procedure gave way.

Book a simulation

SECURE YOUR
FUTURE TODAY

Cyber threats don't sleep, and neither do we. Whether you need an immediate response to a breach or a long-term strategic security partner, ZeroLayer is ready.

Book a 30-minute call

Pick a time that works for you and talk directly to our security team.