Spear Phishing and Whaling: The Tailored Attack
A mass campaign counts on a fraction of a percent of clicks. Spear phishing needs one. We explain where attackers get their knowledge of your company, and why a payment procedure protects you better than vigilance.
The biggest mistake in thinking about spear phishing is treating it as better phishing. It is a different attack. A mass campaign plays the odds. A targeted one goes after a specific person and a specific transfer. A filter catches the first through repetition. The second has nothing to repeat.
What is spear phishing?
Spear phishing targets a specific individual or a small group. Instead of a thousand identical messages, the attacker sends one, written after days or weeks of collecting information about the victim.
The result is that classic warning signs stop being useful. The message has no language errors. It references a project that is genuinely running. It comes from someone the victim really works with, at a moment when that makes sense. The whole mechanism comes down to context. In the wider picture it is one of the variants covered in our guide to types of phishing, but for businesses it is the most expensive one.
What it costs
Spear phishing rarely ends at a stolen password. Usually it ends at a payment. The FBI IC3 report for 2025 gives concrete numbers for BEC, meaning business email compromise:
- $3.046 billion in reported losses in 2025 alone, up from $2.77 billion the year before
- Over $122,000 in average loss per reported incident
- 86% of stolen funds move by wire transfer or ACH
- Over $30 million in losses attributed to attacks with a confirmed AI component
Worth pairing that with another figure from the same report. Phishing and spoofing complaints stayed roughly flat year on year, but losses rose 208%. Attackers are no longer optimising for the number of victims, only for the value of each one.
How it differs from mass phishing
Both techniques share a goal but have completely different economics and risk profiles:
- Scale: a mass campaign reaches thousands, spear phishing reaches one person
- Preparation: anywhere from a few minutes to several weeks of reconnaissance
- Personalisation: an off-the-shelf template versus content referencing the victim's real business
- Detection: mass campaigns give themselves away through repetition, targeted attacks have nothing to repeat
- Stakes: a stolen password versus a payment approved by someone with authority
Whaling: when the board is the target
Whaling is spear phishing aimed at the most senior roles. CEO, CFO, board member. The name refers to the size of the prize, because that account carries access to strategic information and authority nobody below has.
Leadership is more exposed than the rest of the organisation, for reasons that are hard to remove. Their details are public in press releases and company registries. They work under time pressure, often outside standard procedure. And subordinates rarely question an instruction from the CEO. That last point matters most, because the attack does not need to compromise an account at all. It only needs the message to look right.
How a targeted attack unfolds
Target reconnaissance
The attacker builds a profile: role, responsibilities, managers, current projects, writing style, travel plans. Almost all of it is public.
Building the pretext
A scenario gets built around the victim's reality. A reference to a live transaction, an urgent invoice approval, a message supposedly sent from an airport before takeoff.
Contact and compromise
The message reaches the target, usually from a lookalike address. More and more often a call or text follows, to lend the request credibility.
Achieving the objective
At the end there is a payment to the criminal's account, exfiltrated documents, or lasting mailbox access used later for further attacks inside the company.
What attackers already know about your company
Reconnaissance rarely requires a breach. What the organisation publishes itself is usually enough:
- Professional networks: org structure, roles, personnel changes
- Company website: email format, names, departmental contacts
- Registries and filings: board members, ownership links, financial position
- Social media: travel, conferences, photos of badges and screens
- Previous breaches: passwords and addresses leaked from other services
- Job postings: technologies, internal systems, sometimes the security tooling by name
Warning signs
Since a targeted attack is linguistically polished, attention has to move from the form to the nature of the request:
- The request bypasses standard procedure, for example "don't involve finance, let's handle this directly"
- Pressure for confidentiality set alongside pressure of time
- A changed account number in an ongoing matter, even if the thread looks familiar
- Replies route to a different address than the message appeared to come from
- An instruction from someone who does not normally handle such things
- A difference in the sender domain: a swapped letter, another suffix, an added hyphen
KEY TAKEAWAYS
- 1One well-prepared message is more dangerous than a thousand generic ones, because it evades filters built on repetition
- 2Reconnaissance uses open sources, so limit what you publish about company structure
- 3The board needs its own training programme, not the same one as everyone else
- 4Verify on a return channel: call a number from your own records, do not reply to the message
- 5The payment procedure has to work even when the request looks authentic
How to defend
Defence rests on processes that urgency and authority cannot bypass:
- Require two-person approval for payments above a defined threshold
- Confirm every account number change by phone, using a number from your own records rather than the message
- Cover executives and their assistants with spear phishing simulations built on real reconnaissance instead of a stock template
- Deploy hardware keys for accounts with elevated privileges
- Tag external messages with a visible warning in the mail client
- Limit organisational detail published on your website and in job listings
- Let leadership raise doubts without worrying about looking naive
- Benchmark your procedures against the Social Engineering Report 2026
Conclusion
Spear phishing exploits something you cannot switch off: trust in familiar names, and willingness to move fast when a manager asks. A defence based on spotting fake messages will eventually fail, because these messages are good. What works is a procedure that demands confirmation regardless of how convincing the request sounds.
If your procedure only works when you spot the fraud, it is not a procedure. It is a lottery.
Test the board before someone else does
We build spear phishing simulations from real reconnaissance of your organisation, the same way an attacker would. No stock templates, and a report showing exactly where the procedure gave way.