Spear phishing thrives on trust and urgency; independent verification, secure accounts, and safer payment processes stop a convincing message from becoming a costly breach.
Why Spear Phishing Is So Effective
Spear phishing is a targeted scam. Instead of sending a generic message to thousands of people, criminals research a specific person, team, supplier, or organization and create a request that feels relevant.
The message may appear to come from your manager, a client, a recruiter, a bank, a government agency, a software provider, or a trusted vendor. It may mention a real project, event, invoice, job title, colleague, or recent social media post.
That context is what makes spear phishing dangerous. A message can be well written, use the correct logo, include real personal details, and even come from a compromised legitimate account. None of those things prove the request is safe. Business email compromise scams commonly use compromised accounts, lookalike domains, and trusted business relationships to redirect payments or steal information.
Spear phishing is not limited to email. It can arrive through text messages, collaboration apps, social media, phone calls, QR codes, fake shared-document alerts, or virtual meeting invitations. The goal is usually the same: make you act before you verify.
Start With the Three Rules That Matter Most
The best defense is not spotting every scam perfectly. It is making sure one unexpected message cannot trigger a high-risk action.
1. Pause
Do not click a link, open an attachment, scan a QR code, reply, approve a sign-in request, or transfer money immediately.
Urgency is a common manipulation tactic. Be especially cautious when a message demands secrecy, threatens consequences, or pressures you to act outside normal procedures.
2. Verify Independently
Contact the sender through a trusted channel that you already know is genuine.
Use a saved phone number, a company directory, an existing customer portal, a verified email address, or an official app. Do not use the phone number, reply address, or link provided in the suspicious message.
3. Act Only After Confirmation
Complete the request only after you have independently confirmed it is legitimate.
A familiar name, a professional-looking message, and correct personal details are not proof that a request is genuine.
For example, if a supplier emails new banking details, call a known contact using the number already stored in your records. If your bank says there is a problem with your account, open the official app or type the known website address into your browser instead of using the link in the message.
Treat These Requests as High Risk
Spear phishing often works because it copies normal business activity. The risk increases when a message asks you to change an existing process, bypass a control, or act alone.
| If a message asks you to… | Safer response |
|---|---|
| Change bank account details | Call the supplier using a known number before changing anything. |
| Pay an invoice urgently | Verify the request and payment details outside email. |
| Buy gift cards or send money | Contact the person through a separate trusted channel. |
| Reset a password or sign in again | Open the service through a bookmark, official app, or known URL. |
| Approve an MFA prompt | Deny it unless you initiated the sign-in yourself. |
| Share a one-time code | Do not share it. Legitimate providers do not need your code. |
| Open a shared document | Confirm the sender and access the file through the usual platform. |
| Scan a QR code | Treat it like a link and verify where it leads before scanning. |
| Keep a request secret | Assume the secrecy demand is a warning sign and verify it. |
Be especially careful with messages involving:
- New or changed payment details
- Payroll, tax, legal, medical, or identity documents
- Password resets or account reauthentication
- Unexpected file-sharing invitations
- Requests from executives outside normal working hours
- Urgent requests to move money or buy gift cards
- Requests to install software or approve access
- Messages asking you to bypass normal approval steps
- QR codes that claim to lead to invoices, shared files, or sign-in pages
A real colleague may sometimes make an unusual request. The answer is not to ignore them. The answer is to verify the request safely before acting.
Do Not Rely on Obvious Red Flags
Poor grammar, strange formatting, generic greetings, and suspicious links can still expose many scams. But they are no longer reliable tests by themselves.
Targeted phishing messages can be polished, personalized, and written in a convincing style. They may also come from a real but compromised email account. Canadian cyber guidance specifically warns users not to click unsolicited links, attachments, or QR codes and to visit organizations through trusted routes instead.
Instead of asking, “Does this message look fake?” ask:
- Is this request expected?
- Is it normal for this person or organization?
- Does it follow our usual process?
- Is the timing unusual?
- Does it involve money, passwords, codes, files, or access?
- Have I independently verified the request?
That shift matters. Attackers can imitate branding, writing style, and business context. They cannot easily survive an independent verification step.
Protect Your Email and Important Accounts
Email is often the starting point for account takeover. If someone gains access to your inbox, they may reset passwords, search for financial information, impersonate you, create forwarding rules, or target your contacts.
Start with these controls:
- Use a unique, long password for every important account.
- Use a password manager to generate and store strong passwords.
- Enable multifactor authentication on email, cloud storage, financial accounts, workplace tools, and social media.
- Review recovery email addresses and phone numbers.
- Check for unfamiliar devices, active sessions, mailbox rules, and connected apps.
- Remove unknown inbox delegates and forwarding rules.
- Keep browsers, operating systems, apps, and security software updated.
Multifactor authentication is important, but not all methods provide the same protection. Any MFA is better than none, yet phishing-resistant options such as passkeys, FIDO security keys, and other WebAuthn-based methods provide stronger protection against fake sign-in pages than passwords, SMS codes, or basic approval prompts.
Never approve an MFA prompt you did not initiate. Repeated unexpected prompts may be an MFA fatigue attack, also called push bombing, where criminals hope you will accept one request just to make the notifications stop.
Watch for Fake App Permissions and Shared-File Scams
Not every phishing attempt tries to steal your password directly.
Some attacks use realistic Microsoft 365, Google Workspace, Dropbox, or file-sharing pages that ask you to authorize an application. Others send a fake document-sharing alert that leads to a fraudulent sign-in page.
Before granting an app access to your email, files, contacts, or calendar, ask:
- Did I expect this app or file?
- Does the app need the permissions it is requesting?
- Does the sender normally share documents this way?
- Can I open the platform directly and check for the file there?
Review connected applications regularly and revoke access for anything you do not recognize or no longer use.
Make Public Information Less Useful to Attackers
Spear phishing depends on believable context. The more details criminals can gather, the easier it is for them to impersonate people and create convincing requests.
Review what is publicly visible on:
- LinkedIn and professional profiles
- Social media accounts
- Company websites and staff directories
- Press releases and event pages
- Job advertisements
- Public calendars
- Vendor announcements
- Online portfolios, forums, and personal blogs
You do not need to disappear from the internet. The goal is to avoid publishing details that make impersonation easier.
For individuals, limit public posts about travel, family information, new jobs, workplace systems, financial milestones, and sensitive personal events.
For organizations, avoid publishing unnecessary information such as internal email formats, finance-team contact details, detailed organization charts, technology stacks, project timelines, and executive travel plans.
Build Business Processes That Resist Fraud
Training helps, but training alone is not enough. Spear phishing is designed to exploit pressure, authority, and normal business workflows.
The strongest business defense is a process that prevents one email from causing a financial loss or account compromise.
Use a Known-Good Verification Process
For payment changes, new payees, payroll updates, or sensitive account requests:
- Stop the transaction.
- Contact the requester using a phone number or contact method already on file.
- Confirm the request with a second authorized person when appropriate.
- Record the verification.
- Complete the request only after both checks are complete.
Never accept supplier bank-detail changes by email alone.
Separate High-Risk Duties
Reduce the chance that one person can create and approve a risky transaction.
Useful controls include:
- Require two approvals for high-value payments.
- Separate the person requesting a payment from the person authorizing it.
- Require finance staff to verify new payees and banking changes.
- Set approval thresholds for payment amounts.
- Require documented exceptions for urgent or out-of-process payments.
- Use secure portals for sensitive documents instead of email attachments.
- Make it clear that employees will not be penalized for pausing a suspicious request.
Business email compromise targets trusted payment processes, not just poorly protected inboxes. Independent verification is particularly important when money, invoices, supplier details, or executive instructions are involved.
Give Staff a Simple Reporting Path
Employees should be able to report suspicious messages quickly without worrying about blame or embarrassment.
Organizations should provide:
- A one-click “Report Phishing” button in email
- A dedicated security reporting mailbox or help channel
- Clear instructions for reporting text messages, QR-code scams, and suspicious calls
- Regular phishing awareness exercises based on realistic scenarios
- A culture that rewards early reporting, including after someone clicks
Fast reporting can protect other employees, block malicious domains, reset compromised accounts, and stop fraudulent payments before funds move further.
Strengthen Email and Identity Security
Technical controls reduce the number of malicious messages that reach people in the first place. They also limit the damage when someone clicks.
Essential Email Security Controls
Organizations should use:
- Spam, malware, and phishing filtering
- Attachment scanning and sandboxing where appropriate
- Safe-link protection and web filtering
- Restrictions on risky attachment types
- Endpoint security on employee devices
- DNS filtering to block known malicious domains
- Monitoring for unusual sign-ins and mailbox-rule changes
- Restrictions on automatic forwarding to external addresses
- Separate administrative accounts for IT staff
- Phishing-resistant MFA for email, cloud platforms, VPNs, and privileged accounts
Use SPF, DKIM, and DMARC
Organizations should configure SPF, DKIM, and DMARC for every email domain they control.
- SPF identifies which mail servers are authorized to send mail for a domain.
- DKIM uses a digital signature to help receiving systems verify that an email has not been altered and is associated with the claimed domain.
- DMARC tells receiving mail systems how to handle messages that fail aligned SPF or DKIM checks and provides reporting to the domain owner.
These controls make it harder for criminals to spoof your real domain. They do not stop every phishing attack, especially messages sent from lookalike domains or compromised legitimate accounts. DMARC should be deployed carefully, with an enforcement policy such as quarantine or reject once legitimate sending services have been identified and configured correctly.
What to Do If You Clicked or Responded
Act quickly, but do not panic. The right response depends on what happened.
If You Clicked a Suspicious Link
Close the page without entering information. Report the message, especially if it involved a work account or device.
If you downloaded a file, opened an attachment, or believe malware may have been installed, stop using the device and contact your IT or security team immediately. Do not assume a basic scan is enough for a work-related incident.
If You Entered a Password
Change the password immediately through the legitimate website or app, not through the suspicious link.
Then:
- Change the password anywhere else you reused it.
- Sign out of active sessions where possible.
- Review MFA methods and recovery details.
- Check for unfamiliar devices and connected apps.
- Review email forwarding rules, inbox delegates, and mailbox settings.
- Notify your employer or IT team if a work account was involved.
If You Approved an MFA Prompt or Shared a Code
Treat the account as potentially compromised.
Change the password from a trusted device, revoke active sessions, review your recovery methods, and contact the organization’s security team or the account provider. Criminals can use stolen credentials and one-time codes to capture active sessions in real time.
If You Sent Money or Changed Payment Details
Contact your bank or payment provider immediately using a verified number. Ask whether the transfer can be recalled or stopped.
Then notify your employer, finance team, supplier, or client as soon as possible. In the United States, the FBI’s Internet Crime Complaint Center advises victims of attempted or actual fraudulent transfers to contact their financial institution immediately and file a report.
If You Shared Sensitive Information
Report the incident promptly and monitor affected accounts. Depending on what was exposed, you may need to contact your bank, credit provider, employer, identity-protection service, or relevant government agency.
Report Phishing and Fraud
Always report suspicious work messages internally first, even if you did not click. Your report may help protect other people.
National reporting options also vary by country:
- United States: Report cyber-enabled fraud and business email compromise to the FBI’s Internet Crime Complaint Center.
- United Kingdom: Forward suspicious emails to the National Cyber Security Centre’s phishing reporting service.
- Australia: Report scams through Scamwatch and cybercrime through ReportCyber.
- Canada: Report phishing, cybercrime, and fraud through the Canadian Centre for Cyber Security and the Canadian Anti-Fraud Centre.
Reporting helps authorities track campaigns, disrupt malicious infrastructure, and warn others. The U.K. NCSC, for example, asks people to report suspicious emails, texts, and scam websites to help stop cybercriminal activity.
The Practical Takeaway
You cannot eliminate spear phishing completely. Criminals adapt, impersonate trusted people, and exploit ordinary business routines.
You can make spear phishing far less effective.
Pause before acting on unexpected requests. Verify sensitive instructions through a separate trusted channel. Never share passwords, verification codes, or unrequested MFA approvals. Secure your email account, use stronger MFA where available, and keep systems updated.
For businesses, build payment and account-change processes that require independent verification and more than one person for high-risk actions.
The strongest defense is not perfect suspicion. It is a system that makes one convincing message insufficient to cause real harm.