UsefulOrbit

Phishing vs Spear Phishing: Why You Are Targeted

Every phishing scam starts with a message meant to trick you into clicking, paying, or handing over personal data. The difference between a generic phishing blast and a spear phishing attack is how much the sender knows about you. Once you can tell the two apart, you will spot both faster and stop falling for the ones that really hurt.

Illustration of a fishing hook with many envelopes

What is phishing?

Classic phishing is a numbers game. An attacker sends one message to millions of people at once, hoping that even a tiny fraction responds. The email is mass-produced and usually carries generic greetings like "Dear customer" or "Your account has been suspended."

These emails are easy to spot once you know the signs:

  • Urgent or threatening language pushing you to act immediately.
  • A sender address that does not match the company it claims to be from.
  • Links that go somewhere other than where they appear to go.
  • Poor spelling and grammar, though this is becoming less reliable as a clue.

Mass phishing often pretends to be a big brand you likely use. That is why learning how to recognize fake payment emails protects you from a large share of these attacks.

What is spear phishing?

Spear phishing is the targeted version. The attacker knows your name, your employer, or that you recently made a purchase, and builds a message around that detail. That information rarely comes from guesswork. It is pulled from data breaches, social media posts, and publicly available directories.

Where a phisher casts a wide net, a spear phisher has done research on you. The greeting uses your real name. The subject line references something specific, like a shipment you expect or a coworker you met last week. The message simply feels real, because most of it is.

Because the content is personalized, spear phishing demands much less from you. You no longer need to overlook a suspicious greeting or a mismatched sender. The few clues that remain are subtle.

Why targeted emails are more dangerous

A spear phishing email is dangerous because it leans on context instead of volume. It might appear to come from a colleague asking about a shared project, or from a service you actually logged into yesterday. Your brain has already decided the message is legitimate before you look at the details.

Attackers use this trust to ask for small favors that add up:

  1. Confirming your password by "logging in" to a realistic clone page.
  2. Opening an attached invoice or document that installs malware.
  3. Answering a quick question whose reply contains account numbers.

The failure is the same as mass phishing, but each message succeeds far more often. A scammer does not need a million emails when one well-aimed message can drain an account or take over your identity.

The business email compromise variant

One especially costly form of spear phishing is business email compromise (BEC). In this variant, the attacker impersonates a CEO, a vendor, or another trusted figure inside an organization. The fake email asks for an urgent payment, a wire transfer, or a stack of gift cards, with a believable excuse such as a closed office or a supplier who needs immediate funds.

BEC works because it weaponizes authority and urgency together. You are not being asked by a stranger, you are being asked by your boss, and you are told to do it now. These schemes have caused enormous reported losses for businesses and the people who handle their money.

Defenses that actually help

You cannot stop attackers from learning about you, but you can make their research useless. These habits shut down both mass phishing and spear phishing:

  • Verify through a separate channel. If an email asks for money, a password, or gift cards, call the person or company using a number you already know, not one from the email.
  • Check the sender and the link. Hover over links to see the real destination, and inspect the full sender address rather than just the display name.
  • Turn on two-factor authentication. Even if your password leaks, a second factor keeps the attacker out of your account.
  • Slow down. Urgency is the scammer's tool. A real request will survive a ten-minute pause.

For an extra layer, a tool like Scam Guard can help screen suspicious content before it reaches your attention.

Illustration of one targeted envelope with a magnifier
Spear phishing builds the message around you, so the red flags are buried.

How to report phishing

Reporting a phishing attempt takes about a minute and can protect other people from the same campaign.

  1. Forward suspicious emails to your email provider's abuse team, or to the Federal Trade Commission at reportfraud.ftc.gov.
  2. If you fell for the message, change your passwords right away and enable two-factor authentication.
  3. If money was lost, file a complaint with the FBI's Internet Crime Complaint Center (IC3), which tracks these cases.

You can find the full walkthrough in our guide on how to report phishing. Keep every part of the message, including headers and links, so investigators can act on the details.

FAQ

What is the main difference between phishing and spear phishing? Phishing sends one generic message to millions of people, while spear phishing is a personalized message aimed at a specific person using details gathered from data breaches and social media.

How do attackers get the personal details used in spear phishing? They combine information from data breaches, public social media profiles, and company directories, then stitch those pieces into a believable message.

Why is business email compromise so effective? It impersonates someone with authority, like a CEO or a vendor, and pairs that trust with an urgent request for payment or gift cards, leaving little time to think.

What should I do first if I reply to a phishing email? Change your password immediately, turn on two-factor authentication, and report the message so the same trick does not work on someone else.

Sources and further reading

---

Written by Hassan Arshad, founder of UsefulOrbit. Last updated August 31, 2026.

Keep reading