How it works
Attackers research the target, including their role, colleagues, recent deals, and vendors, often from LinkedIn and public sources. They then craft a message that fits the victim’s context, such as a fake invoice from a known supplier or a request that appears to come from a manager.
How it relates to brand impersonation
Spear phishing usually pairs with executive impersonation and combosquatting: a believable sender domain plus a plausible identity. Its precision makes it far more effective than mass phishing.
How nebty helps
nebty reduces the raw material for spear phishing by detecting the lookalike domains and fake profiles attackers use to impersonate your brand and executives, and removing them on demand.
Takedown serviceWhat makes it so convincing
Spear phishing trades volume for precision. Instead of a generic blast, the attacker spends time on one target, pulling details from LinkedIn, your website, press coverage, and past breaches to build a message that fits the victim context exactly. It references a real project, a real colleague, or a deal in progress, and it arrives at a plausible moment. That research is what defeats the usual instinct to be suspicious, because nothing about the message feels generic. Awareness training helps but is not enough on its own against a well-made lure. The structural defence is to deny the attacker their raw materials: the lookalike sender domains and fake executive profiles that make the message credible are detectable, and removing them early is more reliable than expecting every employee to spot a tailored message under time pressure.
A concrete example
An attacker spends an afternoon on the public footprint of Solara Finance: LinkedIn shows a project manager celebrating a new partnership, the press release names the partner, and the website lists the team. The project manager then receives an email from the "partner", sent from solara-partnerportal.com, referencing the deal by name and asking her to review a contract in a shared portal. The portal is a credential page. Everything in the message is real except the sender domain, which was registered nine days earlier.
How to spot and stop it
- Read the sender domain character by character before acting on any request that involves money, credentials, or documents. The tailored story survives scrutiny; the domain usually does not.
- Verify unusual requests over a second, known channel, even when the message references real projects and colleagues. Research is cheap for attackers; a callback defeats it.
- Remove the raw material: monitor for the lookalike domains and fake profiles that make spear phishing credible, and take them down before they are used.
Frequently asked questions
What is the difference between phishing and spear phishing?
Phishing goes out in bulk and relies on a few victims out of thousands. Spear phishing targets one person or a small group with a message built from research about them, which makes it far more likely to succeed per attempt.
Why do spam filters miss spear phishing?
Filters learn from volume and known-bad patterns. A spear-phishing mail is sent a handful of times, from a fresh domain with clean reputation, and often carries no malware at all, just a plausible request. There is little for the filter to match.
Related terms
See who is impersonating your brand
The free nebty report scans the web for lookalike domains and fake profiles targeting your brand, with no obligation.
Get your free report