
Spear Phishing
Spear phishing is phishing aimed at a specific person, company or industry rather than sent at random. MITRE ATT&CK has no technique by that name: it has a parent called Phishing whose every sub-technique is a spearphishing variant, plus a separate one filed under lateral movement.
Every explanation in the captured results works the same way. It tells you what ordinary phishing is, then tells you this one is targeted, and stops. The definition is a contrast, and the contrast never comes with a line.
That leaves the question a working definition has to answer: how targeted does a message have to be? Two hundred recipients? Twenty? One name in a greeting? Nothing on the first page of either major search engine says.
There is a second thing to notice before we start. Google's own answer for this term will define it, offer to write you an example message, and walk you through the red flags, all without you leaving the results page. The definitional ground is gone, and so is the example ground. So this page does what that answer cannot: quotes the framework's actual definition, names two objects no captured page mentions, and reads the AI study those results cite at the paper rather than at the summary.

Explain it like I'm 10
Ordinary phishing is a net. The same message goes to a million people, and it does not matter that most of them ignore it, because a few will not.
Spear phishing is one message written for one person. Before sending it, the attacker finds out something true about them: who they work with, what project they are on, which supplier they use. Then the message refers to that true thing, and everything else follows from it.
The reason this works is not that the target was careless. It is that the message was plausible, and plausible is exactly what a message is supposed to be.
Spear Phishing Quiz
Test your knowledge about Spear Phishing - maybe you already know everything about it.
What is spear phishing aimed at, rather than sent at random?

There is no technique called spear phishing
Open MITRE ATT&CK and search for spear phishing. You will not find a technique with that name.
What you find is T1566, Phishing: tactic Initial Access, version 2.7, last modified 12 May 2026, with platforms listed as Identity Provider, Linux, Office Suite, SaaS, Windows and macOS. Under it sit exactly four sub-techniques.
ID | Name | What arrives | Tactic |
|---|---|---|---|
T1566.001 | Spearphishing Attachment | An email with a malicious file | Initial Access |
T1566.002 | Spearphishing Link | An email with a malicious link | Initial Access |
T1566.003 | Spearphishing via Service | A message on a third-party service | Initial Access |
T1566.004 | Spearphishing Voice | A phone call | Initial Access |
Read the second column again. All four children are spearphishing variants. There is no sub-technique for the untargeted case at all.
State that carefully, because it is easy to overclaim. ATT&CK can absolutely describe mass phishing: that is the parent technique, and its description says so. What the framework does not have is a child for it. The general case lives at the top of the tree and every branch below it is the targeted one.
Which inverts how the subject is usually taught. In the training-module version, phishing is the main event and spear phishing is the special case at the end. In the framework, the targeted case is the only case with vocabulary of its own.
The threshold, and the word the captured pages skip
Here is the definition itself, from the parent technique's own description: "Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns."
Industry. Every page in the captured results teaches this term as one person or a small group. The framework's own threshold includes an entire sector. A campaign aimed at every hospital in a country, or every regional credit union, is spearphishing by this definition and would be described as mass phishing in most ordinary usage.
And then the gap, which is the reader's actual question and has no answer: the framework supplies a definition and no threshold. No recipient count, no personalisation test, nothing measurable. The line is a judgement call, and no source located for this article publishes a rule for making it.
The parent's description also names three things the field usually treats as separate topics. Thread hijacking is one: adversaries may include "the intended target as a party to an existing email thread that includes malicious files or links". Email spoofing is another, and the framework notes it "can be used to fool both the human recipient as well as automated security tools". The third is the use of email hiding rules on a compromised mailbox, so the account's real owner never sees the replies.
One small thing while we are here. ATT&CK writes it as a single word, spearphishing, in every technique name it has. Almost nobody else does.
The lure sometimes contains its own bypass instructions
One detail from T1566.001, Spearphishing Attachment, version 2.2, is a useful thing to know and appears on no captured page. The framework records that the email "usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so", and that it "may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses."
That second one is a detection tell as much as an attacker technique. A message that arrives with a password for its own attachment has, by design, made the file unreadable to the scanner that was supposed to inspect it, and it has told the recipient how to finish the job.
There is a second family, for a different purpose
Alongside the phishing family sits T1598, Phishing for Information, tactic Reconnaissance, with four sub-techniques of its own and the same threshold sentence in its description. It exists because some phishing is not trying to run code on anything. It is collecting information for later.
A small inconsistency between the two families is visible if you read the lists side by side: T1566's third child is called Spearphishing via Service, and T1598's first is called Spearphishing Service. Same idea, two names, in one framework.

The variant that arrives somewhere else entirely
The single most repeated instruction across the captured results is to check the sender's email address. Hold that thought against T1566.003, Spearphishing via Service, version 2.0, last modified 24 October 2025.
It is defined by what it avoids: it "employs the use of third party services rather than directly via enterprise email channels", because those services "are more likely to have a less-strict security policy than an enterprise."
The procedure examples are where this gets concrete. There are sixteen of them, and two patterns run through the list.
The dominant lure is a job offer. Contagious Interview, FIN6, Lazarus Group, Moonstone Sleet and the campaign MITRE tracks as Operation Dream Job all used fake job advertisements or recruitment messages, mostly on LinkedIn. The dominant channels are LinkedIn, WhatsApp, Facebook, Telegram and Microsoft Teams, with Dark Caracal recorded as having "spearphished victims via Facebook and Whatsapp" and Storm-1811 using Teams.
And two of them arrive through a service that is entirely genuine. APT29 "has used the legitimate mailing service Constant Contact to send phishing e-mails". EXOTIC LILY "has used the e-mail notification features of legitimate file sharing services". In both cases the sending domain is real, the service is real, and the message passes every authenticity check because it is authentic. Only the content is not.
The sentence that changes the unit of analysis
The description contains one passage that no vendor page in the capture carries, and it is the most useful thing in this article:
"A common example is to build rapport with a target via social media, then send content to a personal webmail service that the target uses on their work computer. This allows an adversary to bypass some email restrictions on the work account, and the target is more likely to open the file since it's something they were expecting. If the payload doesn't work as expected, the adversary can continue normal communications and troubleshoot with the target on how to get it working."
Read that last clause again. The attacker stays in the conversation and helps the victim get the malware running.
This is not a message. It is a relationship. Advice built around inspecting an email has no purchase on an exchange that has been running for a fortnight, in an app the security team does not administer, about a job the target actually wants. The two mitigations MITRE lists here are antivirus and auditing "interactions with third-party messaging services or collaboration platforms", and both presume visibility into a service the organisation does not own.

The spear phishing that is not initial access
Here is the object the field omits entirely. T1534, Internal Spearphishing has no sub-techniques, version 1.4, created 4 September 2019, last modified 12 May 2026, with Microsoft's threat intelligence centre among its contributors.
Its tactic is Lateral Movement.
The description explains why. "After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization." A legitimate account is compromised first. Then the attacker uses it, "to take advantage of the trusted internal account to increase the likelihood of tricking more victims", including through "internal chat apps, such as Microsoft Teams".
Apply the standard advice to that. Check the sender's address: it is your colleague's address. Check the domain: it is your domain. Check whether the display name matches the real address: it does. Every test the field teaches returns a clean result, because nothing about the sender is fake. The account is genuine and the person operating it is not.
Eight entries, and two of them aimed at the security function
Eight entries are recorded under this technique: six named groups, one campaign and one piece of malware. Two stand out for who they aimed at: HEXANE "has conducted internal spearphishing attacks against executives, HR, and IT personnel", and APT-C-36 "used a compromised account to send a phishing email to an address likely used and monitored by the IT team within the same targeted organization". The function that investigates the phishing report is itself a target. Gamaredon Group is recorded using an Outlook module on infected systems to send the messages, and a piece of malware called SameCoin simply mails itself onward to other addresses inside the same organisation.
What the framework offers against it
The mitigations section for this technique is one sentence long, and here it is in full:
"This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features."
That is the whole preventive answer. Everything else moves to detection, and there the framework is more specific than usual. Detection strategy DET0054 carries five analytics, and the first describes the shape of the thing: a "sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting", observed as "internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts".
The detectable unit is the sequence, not the message. An abnormal logon, then internal mail, then a click and a credential prompt. A further analytic covers the same pattern in SaaS applications and names Slack, Teams and Gmail; others cover Outlook, Apple Mail, Thunderbird and Evolution. None of them asks anyone to look at an email and feel suspicious.

What the AI study actually found
The claim in circulation is easy to state. Google's AI Overview for AI spear phishing reports attackers "achieving click-through rates over 50%", cited to a security vendor and a summary post, and presents it as what artificial intelligence has done to this attack.
The underlying work is a paper on arXiv by Fred Heiding, Simon Lermen, Andrew Kao, Bruce Schneier and Arun Vishwanath, submitted 30 November 2024, titled Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects. It is a preprint, which is worth saying plainly.
Its design matters more than its headline. The study ran four groups with 101 participants in total, which is roughly twenty-five people per arm. Against that sample: a control group of arbitrary phishing emails clicked at 12%; emails written by human experts clicked at 54%; fully AI-automated emails clicked at 54%; and AI emails with a human in the loop clicked at 56%.
The AI did not beat the experts. It tied with them.
That is the finding, and it is not the story being told. The authors' own summary is that "the AI-automated attacks performed on par with human experts and 350% better than the control group."
So the comparison that matters is not AI against ordinary phishing. It is AI against a skilled human operator, and there the result is a draw. What changed is the other variable the authors measured: the campaigns "increase profitability by up to 50 times for larger audiences."
The quality of the message did not move. The price of producing it did. That is a different threat model and a more useful one. Expert-grade targeting used to be rationed by how many hours a skilled operator had. If it now costs what a bulk campaign costs, the change is in who can afford to aim at you, not in what arrives when they do. An organisation that assumed it was too small to be worth a person's afternoon is the one whose assumptions have changed.
Two further AI figures appear in the same set of search results and this article declines to repeat either: a claim that preparation time fell from sixteen hours to under five minutes, and a claim that AI scams grew by 1,210% in a year. Neither carries a published method, dataset or baseline. They are named here as a gap, not as evidence.

What a national cyber security centre says about the advice
Every captured page ends in a list of things to look for. The UK's National Cyber Security Centre publishes guidance on the same subject that is organised completely differently, and it appears nowhere in either engine's organic results.
Its guidance, published 5 February 2018 and reviewed 13 February 2024, sets out four layers of defence:
- Make it difficult for attackers to reach your users
- Help users identify and report suspected phishing emails
- Protect your organisation from the effects of undetected phishing emails
- Respond quickly to incidents
Note where the red-flags list sits. User identification is layer two of four, and layer three exists because layers one and two are expected to fail. The entire structure is built around messages that get through.
The guidance is unusually direct about why. "No training package, including phishing simulations, can teach users to spot every phishing attempt." On this article's own subject specifically: "Spotting all phishing emails is hard, and spear phishing attacks are even harder to detect." And a practical objection no other captured page raises: "Asking users to examine, in depth, every email they receive will not leave enough hours in the day for work tasks."
That last one prices the advice. Scrutinising every message is not free, and the cost is paid in the working day.
If you are reading this because you clicked something
Then one more sentence from the same guidance belongs here, and it is theirs rather than ours: "Blaming users for clicking on links doesn't work." The guidance adds that "threatening someone with punishment doesn't change these factors."
This is a national cyber security centre, in published guidance, and it is not a reassurance this page invented for the occasion.
To be precise about what the NCSC is and is not saying: it is not saying training is useless. Layer two exists, and reporting is half of what it is for. It is saying training cannot be the boundary, which is a different claim and a much better supported one.

Where the boundary actually is
Put the two framework objects together and the standard instruction has three documented shapes it cannot handle.
- A message on a platform with no corporate address to inspect, which is T1566.003.
- A message from a genuine service, correctly signed and correctly sent, as in the Constant Contact and file-sharing cases.
- A message from a real colleague's real account, which is T1534, and which the framework says preventive controls cannot easily stop.
Which turns into a coverage question, and it is the one to leave with, so here it is: do your organisation's phishing controls extend past the corporate mail gateway? To the collaboration platform. To internal mail moving between colleagues. To the sequence detection that internal spearphishing actually requires, where the signal is an abnormal logon followed by internal mail followed by a click. MITRE names the platforms in its own analytics. The question is whether anybody is watching them.
Two boundaries in one line each, because they belong to their own pages rather than this one: whaling and business email compromise are targeted variants distinguished by who is impersonated and what is asked for, and the voice, text and QR-code channels each get their own entry in this glossary.

What this page cannot tell you
No dataset located measures spear phishing separately from phishing. The large incident-response datasets this site has read report a single phishing or email-phishing vector. The category is taught as a distinct thing and, so far as this research could establish, never separately counted.
No threshold exists. ATT&CK gives a definition and no test. If you need to classify an incident as targeted or not, you are making a judgement, and nothing located will make it for you.
The AI study is a preprint with 101 participants across four arms. It is the best evidence available on the question and it is one study of about twenty-five people per group. It should not be generalised into a claim about the world.
And two circulating AI figures were refused, because no method, dataset or baseline was published for either.

The short version
Spear phishing is phishing aimed at a specific individual, company or industry, which is the framework's own wording and is broader than the definition in general use. ATT&CK has no technique by that name: it has a parent called Phishing, four sub-techniques that are all spearphishing variants, and no child at all for the untargeted case.
Two of those shapes defeat the advice everyone gives. T1566.003 arrives on a service where there is no corporate address to check, sometimes through a genuine provider. T1534 arrives from a real colleague's real account, and MITRE says preventive controls cannot easily stop it.
The AI study everyone quotes found a tie with human experts, not a win, on 101 participants. What changed is cost, which changes who can afford to target you.
The one thing to do after reading this: find out whether your phishing controls stop at the mail gateway. If they do, two of the three documented shapes above are arriving somewhere nobody is looking.