Skip to content

Spear Phishing & Whaling

Spear phishing uses tailored context to target a specific person, team, role, organisation, project, or business process. Whaling applies the same targeted approach to senior executives, leaders, and other high-profile decision-makers whose authority, access, influence, or delegated support relationships increase the potential impact of a successful interaction.

Accurate details can make the message appear relevant before the request has been independently assessed. Project information, supplier relationships, role data, public activity, and other collected context may be used to align the interaction with an expected business concern.

Timing strengthens the effect. Contact may coincide with a deadline, travel, organisational change, or another period in which related communication is already expected, so authority and urgency around the requested action land against a plausible backdrop rather than in isolation.

Delivery is not limited to email. Messaging platforms, collaboration tools, social media, document-sharing services, calendar invitations, and follow-up calls can carry or reinforce the same targeted approach.

Spear phishing and whaling commonly present as business communication tied to an identifiable person, workflow, or current activity. The interaction may concern an approval, document, account, supplier, legal matter, or other process where the target’s role creates a plausible reason for contact.

The message usually combines collected context with a requested action. Tailoring aligns the sender identity, timing, language, and delivery path with the target’s responsibilities or the organisation’s current activity, so the request reads as a natural extension of work already under way. What separates this from bulk phishing is the targeting itself: who was chosen, the real context used to reach them, and the moment picked to make contact.

ElementWhat it meansExamples
Target selectionThe authority, access, information, or influence that makes a person or role worth the effort of tailoring.Executive, assistant, finance officer, HR staff, project lead, system owner, procurement contact.
Personalised contextThe real or believable detail used to align the message with the target’s environment.Project name, supplier, event, colleague, public post, travel, invoice, meeting, job role.
Timing advantageThe current condition that makes the request appear plausible or time-sensitive.Deadline, travel, event, procurement phase, public announcement, incident, end-of-month processing.

Targeted messages may contain accurate information and familiar business detail. Indicators commonly arise where that context is paired with an anomalous request, communication path, or departure from established process.

IndicatorWhat to look for
Real detail, unusual requestA genuine project, supplier, colleague, event, or role is referenced alongside an action that does not match normal process.
Urgency or confidentialityDeadlines, executive pressure, legal sensitivity, secrecy, travel, customer impact, or operational disruption are used to discourage verification.
Sender or domain mismatchThe sender address, reply-to address, display name, domain, signature, or linked destination differs from the expected person or organisation.
Unusual attachment or linkAn unexpected document, shared file, login prompt, calendar invitation, form, or destination is introduced into the interaction.
Approval bypassThe request seeks to skip, rush, or override established approval, finance, procurement, access, legal, or security processes.
Channel shiftThe sender moves the conversation to a new email address, personal account, messaging application, phone number, file-sharing service, or external portal.
Credential or MFA promptA login page or direct request seeks passwords, MFA codes, recovery details, session approval, or account verification.
Tone or timing mismatchWording, urgency, timing, formatting, greeting, or decision style differs from the established pattern for the claimed sender.
Tailored but context-lightSpecific details appear without the conversation history, documentation, ticket, approval trail, or business context normally associated with the request.