TroutTrout
Back to Glossary
Spear phishingTargeted phishingPhishing attack

Spear Phishing

4 min read

Spear phishing is a targeted phishing attack aimed at a specific person or organization. Instead of blasting a generic lure to thousands of inboxes, the attacker researches the target and crafts a message that fits their role, their vendors, and their language, so it reads as legitimate. The goal is to steal credentials or get the victim to open a payload that gives the attacker a foothold.

What is spear phishing?

It is phishing with homework done. A commodity phishing email is written to be plausible to anyone. A spear-phishing email is written to be plausible to you: it may reference a real purchase order, impersonate a named colleague or supplier, or arrive right when you would expect that kind of message. Attackers build that specificity from LinkedIn, company websites, press releases, and past breaches, which is why it is a form of social engineering as much as a technical attack.

A related variant, "whaling," aims the same technique specifically at executives and other high-value targets who can authorize payments or access sensitive systems.

How does a spear-phishing attack work?

The pattern is consistent across incidents:

  1. Reconnaissance. The attacker maps the target's role, relationships, and vendors from public sources.
  2. Pretext. They craft a message that impersonates a trusted party, an invoice from a real supplier, a shared document from a real coworker, an urgent request from a real manager.
  3. The hook. A malicious link harvests credentials on a fake login page, or an attachment carries malware.
  4. Foothold and pivot. With stolen credentials or code execution, the attacker moves from the compromised inbox toward the systems they actually want.

That last step is what makes spear phishing dangerous in industrial settings. The email is rarely the target; it is the door.

Why does spear phishing matter for OT and industrial environments?

Because a single tricked employee can become a path into the plant. The 2015 attack on the Ukrainian power grid started with spear-phishing emails carrying BlackEnergy malware inside Microsoft Office attachments. Once the Sandworm operators had a foothold in the IT network, they moved laterally until they reached the SCADA systems and opened breakers, cutting power to roughly 230,000 people. The intrusion began in an inbox and ended at a circuit breaker.

Industrial organizations are exposed for two reasons. Their OT and IT networks are converging, so an IT foothold can reach OT if nothing stops lateral movement. And plant-floor staff are often less drilled on these tactics than corporate IT users, which makes them the softer target. Awareness training reduces click rates, but no training program gets them to zero, so the network has to assume a phish will eventually succeed.

How do you defend against spear phishing?

Defense works in layers, and the important shift is to stop treating email as the only place to fight:

  • Reduce successful delivery with DMARC, DKIM, SPF, and modern email filtering.
  • Train and test with awareness training and periodic simulated campaigns to keep click rates low.
  • Blunt stolen credentials with multi-factor authentication, so a harvested password alone is not enough.
  • Contain the foothold with zero-trust segmentation, so a compromised IT account cannot pivot into OT. This is the layer that would have mattered most in Ukraine.
  • See the pivot by monitoring east-west traffic and having an incident response plan ready for when detection fires.

How is spear phishing different from regular phishing?

Regular phishing is high-volume and generic: one lure sent widely, low success rate per message, aimed at whoever bites. Spear phishing is low-volume and specific: a tailored lure aimed at a chosen target, with a far higher success rate because it is built to survive scrutiny. Generic phishing plays a numbers game; spear phishing plays a research game, and it is the version that shows up in targeted intrusions against critical infrastructure.

How Access Gate helps

Access Gate assumes a phish will eventually land and limits what a stolen credential can do. Its identity-enforced overlay segments the network so a compromised IT account cannot reach OT systems it was never authorized to touch, remote sessions are proxied and logged, and east-west traffic is watched for the lateral movement that follows a foothold. See OT network visibility.

Related terms