← Blog
For businesses

What Is Spear Phishing? A Business Guide to Targeted Attacks and BEC

Explore an AI summary

Most phishing is a wide net. Spear phishing is a guided missile. Instead of blasting the same generic email to millions, an attacker studies one person, your finance manager, your CEO, a specific employee, and crafts a message designed to fool that individual. It is more work for the attacker, and far more effective, which is why spear phishing sits behind some of the costliest attacks businesses face, including business email compromise.

This guide explains what spear phishing means, how it differs from ordinary phishing, how business email compromise (BEC) attacks work, and what your organization can do to prevent them.


What is spear phishing?

Spear phishing is a targeted phishing attack aimed at a specific person or organization, using details about the target to make the message convincing. Where regular phishing relies on volume, spear phishing relies on relevance: the attacker references your real colleagues, your real vendors, a real project, or a real workflow, so the request feels legitimate.

To put the definition plainly, spear phishing means a phishing attack that has been researched and personalized for one target rather than sent at random. That personalization is the whole point. A message that names your manager and refers to an invoice you are actually expecting is far harder to dismiss than a generic "your account is locked" email.


Keep your business safe from online threats

Haven for Business protects every employee from phishing, fake sites, and browser-based attacks.

Spear phishing vs. phishing

The difference comes down to targeting and effort.

Phishing is high-volume and generic. The same email goes to huge lists, and the attacker wins on numbers, even a tiny response rate pays off. The tells are often visible: odd sender, generic greeting, obvious urgency.

Spear phishing is low-volume and specific. The attacker invests time researching the target through social media, company websites, and past breaches, then writes a message tailored to that person. There may be no link at all, just a plausible request from someone you appear to know. That is what makes it dangerous: the usual warning signs are engineered away.


What is business email compromise (BEC)?

Business email compromise is a spear phishing attack that impersonates a trusted party, an executive, a vendor, a lawyer, to trick an employee into sending money or sensitive data. A BEC attack usually has no malware and often no link. It is pure social engineering: a message that looks like it came from your CFO asking finance to wire a payment, or from a known supplier updating their bank details before an invoice is due.

Because there is nothing technically malicious to detect, many BEC attacks sail past traditional filters. The attack lives entirely in language and trust, which is exactly why spear phishing is the delivery method of choice for it.


How spear phishing and BEC attacks work

Most targeted attacks follow the same three steps.

  1. Research. The attacker builds a profile of the target and the people they trust, using public information about roles, relationships, vendors, and ongoing work.

  2. Impersonation. They pose as someone with authority or familiarity, an executive, a supplier, an IT admin, sometimes from a lookalike domain, sometimes from a genuinely compromised account.

  3. The ask. They make a request that feels routine but benefits the attacker: wire a payment, change bank details, buy gift cards, approve access, or sign in to "review" something. Urgency is added so the target acts before verifying.

Some spear phishing leads to a fake login page that harvests credentials. Some BEC attacks skip the link entirely and just ask for a transfer. Both rely on the same thing: a person deciding to trust a message that only looks legitimate.


Common types of spear phishing and BEC

  • CEO fraud. A message impersonating a senior executive pressures an employee to make an urgent payment or share data.

  • Vendor or invoice fraud. An attacker impersonates a known supplier and requests a change to payment details before an invoice is paid.

  • Credential harvesting. A targeted email leads to a fake login page for Microsoft 365, Google Workspace, or another business system.

  • Account takeover. Once one account is compromised, the attacker sends BEC messages from a real internal address, which makes them even harder to catch.


Why BEC is so costly for businesses

The financial stakes are high and well documented. The FBI's Internet Crime Complaint Center reported $3.05 billion in BEC losses in its 2025 report, and has identified business email compromise as a $55 billion problem globally between 2013 and 2023. The IC3 also notes that the large majority of BEC losses move by wire transfer or ACH, which makes the money fast and often impossible to recover once it is gone.

For a business, a single successful spear phishing or BEC attack can mean a six or seven figure loss, exposed customer data, or a compromised email system that keeps attacking from the inside. This is why it is a leadership issue, not just an IT one.


How to prevent spear phishing and BEC

No single control stops targeted attacks, so defense has to be layered.

  • Verify money and data requests out of band. Any request to move funds or change bank details should be confirmed through a known phone number, never by replying to the email.

  • Harden email authentication. Implement SPF, DKIM, and DMARC to make domain spoofing harder, and flag external senders.

  • Require phishing-resistant MFA. Passkeys and hardware keys protect accounts even when a password is stolen.

  • Train for the specific patterns. Teach staff to expect CEO fraud and vendor-invoice fraud, and to treat urgency as a reason to slow down.

  • Add protection at the browser. When a spear phishing message does lead to a fake login page, a browser-layer check can flag it before an employee enters credentials. You can also verify a suspicious link with a tool like Haven's free link checker before clicking.


How Haven helps

Haven is a browser-security companion that works at the moment of risk, when an employee lands on a page and is about to enter credentials. A large share of spear phishing exists to harvest logins, and detecting fake and impersonated login pages is exactly what Haven does. When a targeted email points an employee to a page mimicking Microsoft 365, Google Workspace, or another trusted service, Haven is designed to recognize it as fraudulent and warn them before they type anything, regardless of how the link arrived or how convincing the page looks.

To be precise about scope, the purest BEC attacks, a plain email asking finance to wire money with no link, are stopped by process and email controls rather than a browser tool, which is why the verification and authentication steps above matter. Where Haven adds a distinct layer is the credential-harvesting side of spear phishing, the fake login page that so many targeted attacks depend on.

For organizations, Haven for Business extends this browser-level protection across every employee, and Haven for MSP lets managed service providers deliver it across their clients. Haven is also free for individual use, so employees can protect their own browsing right away. No tool can promise to stop every attack, and we will not claim that. What Haven offers is coverage at the browser, the layer where a targeted lure turns into a stolen credential.


About Haven

Haven is a browser-security companion that helps people and organizations make safer trust decisions online. It works at the browser level, in the moment between clicking a link and entering your information, to flag suspicious sites, fake login pages, and phishing before you act on them. Rather than relying only on lists of known threats, Haven analyzes the page in front of you, which helps it catch newly created and impersonated pages that other tools can miss. Haven is free for individual use, with Haven for Business and Haven for MSP for teams and providers. Haven is operated by MirrorTab, Inc.


FAQs

What is spear phishing?

Spear phishing is a targeted phishing attack aimed at a specific person or organization, using real details about the target, such as their colleagues, vendors, or projects, to make the message convincing. Unlike mass phishing, which is sent at random, spear phishing is researched and personalized, which makes it much harder to spot.

What does spear phishing mean, in simple terms?

Spear phishing means a phishing attack that has been customized for one target instead of blasted to millions. The attacker studies the person, then writes a message that references things that person would recognize, so the request feels normal and legitimate.

What is the difference between spear phishing and phishing?

Regular phishing is high-volume and generic, the same email sent to huge lists in the hope that a few people respond. Spear phishing is low-volume and specific, tailored to one target using researched details. Spear phishing takes more effort but is far more effective, which is why it drives many of the costliest business attacks.

What is business email compromise (BEC)?

Business email compromise is a spear phishing attack that impersonates a trusted party, such as an executive or a vendor, to trick an employee into sending money or sensitive data. A BEC attack usually has no malware and often no link, which is why it frequently bypasses traditional email filters. The FBI has recorded billions in BEC losses.

How can businesses prevent spear phishing and BEC attacks?

Use layered defenses: verify any money or data request through a known phone number rather than replying to the email, implement SPF, DKIM, and DMARC, require phishing-resistant MFA like passkeys, train employees on CEO and vendor-invoice fraud, and add browser-layer protection that flags fake login pages before credentials are entered.

Does Haven stop business email compromise?

Haven protects the credential-harvesting side of spear phishing. When a targeted email leads to a fake login page, Haven detects the impersonated page and warns the employee before they enter their credentials. Pure BEC attacks that only ask for a wire transfer, with no link, are addressed by process and email controls, which is why Haven is one layer in a broader defense.

Is Haven free?

Haven is free for individual use. Haven for Business and Haven for MSP extend browser-level protection to teams and managed service providers. Haven is operated by MirrorTab, Inc.