Overview
Spear phishing tailors the lure using public information: a real invoice, an actual colleague's signature, a project name from a job advert.\nThe goal is usually privilege: the finance officer who can wire funds, or the administrator who can grant mailbox access.\nBecause the message is individually crafted, generic filter rules rarely catch it.
Indicators of Compromise
Signals that suggest this is present on a system.
- Mail referencing internal projects or real conversations
- Replies-to domain differing from the display name
- Urgent payment or document-share requests
Controls that stop it
-
Enforce Multi-Factor Authentication
Require a second factor on every login, and make it phishing-resistant where you can: passkeys, FIDO2 security keys or certificate-based authentication. Push-based MFA is meaningfully better than no second factor, but it is still vulnerable to fatigue and real-time relay attacks. Apply it first to remote access, email and administrative accounts.