home/glossary/Spear phishing

Spear phishing

nounverified·updated May 9, 2026

An attack targeting a specific user or group of users, and attempts to deceive the user into performing an action that launches an attack, such as opening a document or clicking a link. Spear phishers rely on knowing some personal piece of information about their target, such as an event, interest, travel plans, or current issues. Sometimes this information is gathered by hacking into the targeted network.

MWEFederal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary

Senses

ISACA Cybersecurity Glossary

An attack where social engineering techniques are used to masquerade as a trusted party to obtain important information such as passwords from the victim

Classifications

Entity Type

Threat90%rule-basedr:entity.threat.attack.v1
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
Spear phishings
possessive
Spear phishing's
pluralpossessive
Spear phishings'