Spear Phishing

Spear phishing is a targeted form of phishing in which the attacker researches a specific person and crafts a personalized message built to fool that one individual. Where mass phishing casts generic lures at thousands of inboxes, a spear phishing email names the target, references real colleagues, projects, or recent events, and reads like something a trusted contact would genuinely send.

Business email compromise (BEC) is the costliest variant, with attackers posing as an executive or supplier to push finance staff into wiring funds to fraudulent accounts. The FBI has tracked documented losses in the tens of billions of dollars from this scheme. The uncomfortable truth is that technical filters alone will not stop a well-researched BEC message, because it often carries no malware or bad link at all. Verification procedures for payment changes matter as much as any email gateway.

How is spear phishing tested on the CISSP?

Spear phishing falls under social engineering in Domain 1: Security and Risk Management. Candidates should be able to distinguish targeted attacks from mass campaigns and identify the awareness training and process controls that reduce the risk.