Spear phishing is personalized phishing aimed at a specific person or role. The attacker uses credible details about a project, supplier, executive or schedule to obtain access, money or code execution.
BEC complaints in 2025
The FBI received 24,768 Business Email Compromise complaints, with more than $3.0 billion in reported losses. This measures reports received, not every attack that occurred.
FBI — 2025 Internet Crime ReportWhy spear phishing feels legitimate
Unlike mass phishing, the message builds on a real or plausible relationship. Names, travel plans or projects may be accurate. The trap sits in the instruction: new bank details, a document in another tenant, an MFA approval or a move to a private channel.
Do not hunt only for spelling mistakes. Look for a break in process. Would a legitimate request normally eliminate dual approval, change domains or demand secrecy?
Qualify the scenario before containment
Determine whether the sender is spoofed, compromised or merely similar. Search for other recipients, forwarding rules, unusual sessions and new OAuth grants. This avoids treating a compromised supplier mailbox as a simple domain-blocking problem.
- Preserve headers and URLs
- Hunt for related messages
- Review sessions, MFA and OAuth grants
- Confirm payment changes outside email

Contain according to the action taken
With no interaction, remove copies and block validated indicators. After a click, inspect network and download activity. After credential entry, revoke sessions, reset secrets and review MFA methods. After execution, isolate the host and start endpoint investigation.
A payment or bank-detail change also activates the fraud response immediately. Finance, banking partners and legal stakeholders should not wait for technical analysis to finish.
Reduce repeat exposure
Combine phishing-resistant authentication, email protection, restricted OAuth consent and out-of-band business controls. Exercises should reproduce realistic workflows and measure reporting speed and escalation quality, not only click rates.
Operational decision matrix
| Stage | Question to resolve | Expected outcome |
|---|---|---|
| Pretext | Spot real details used to manufacture trust. | List possible sources |
| Break in process | Identify a changed procedure or channel. | Pause the sensitive action |
| Scope | Search sessions, rules, OAuth and other recipients. | Classify account or domain |
Field note
The strongest indicator is often not a typo but an instruction that bypasses a normal business control.
The right control level depends on context, exposed assets and business impact: document assumptions, measure the outcome and reassess after every material change.
Turn uncertainty into a structured investigation
The Phish Analyzer brings suspicious-email triage, indicator extraction and the investigation pivots a security analyst or SOC team needs into one workbench.
- Import and parse RFC822 or EML messages: headers, authentication, URLs, domains, addresses and attachments.
- Investigate URLs, domains and files with configurable OSINT enrichment and reputation signals.
- Open links in an isolated remote browser, preserving screenshots and traces as case evidence.
Watch the full demonstrationFrequently asked questions
What is the difference between phishing and spear phishing?
Phishing targets broadly; spear phishing customizes the scenario for a person, team or organization.
Does MFA stop spear phishing?
Not by itself. Session theft and approval manipulation remain possible. Phishing-resistant methods and session monitoring provide stronger protection.
What should investigators collect first?
Preserve the original message with full headers and document every action the user performed.
Official sources
Achraf Hachimi
CISSP-certified Senior SOC / CSIRT Engineer specializing in Incident Response, Threat Hunting and Detection Engineering. Eight years of experience in critical environments with Splunk ES, Microsoft Defender XDR, SentinelOne and Cybereason.
