SOC / IDENTITY2026-09-029 min

Spear phishing: recognize a targeted attack and contain it

Spear phishing uses real context about its target. Learn how to recognize it and choose the right containment action.

Direct answer

Spear phishing is personalized phishing aimed at a specific person or role. The attacker uses credible details about a project, supplier, executive or schedule to obtain access, money or code execution.

24,768

BEC complaints in 2025

The FBI received 24,768 Business Email Compromise complaints, with more than $3.0 billion in reported losses. This measures reports received, not every attack that occurred.

FBI — 2025 Internet Crime Report

Why spear phishing feels legitimate

Unlike mass phishing, the message builds on a real or plausible relationship. Names, travel plans or projects may be accurate. The trap sits in the instruction: new bank details, a document in another tenant, an MFA approval or a move to a private channel.

Do not hunt only for spelling mistakes. Look for a break in process. Would a legitimate request normally eliminate dual approval, change domains or demand secrecy?

Qualify the scenario before containment

Determine whether the sender is spoofed, compromised or merely similar. Search for other recipients, forwarding rules, unusual sessions and new OAuth grants. This avoids treating a compromised supplier mailbox as a simple domain-blocking problem.

  • Preserve headers and URLs
  • Hunt for related messages
  • Review sessions, MFA and OAuth grants
  • Confirm payment changes outside email
A credible attack is dismantled by separating true context from the malicious instruction.
Key takeaway:A credible attack is dismantled by separating true context from the malicious instruction.

Contain according to the action taken

With no interaction, remove copies and block validated indicators. After a click, inspect network and download activity. After credential entry, revoke sessions, reset secrets and review MFA methods. After execution, isolate the host and start endpoint investigation.

A payment or bank-detail change also activates the fraud response immediately. Finance, banking partners and legal stakeholders should not wait for technical analysis to finish.

Reduce repeat exposure

Combine phishing-resistant authentication, email protection, restricted OAuth consent and out-of-band business controls. Exercises should reproduce realistic workflows and measure reporting speed and escalation quality, not only click rates.

Operational decision matrix

StageQuestion to resolveExpected outcome
PretextSpot real details used to manufacture trust.List possible sources
Break in processIdentify a changed procedure or channel.Pause the sensitive action
ScopeSearch sessions, rules, OAuth and other recipients.Classify account or domain

Field note

The strongest indicator is often not a typo but an instruction that bypasses a normal business control.

The right control level depends on context, exposed assets and business impact: document assumptions, measure the outcome and reassess after every material change.

Tool built by Achraf Hachimi

Turn uncertainty into a structured investigation

The Phish Analyzer brings suspicious-email triage, indicator extraction and the investigation pivots a security analyst or SOC team needs into one workbench.

  • Import and parse RFC822 or EML messages: headers, authentication, URLs, domains, addresses and attachments.
  • Investigate URLs, domains and files with configurable OSINT enrichment and reputation signals.
  • Open links in an isolated remote browser, preserving screenshots and traces as case evidence.
The Phish Analyzer: Open-Source Phishing Email & URL Analysis Tool DemoWatch the full demonstration

Frequently asked questions

What is the difference between phishing and spear phishing?

Phishing targets broadly; spear phishing customizes the scenario for a person, team or organization.

Does MFA stop spear phishing?

Not by itself. Session theft and approval manipulation remain possible. Phishing-resistant methods and session monitoring provide stronger protection.

What should investigators collect first?

Preserve the original message with full headers and document every action the user performed.

Official sources

Achraf Hachimi

CISSP-certified Senior SOC / CSIRT Engineer specializing in Incident Response, Threat Hunting and Detection Engineering. Eight years of experience in critical environments with Splunk ES, Microsoft Defender XDR, SentinelOne and Cybereason.