What separates it from bulk phishing
Bulk phishing is a numbers game: one template, an enormous list, and a conversion rate low enough that it only works because sending costs nothing. Spear phishing inverts that. One target, one message, and hours of preparation - justified because the payoff from a single success is far larger.
The practical consequence is that the tells people are trained to look for are absent. There is no generic greeting, because the attacker knows the name. There is no implausible pretext, because they know what project the target is working on. The message arrives in a real thread, at a plausible moment, referring to a real supplier.
Where the research comes from
Almost all of it is public and legally obtained. No intrusion is required to write a convincing spear-phishing message.
- The company website: names, roles, and the email format the whole organisation follows.
- LinkedIn and similar: who reports to whom, who just joined and does not yet know the norms, who is on holiday.
- Public filings, tender records and press releases: real supplier relationships and real amounts.
- Previous data breaches: which of the target's passwords have leaked, and which services they use.
- Out-of-office replies, which helpfully name a deputy and a date range.
- A previously compromised mailbox belonging to a supplier - the strongest starting point of all, because the attacker can simply reply to a genuine existing thread.
That last route is what makes vendor compromise so effective: the sender is genuine, the domain is genuine, the thread history is genuine, and every sender-authentication check passes cleanly. Where the target is an executive the same technique is called whaling, and where the goal is redirecting a payment it becomes business email compromise.
What holds against it
- Process, not vigilance, for anything involving money. A verification callback to a number already on file, mandatory regardless of who appears to be asking, removes the need for anyone to judge a message correctly.
- Two-person approval above a threshold, so no single compromised account can complete a payment.
- Phishing-resistant sign-in for the people most worth targeting - executives, finance, IT administrators - since these accounts convert directly into loss.
- External-sender tagging, which is one of the few controls that still fires on an otherwise flawless message.
- Detection of new mailbox rules and forwarding, since a compromised account is usually the launch point for the next spear-phishing message rather than the goal itself.
- Reduce the public detail where it costs nothing - though accept that most of the research surface is unavoidable for any company that wants to be found.
For where this sits among the other variants see types of phishing, and for the underlying definition what is phishing.