Spear Phishing

Spear Phishing: Definition & Defense

Spear phishing is a targeted form of phishing aimed at a specific person or role, built from research about the target. Where generic phishing casts a wide net with one lure, spear phishing crafts the message around the victim’s employer, colleagues, vendors, or recent activity, which is what makes it dramatically more effective.

How Spear Phishing Works

The attacker gathers detail from public sources, social profiles, breach data, and prior compromises, then impersonates someone the target trusts: a CEO requesting an urgent payment, a vendor sending “updated” bank details, IT support needing a password reset. Generative AI has removed the old tells; Visa’s Spring 2026 threats report describes criminals shifting to AI-enabled social engineering that produces flawless, personalized messages at scale.

Why It Matters for Commerce Brands

For ecommerce businesses the exposure runs through staff: finance teams targeted for payment redirection, support and operations staff targeted for system access, and executives impersonated to authorize exceptions. A single successful spear phish can yield admin access to the store platform, the customer database, or the payment stack, turning one employee’s click into an incident affecting every shopper.

How to Defend Against Spear Phishing

Process defenses beat vigilance: out-of-band verification for payment and credential requests, hard rules that no legitimate request bypasses (“we never change vendor bank details on an email alone”), multi-factor authentication on every internal system, and least-privilege access so one compromised account can’t reach everything.

Frequently Asked Questions

What is the difference between spear phishing and whaling?

Whaling is spear phishing aimed at the biggest targets: executives with signing authority. The technique is identical; the payoff per victim is larger.

How can employees recognize a spear phishing attempt?

Look past the polish to the request: urgency, secrecy, a change to payment or credentials, or a channel switch (“reply only to this address”). Any of those triggers out-of-band verification, no matter how legitimate the message looks.

Related Glossary Categories

Install Wyllo

Select your ecommerce platform to start your free two-week trial.​

See Wyllo in Action

Contact the Wyllo team and we’ll be in touch within one business day to schedule your personalized demo. 

Let's find those
bad actors.

Contact the Wyllo team and we’ll review your system together to identify the bad actors.