---
title: "Phishing vs. Spear Phishing"
id: "30945"
type: "glossary"
slug: "phishing-vs-spear-phishing"
published_at: "2026-05-29T05:51:25+00:00"
modified_at: "2026-05-29T13:14:39+00:00"
url: "https://www.kitecyber.com/glossary/phishing-vs-spear-phishing/"
markdown_url: "https://www.kitecyber.com/glossary/phishing-vs-spear-phishing.md"
excerpt: "Phishing vs. Spear Phishing Home / Glossary Index / Alphabet F Phishing vs. Spear Phishing: 5 Critical Differences That Determine How You […]"
---

# [Phishing](https://www.kitecyber.com/glossary/phishing-2/) vs. Spear Phishing

[Home](https://www.kitecyber.com/)
 / [Glossary Index](https://www.kitecyber.com/glossary/endpoint-security-terms/)
 / Alphabet F

## Phishing vs. Spear Phishing: 5 Critical Differences That Determine How You Defend Against Them

**Definition:** [Phishing](https://www.kitecyber.com/glossary/phishing-2/)
 is a cyberattack technique that uses fraudulent emails, messages, or websites to trick users into disclosing credentials, clicking malicious links, or downloading [malware](https://www.kitecyber.com/glossary/malware/)
. Spear [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 is a targeted variant that personalizes the attack using specific information about the recipient, such as their name, role, organization, recent activities, or relationships, to make the deception significantly more convincing.

[Phishing](https://www.kitecyber.com/glossary/phishing-2/)
 casts a wide net. Spear [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 is a sniper shot. Both are dangerous, but they require different defenses.

### Understanding Phishing

A standard [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 attack is a volume play. Attackers send thousands or millions of nearly identical messages, hoping a small percentage of recipients will take the bait. The messages often impersonate trusted brands: banks, courier companies, software vendors, government agencies, or popular online services.

Common [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 scenarios include fake package delivery notifications with malicious links, fraudulent bank security alerts asking you to “verify your account,” fake password reset requests, and invoice or payment confirmation emails with malicious attachments.

[Phishing](https://www.kitecyber.com/glossary/phishing-2/)
 succeeds through urgency and mimicry. The message creates pressure (your account will be suspended, your package is on hold, your payment failed) and mimics the visual style of a trusted sender well enough to fool users who are not looking closely.

**Common [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 delivery channels:**

- Email (the dominant channel)
- SMS (smishing)
- Voice calls (vishing)
- Social media messages
- Instant messaging platforms

### Understanding Spear Phishing

Spear [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 starts with research. Before writing a single word of the attack message, the attacker collects information about the target: their name, job title, employer, colleagues’ names, recent projects, vendor relationships, travel schedule, or anything else available through LinkedIn, corporate websites, social media, or previously breached data.

This information gets woven into a message that feels legitimate, contextually accurate, and personally relevant. Instead of a generic “Dear Customer” message, the target receives an email that uses their full name, references their manager by name, mentions a current project, and asks them to review a document that appears to come from a known colleague.

The 2020 Twitter hack that compromised accounts of high-profile figures including Barack Obama and Elon Musk began with spear [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 attacks targeting Twitter employees. The attackers obtained employee credentials through a phone-based spear [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 campaign and used them to access internal administrative tools. That single campaign exposed the accounts of over 130 high-profile users.

[Phishing vs. Spear Phishing](https://www.kitecyber.com/glossary/phishing-vs-spear-phishing/)
: Key Differences

| Factor | Phishing | Spear Phishing |
| --- | --- | --- |
| Target scope | Mass audience, undifferentiated | Specific individuals or small groups |
| Personalization | Generic or minimal | Highly personalized using researched details |
| Effort required | Low (automated, templated) | High (research-intensive, custom-crafted) |
| Detection difficulty | Easier (patterns easier to identify) | Harder (context-specific, harder to flag) |
| Success rate | Low per target | Much higher per target |
| Common targets | General consumers, employees broadly | Executives, finance staff, IT administrators |
| Associated attacks | Credential harvesting, malware delivery | BEC, wire fraud, corporate espionage |

### Whaling: Spear Phishing for C-Suite Targets

Whaling is spear [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 specifically aimed at senior executives: CEOs, CFOs, board members, and other high-value targets. Because executives have broad system access and financial authority, they are high-value targets. A CFO receiving a convincing email purportedly from the CEO requesting a wire transfer to a new vendor is a classic whaling attack scenario.

Business Email Compromise (BEC), a category of fraud that cost businesses over $2.9 billion in 2023 according to the FBI IC3 report, frequently relies on whaling or spear [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 techniques targeting finance personnel and executives.

How to Defend Against Both

- **For phishing (broad defense):** Email security gateways filter known phishing domains, malicious links, and malware-laden attachments. DMARC, DKIM, and SPF email authentication protocols prevent attackers from spoofing your domain. Security awareness training teaches users to recognize phishing indicators. Multi-factor authentication (MFA) limits the damage even when credentials are stolen.
- **For spear phishing (targeted defense):** The same controls apply, but they need reinforcement at the human layer because technical controls struggle with contextually accurate, personalized messages. Advanced email security tools that analyze behavioral anomalies (unusual sender patterns, out-of-character requests, unusual attachments) catch what signature-based filters miss. Verification protocols for financial transactions, where any wire transfer or sensitive action above a threshold requires phone confirmation, stop BEC attacks even when the initial email gets through.
- **Simulated phishing campaigns** help organizations measure how many employees click on phishing emails and provide targeted training for those who do.

## Frequently Asked Questions About Phishing vs. Spear Phishing

[How can I tell if an email is a spear phishing attempt?](#collapse-63098cb6a88d2f14d8d2)

Spear [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 emails are designed to appear legitimate, which is what makes them dangerous. Look for subtle inconsistencies: the sender's email domain does not exactly match the expected domain, the request is unusual even if the context sounds familiar, there is an unexpected urgency or confidentiality request. When in doubt, verify requests through a separate, known communication channel before taking action.

[Does MFA protect against phishing?](#collapse-96023976a88d2f14d8d2)

MFA significantly reduces the risk of credential theft through [phishing](https://www.kitecyber.com/glossary/phishing-2/)
. Even if an attacker captures a username and password, they still need the second factor. However, advanced [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 techniques including adversary-in-the-middle (AiTM) attacks can bypass some MFA implementations by intercepting session cookies. Phishing-resistant MFA using hardware security keys (FIDO2/WebAuthn) provides stronger protection.

[What is the difference between phishing and social engineering?](#collapse-573c5b46a88d2f14d8d2)

[Phishing](https://www.kitecyber.com/glossary/phishing-2/)
 is a specific technique within the broader category of social engineering, which covers any attack that manipulates people into taking actions that benefit the attacker. Social engineering includes [phishing](https://www.kitecyber.com/glossary/phishing-2/)
, pretexting (creating a fabricated scenario), baiting (offering something enticing to get a user to take action), and physical manipulation. Spear [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 combines [phishing](https://www.kitecyber.com/glossary/phishing-2/)
 with pretexting.

[Request a Demo](https://www.kitecyber.com/request-a-demo/)
