A personalized form of phishing aimed at a specific person or organization after reconnaissance, and the main gateway for attacks.
Spear phishing is a sophisticated variant of classic phishing. Where mass phishing sends the same fraudulent message to a very large number of recipients in the hope that a few will bite, spear phishing addresses a specific person or organization, after reconnaissance work that allows the message to be personalized, citing real names, ongoing projects or professional relationships, in order to make it credible. Its variant aimed specifically at executives is sometimes called whaling. This personalization makes it a formidably effective weapon, and spear phishing ranks year after year among attackers' leading vectors of initial access, whether used to steal credentials, install malware or initiate a transfer fraud. For insurance, it sits at the crossroads of several covers, because it can lead just as easily to ransomware as to financial fraud. The best defenses combine continuous staff awareness, since employees remain the targeted link, multi-factor authentication, which limits the exploitation of stolen credentials, and technical filtering of messages.
An attacker studies the public profile of a chief financial officer, then sends her an email imitating a lawyer involved in a real acquisition by the company. The precision of the details disarms suspicion and opens the way to a transfer fraud.
spear phishing, hameçonnage ciblé, harponnage, whaling