Where classic phishing campaigns cast a wide net, a spear phishing attack targets high-value accounts. The value of a target may be due to their individual value, or to the role or function they play in an organization. For example, the IT admins of an organization will usually have the highest level permissions to access any organizational assets, therefore the IT department may specifically be targeted. Employees in the finance or HR departments are also common individual targets.
Malicious actors will often expend considerable time and resources in preparing these high-value spear phishing campaigns. They utilize a variety of intelligence-gathering techniques, often relying heavily on social media, to create a compelling social engineering attack custom-fit to the target. For this reason, Microsoft’s 2020 DDR reports that 44% of the successful breaches they responded to utilized spear phishing as the initial attack vector.