Spearphishing
Spearphishing is a targeted form of phishing in which an attacker crafts a personalized, convincing message aimed at a specific individual or organization rather than sending generic messages to many people at once. The goal is usually to trick the recipient into revealing sensitive information or into taking an action that installs malware on their device. Because these messages are tailored to the target, they can be harder to recognize as fraudulent than mass phishing attempts.
Spearphishing is a social-engineering attack method in which an adversary directs a highly personalized fraudulent communication, commonly email, at specific individuals within a targeted organization to elicit a particular response. Typical objectives include harvesting sensitive credentials or data and delivering malware to the victim's device or endpoint. It is distinguished from broad, untargeted phishing by its use of tailored content designed to increase credibility against a chosen target. As an attack technique, spearphishing is a security threat concept and not itself an insurance coverage term; whether losses arising from a spearphishing incident (for example, fraudulently induced transfers, data restoration, or resulting liability) are covered depends on the specific policy wording, applicable endorsements, exclusions, and conditions.
Why it matters
Spearphishing matters because it is one of the most common initial-access techniques behind cyber incidents that later trigger insurance claims and resilience responses. Because the message is tailored to a specific person or organization, it can defeat the pattern-based instincts that help people spot generic mass phishing. A single successful spearphishing message can lead to credential theft, malware installation, fraudulently induced fund transfers, or a broader network compromise, each of which may cascade into business interruption, data restoration costs, and third-party liability.
For insurance purposes, the critical point is that spearphishing is an attack method, not a coverage grant. The fact that a loss began with a spearphishing email does not by itself determine whether that loss is covered. Depending on the specific policy wording, endorsements, exclusions, and conditions, the resulting losses might be addressed under different insuring agreements, for example first-party coverage for the insured's own data restoration or extortion costs, social-engineering or fraudulent-transfer coverage for induced payments, or third-party coverage for privacy liability arising from compromised data. Whether any given loss falls within coverage is subject to the precise wording and the facts of the incident.
Spearphishing also illustrates the limits of risk transfer. Buying insurance does not reduce the likelihood that an employee will receive and act on a convincing targeted message; it only transfers some portion of the financial consequences, subject to policy terms. Reducing the likelihood and impact of spearphishing requires mitigation measures such as security awareness training, email filtering, and authentication controls, which sit in the security and resilience domain rather than the coverage domain.
Who it's relevant to
Inside Spearphishing
Common questions
Answers to the questions practitioners most commonly ask about Spearphishing.