Spear phishing vs. mass phishing: what's the difference?
Phishing comes in two broad shapes: the net and the spear. Understanding the difference between mass phishing and spear phishing explains why some attacks slip past filters and trained employees alike — and what defences actually apply to each.
Mass phishing: the net
Mass phishing sends the same generic message to thousands of people: a fake delivery notice, a "your account is locked" email. It costs almost nothing to send, relies on volume, and is relatively easy to filter because the same message and infrastructure appear many times.
Spear phishing: the spear
Spear phishing flips the trade-off. It targets one person or a small team, using real details — their name, role, current projects, a colleague's name — to craft a message that feels genuine. Low volume and high personalisation make it far harder for filters to catch and for people to doubt.
- Research — attackers mine social media, your website and leaks for details.
- Pretext — a believable reason that fits the target's world.
- Impersonation — often a trusted colleague or vendor, sometimes via a lookalike domain.
The more public detail an attacker can gather, the sharper the spear. Reducing what's exposed is a real defence, not just hygiene.
Defending against each
Mass phishing is largely a filtering and takedown problem — block the campaign, remove the pages. Spear phishing needs more: email authentication to stop spoofing, out-of-band verification for unusual requests, and monitoring for lookalike domains used to impersonate trusted senders. Both benefit from removing the fake pages behind the links.
Phish Plug helps on the infrastructure both share — the lookalike domains and cloned pages — detecting and taking them down whether the lure was sprayed to thousands or aimed at one.
The takeaway
Mass phishing bets on volume; spear phishing bets on precision. Filters handle the net reasonably well, but the spear needs layered defences — authentication, verification and lookalike-domain monitoring — because its whole design is to look exactly like something you trust.
Keep reading
Related articles
Whaling: phishing that targets the executives
Whaling aims at leadership, where one approval moves money. How executive-targeted phishing works and the controls that stop a convincing impersonation.
Read article Threats · 6 minClone phishing: when a real email comes back poisoned
Clone phishing copies a legitimate message and swaps the link or attachment. Why the familiarity makes it dangerous and how to recognise and stop it.
Read article Threats · 6 minQR code phishing (quishing): the scan-and-steal scam
A QR code hides its destination until you scan it. How quishing abuses that trust, where fake codes appear, and how to defend your brand and customers.
Read articleProtect your brand from impersonation
Run a free clone check on one domain — Phish Plug proves the cloaking and builds the takedown case for you.