If a suspicious email appears to come from someone your staff know, spelling mistakes are a poor test of whether it is genuine. Teach people to check the requested action and verify unusual requests through a trusted, separate channel.

Understanding the difference matters because the countermeasures are different too. Generic phishing is largely defeated by technical filtering and basic staff awareness. Spearphishing is defeated by process discipline, because the email itself is often good enough to get past both the filter and an alert staff member on a bad day.

A convincing email still needs checking: Notice an unusual request; Verify through a known channel; Report the suspicious message.
Familiar names and polished writing are not proof.

Spearphishing vs phishing: two different attacks, one training gap

Phishing and spearphishing are both attempts to get someone to click a link, open a file or hand over credentials, but they work on different mechanics, and a staff member trained to spot one will often miss the other entirely.

Ordinary phishing is a volume game. The same email goes to thousands of addresses, the sender has done no research on any individual recipient, and the content is generic enough to plausibly apply to anyone: a delivery notice, an invoice, a password reset. The economics work because even a very low response rate across a large enough list produces victims.

Spearphishing is a targeting game. The attacker has done research — on the organisation, the individual, or both — and the email reflects that research back at the target: a real supplier name, a real project, an internal title used correctly, or a plausible reason for urgency tied to something actually happening at the time. The volume is low, sometimes a single email to a single person, because the cost of the research is paid back by a much higher chance that specific person acts on it.

Why the usual red flags don't transfer

Most staff-facing training teaches signals that work well against generic phishing and poorly against spearphishing:

Signal taught in generic training Works against phishing Works against spearphishing
Poor spelling and grammar Yes — mass campaigns are often low-effort Not reliably — targeted emails are frequently well written
Generic greeting ("Dear Customer") Yes No — spearphishing typically uses the correct name and role
Unfamiliar sender address Yes, if staff check Often defeated by a spoofed or lookalike domain close enough to pass a quick glance
Suspicious link destination Yes, when staff hover to check Still valid, but the surrounding pretext is designed to reduce the instinct to check
Unusual request (gift cards, wire transfer) Sometimes present Present, but framed with specific, plausible internal context that lowers suspicion

The practical implication: staff who rely only on the left-hand column will correctly ignore most of their inbox spam and still fall for the one email built around a real supplier, a real project code, and a request that sounds exactly like something their manager would actually ask for.

What staff need to be able to recognise instead

The signal that transfers best to spearphishing is not about the email's surface quality — it is about the relationship between urgency and verification. Teach staff to notice when a message asks them to act quickly, outside the normal process, using information that feels personal or internal enough to seem legitimate. That combination — urgency plus a bypass of the normal channel — is the pattern, regardless of how polished the email looks.

A short, practical rule that holds up in most organisations: any request involving money, credentials or sensitive data that arrives by email and asks to skip the normal approval step gets verified through a second channel before anyone acts, no matter who it appears to be from. That single habit defeats a large share of spearphishing attempts, because it doesn't depend on staff detecting the deception — it depends on a process that doesn't trust email alone for anything consequential.

Worked example: a fictional finance team incident

At a fictional mid-size manufacturer, Corrin Industries, an accounts payable clerk received an email that appeared to come from the CFO, referencing a real acquisition the company had announced internally the week before, and asking for an urgent payment to a "new supplier account" ahead of a Friday deadline. The email used the CFO's correct name, referenced the real deal, and was well written. It was not caught by spelling or tone. It was caught because the clerk's process required a phone call to confirm any new payee before the first payment — a rule that existed for unrelated reasons and happened to catch this attempt regardless of how convincing the email was.

Reporting matters as much as detection. A staff member who notices something feels wrong but has no quick, low-friction way to flag it will often do nothing, especially if they are not fully sure and don't want to raise a false alarm. The organisations that catch spearphishing attempts early are usually the ones where reporting a suspicious email takes ten seconds and carries no risk of looking foolish if it turns out to be nothing.

Common mistakes in spearphishing awareness training

This distinction matters more broadly than the inbox. If you are documenting the pathway from a plausible pretext through to an actual loss for a risk assessment, Free Online Course: The Risk Bow-Tie Method is a useful way to map how a single spearphishing email becomes a financial or data loss event, and what controls sit on either side of it. If you're building out a broader awareness program, pairing staff-facing material with something visible in shared spaces — see Free Security Risk Management Wall Chart for Your Project Room — keeps the message present outside of the annual training slot. And if your organisation's risk policy is too long for anyone to actually read before an incident, Why Your Risk Policy Should Fit on One Page covers the same discipline applied to policy documents.

Give staff and their families the short version

Most staff will not read a long policy document, but they will read a one-page tipsheet, especially one written for their own inbox and their own family's, not just the office network. SRMBOK's Spearphishing Tipsheet covers impersonation scams, investment scams and buyer/seller marketplace scams in plain language, built for a company newsletter or a staff and family awareness handout.