If a suspicious email appears to come from someone your staff know, spelling mistakes are a poor test of whether it is genuine. Teach people to check the requested action and verify unusual requests through a trusted, separate channel.
Understanding the difference matters because the countermeasures are different too. Generic phishing is largely defeated by technical filtering and basic staff awareness. Spearphishing is defeated by process discipline, because the email itself is often good enough to get past both the filter and an alert staff member on a bad day.

Spearphishing vs phishing: two different attacks, one training gap
Phishing and spearphishing are both attempts to get someone to click a link, open a file or hand over credentials, but they work on different mechanics, and a staff member trained to spot one will often miss the other entirely.
Ordinary phishing is a volume game. The same email goes to thousands of addresses, the sender has done no research on any individual recipient, and the content is generic enough to plausibly apply to anyone: a delivery notice, an invoice, a password reset. The economics work because even a very low response rate across a large enough list produces victims.
Spearphishing is a targeting game. The attacker has done research — on the organisation, the individual, or both — and the email reflects that research back at the target: a real supplier name, a real project, an internal title used correctly, or a plausible reason for urgency tied to something actually happening at the time. The volume is low, sometimes a single email to a single person, because the cost of the research is paid back by a much higher chance that specific person acts on it.
Why the usual red flags don't transfer
Most staff-facing training teaches signals that work well against generic phishing and poorly against spearphishing:
| Signal taught in generic training | Works against phishing | Works against spearphishing |
|---|---|---|
| Poor spelling and grammar | Yes — mass campaigns are often low-effort | Not reliably — targeted emails are frequently well written |
| Generic greeting ("Dear Customer") | Yes | No — spearphishing typically uses the correct name and role |
| Unfamiliar sender address | Yes, if staff check | Often defeated by a spoofed or lookalike domain close enough to pass a quick glance |
| Suspicious link destination | Yes, when staff hover to check | Still valid, but the surrounding pretext is designed to reduce the instinct to check |
| Unusual request (gift cards, wire transfer) | Sometimes present | Present, but framed with specific, plausible internal context that lowers suspicion |
The practical implication: staff who rely only on the left-hand column will correctly ignore most of their inbox spam and still fall for the one email built around a real supplier, a real project code, and a request that sounds exactly like something their manager would actually ask for.
What staff need to be able to recognise instead
The signal that transfers best to spearphishing is not about the email's surface quality — it is about the relationship between urgency and verification. Teach staff to notice when a message asks them to act quickly, outside the normal process, using information that feels personal or internal enough to seem legitimate. That combination — urgency plus a bypass of the normal channel — is the pattern, regardless of how polished the email looks.
A short, practical rule that holds up in most organisations: any request involving money, credentials or sensitive data that arrives by email and asks to skip the normal approval step gets verified through a second channel before anyone acts, no matter who it appears to be from. That single habit defeats a large share of spearphishing attempts, because it doesn't depend on staff detecting the deception — it depends on a process that doesn't trust email alone for anything consequential.
Worked example: a fictional finance team incident
At a fictional mid-size manufacturer, Corrin Industries, an accounts payable clerk received an email that appeared to come from the CFO, referencing a real acquisition the company had announced internally the week before, and asking for an urgent payment to a "new supplier account" ahead of a Friday deadline. The email used the CFO's correct name, referenced the real deal, and was well written. It was not caught by spelling or tone. It was caught because the clerk's process required a phone call to confirm any new payee before the first payment — a rule that existed for unrelated reasons and happened to catch this attempt regardless of how convincing the email was.
Reporting matters as much as detection. A staff member who notices something feels wrong but has no quick, low-friction way to flag it will often do nothing, especially if they are not fully sure and don't want to raise a false alarm. The organisations that catch spearphishing attempts early are usually the ones where reporting a suspicious email takes ten seconds and carries no risk of looking foolish if it turns out to be nothing.
Common mistakes in spearphishing awareness training
- Reusing generic phishing training content and calling it complete. If the training material only covers spelling, generic greetings and obviously wrong domains, it has not addressed spearphishing at all.
- Assuming seniority is protection. Executives and finance staff are disproportionately targeted precisely because they can authorise things, which makes "whaling" against senior staff a distinct risk, not a lesser one.
- No verification-by-second-channel rule, or one that exists on paper but is routinely skipped under time pressure — the exact condition a spearphishing email is designed to create.
- Treating a near miss as a non-event. A staff member who almost clicked, or who reported suspicion after the fact, is a source of intelligence about what pretext is being used against your organisation right now. If there's no easy way to report it, that intelligence is lost.
- One annual training session. Attacker pretexts change with current events, company announcements and the calendar (tax time, end of financial year, major internal changes). Training delivered once a year goes stale well before the next session.
This distinction matters more broadly than the inbox. If you are documenting the pathway from a plausible pretext through to an actual loss for a risk assessment, Free Online Course: The Risk Bow-Tie Method is a useful way to map how a single spearphishing email becomes a financial or data loss event, and what controls sit on either side of it. If you're building out a broader awareness program, pairing staff-facing material with something visible in shared spaces — see Free Security Risk Management Wall Chart for Your Project Room — keeps the message present outside of the annual training slot. And if your organisation's risk policy is too long for anyone to actually read before an incident, Why Your Risk Policy Should Fit on One Page covers the same discipline applied to policy documents.
Give staff and their families the short version
Most staff will not read a long policy document, but they will read a one-page tipsheet, especially one written for their own inbox and their own family's, not just the office network. SRMBOK's Spearphishing Tipsheet covers impersonation scams, investment scams and buyer/seller marketplace scams in plain language, built for a company newsletter or a staff and family awareness handout.
