Spear phishing: when scams seem way too real
Compared to phishing, a term you might already know (if you do not, start with /blog/email-phishing-examples-by-country/), spear phishing is when the scam uses real details. Your name. Your family. Your actual bank. A tax number. A package you really were waiting for.
That information can come from social media, old breaches, leaked contact lists, compromised email accounts, scraped business directories, invoices, or a previous scam attempt.
So the message will not always have spelling mistakes. Sometimes it looks normal because it was built to look normal.
Easy lure vs hard lure
An easy phishing lure is the obvious one: bad spelling, strange logo, generic greeting, weird link, no real context. People still click those, but many people pause.
A hard lure is more specific. It may name your bank, use your first name, arrive during tax season, mention a real package, or copy the tone of a company you already use.
In one phishing training study using the NIST Phish Scale, easy lures had a 7.0% click rate. Hard lures had a 15.0% click rate. Put another way: out of 100 people, about 7 clicked the easier scam. With the harder lure, about 15 clicked.
That is a little more than twice as many people.
Out of 100 people
In the study, harder phishing lures got about twice as many clicks.
Why real details do not prove the message is real
CISA describes phishing as social engineering: someone pretends to be trustworthy so you will click, download, reply, log in, or pay.
Spear phishing adds personalization. A 2026 paper on context aware spear phishing found that public social media data can be used to generate more personalized messages that feel less suspicious than older phishing examples.
That is the point. A true detail can sit inside a false message.
A fake invoice can include a real company name. A bank text can name the bank you actually use. A DM can mention an influencer you follow. The true detail is bait. The request is what you check.
The mismatch test
Use this when a message feels real.
| What looks real | What to check |
|---|---|
| It knows your name | Did it use your name in a specific way, or just paste it into a generic message? |
| It names your bank | Does the alert appear inside your bank app too? |
| It mentions a package | Is the tracking number real on the carrier website you opened yourself? |
| It includes a factura or invoice | Were you expecting that invoice from that supplier, for that amount, today? |
| It mentions tax or government | Does that agency normally send SMS or email links for this action? |
| It uses a real logo | Does the domain match the real company exactly? |
| It comes from a known contact | Is the request normal for that person, or urgent and secret? |
| It sounds local | Do the phone number, currency, domain, and wording actually match the country? |
Examples you can open
Use dropdowns in the HTML version. Readers can open the one that matches the message they received.
Bank SMS, wrong route
"Chase: A new device was added to your account. Tap to cancel."
Check whether the same alert appears inside the bank app. If the text comes from a normal number, uses a short link, or asks for a one time code, treat it as unsafe.
Tax invoice, wrong expectation
"Estimado contribuyente, se detectaron irregularidades. Descargue su factura pendiente."
Fake factura and CFDI emails can contain real looking data. That does not make them safe. Check the official portal or ask the supplier through another channel.
Package delivery, wrong timing
"Your package is held for a $3.50 customs fee."
Small fees are a trick. Use the tracking number you already had, not the link in the message.
Family emergency, wrong behavior
"Mom, I changed my number. I need money today."
Call the old number. Ask the family verification phrase. Be careful if the person refuses a voice call or asks you not to tell anyone.
What the scam wants you to do
The details are bait. The action is the danger.
Be careful when the message asks you to:
- Click a link
- Download a factura, boleto, ZIP, or PDF
- Share a one time code
- Pay a small delivery fee
- Move money to a safe account
- Send Pix, Interac, wire, crypto, gift cards, or a bank transfer
- Keep the message secret
- Act before a deadline
What to do next
- Do not use the link in the message.
- Open the official app or website yourself.
- Call through a known number, not the number in the message.
- Ask whether you expected this invoice, package, tax notice, or payment.
- If it involves family, verify through a second family member.
- Save screenshots if money or identity information is involved.
- Report it through the relevant authority or company.
Related guides
- /us/blog/online-banking-activity-alert-text-scam/
- /us/blog/influencers-social-media-dangerous-scams/
- /mx/blog/fraude-sms-correo-bbva-sat-paqueteria-facturas/
- /br/blog/como-saber-se-e-golpe-do-pix/
- /us/blog/best-spam-text-blocker-iphone-2026/
Sources
- Phishing training study with NIST Phish Scale results: https://arxiv.org/abs/2506.19899
- CISA social engineering and phishing guidance: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
- Context aware spear phishing with generative AI and public social data: https://arxiv.org/abs/2605.11268
- PiMRef spear phishing detection research: https://arxiv.org/abs/2507.15393
- FTC report fraud portal: https://reportfraud.ftc.gov/
- Local Security Engine research files for US, MX, CA, BR, UAE