Spear Phishing: How to Protect Your Employees From Targeted Attacks

Reviewed by IT Cares certified technicians · Updated July 2026

Canadian business employee reviewing a suspicious targeted spear phishing email that appears to come from a company executive
A spear phishing email is built for one person, one company, one moment — which is exactly what makes it so much more convincing than a generic scam.
🎯
Not sure your team could spot a targeted attack aimed straight at them? IT Cares helps Canadian businesses build real spear phishing defenses — training, reporting culture, and technical controls together.
See Cybersecurity Services →

A generic phishing email is easy to laugh off — "Dear Customer, your account has been suspended" fools almost nobody who's paying attention. A spear phishing email is a different animal entirely: it uses your real name, references your actual manager, mentions a project you're genuinely working on, and arrives at exactly the moment you're rushed and distracted. That level of personalization is why spear phishing, not mass phishing, is responsible for the overwhelming majority of the financial losses Canadian businesses actually report — and why training employees to recognize a generic scam email does surprisingly little to protect them against an attack built specifically around who they are.

This guide covers spear phishing specifically — not generic phishing in general, which our foundational guide to what phishing is and how to spot it already covers in depth. Here, the focus is narrower and more practical: how attackers research a target before ever sending an email, the handful of scenarios that account for most real-world losses (fake CEO wire transfers, vendor invoice fraud, fake IT helpdesk requests, fake legal demands, and malicious job applications aimed at HR), the red flags that actually distinguish a targeted attack from a legitimate request, why these emails slip past the spam filter that catches everything else, and the training, reporting culture, and verification procedures that genuinely reduce the risk — along with real Canadian pricing for the tools involved and three realistic case studies showing exactly how this plays out for businesses your size.

Who wrote this guide

This guide was written and reviewed by IT Cares certified technicians based on supporting Canadian businesses through real spear phishing incidents and building the awareness training and verification procedures that prevent the next one. We're not selling a single tool as the fix — spear phishing is defeated by a combination of trained people, a reporting culture that works, and a small number of specific technical controls, and this guide is structured to walk through all three.

What Is Spear Phishing, and How Is It Different From Generic Phishing?

Spear phishing is a targeted email attack aimed at a specific individual or small group, built using genuine, researched information about the target rather than a one-size-fits-all script. Where mass phishing plays a numbers game — send the same message to hundreds of thousands of addresses, and even a 0.1% click rate produces results — spear phishing plays a precision game: research one target thoroughly, craft a message specifically for them, and rely on that precision rather than volume to succeed. A mass phishing email might claim to be from "your bank" and ask you to verify your account; a spear phishing email addresses you by name, references your actual employer, names your actual manager or a real vendor your company works with, and asks for something that fits naturally into your actual job.

The distinction matters practically because the two require genuinely different defenses. Generic phishing is largely a technology problem — spam filters, link scanning, and attachment sandboxing catch the bulk of it before it ever reaches an inbox, because the patterns are broad and repetitive across millions of near-identical messages. Spear phishing is much more a human and process problem — because each message is unique, low-volume, and specifically crafted to look legitimate, technology alone consistently fails to catch it, and the real defense has to live in how employees are trained to verify unusual requests and how comfortable they feel flagging something that feels slightly off.

Within spear phishing, it's worth being precise about a further distinction: whaling refers specifically to spear phishing aimed at senior executives — a CFO, CEO, or board member — where the attacker is either impersonating that executive to someone else, or targeting the executive directly because of the outsized authority and access their account carries. Whaling attacks tend to be even more heavily researched than a typical spear phishing attempt, because the payoff for successfully compromising or impersonating a senior executive is proportionally larger, and attackers invest reconnaissance time accordingly.

Business Email Compromise (BEC) is the category within spear phishing responsible for the largest actual dollar losses, and it deserves its own definition because it doesn't always look like a traditional phishing attack at all. BEC is any scheme where an attacker impersonates a trusted figure — a CEO, a real vendor, a lawyer, a colleague — specifically to induce a financial action: a wire transfer, a change to banking details on file, a gift card purchase, or the release of sensitive financial or personal data. Critically, a large share of BEC attempts contain no malicious link and no attachment whatsoever — just a well-written, well-timed, well-researched email asking for something that sounds like an ordinary part of someone's job. That absence of a "smoking gun" technical artifact is precisely why BEC is so effective and so hard to catch with traditional security tools.

Want your team trained on exactly these scenarios?

IT Cares builds simulated phishing campaigns and employee training programs specifically calibrated to how targeted attacks actually work.

The Reconnaissance Phase: How Attackers Research Your Employees

Before a single email is sent, an attacker running a real spear phishing operation spends time building a profile of their target — and the uncomfortable truth is that this research is neither difficult nor time-consuming, because most of what's needed is already public. Understanding exactly where this information comes from is the first step toward recognizing why a spear phishing email feels so unnervingly accurate.

LinkedIn is the single richest source. A target's job title, direct manager, department, tenure, recent promotions, and even a recent job change are all visible on a public profile, and LinkedIn's own "who's viewed your profile" and connection-request features make it trivial for an attacker to identify a company's finance team, its executive assistants (who often manage an executive's calendar and correspondence), and anyone recently onboarded — new employees are a favourite target because they haven't yet learned the company's normal communication patterns and are motivated to be responsive and helpful.

Company websites — specifically "About Us," "Our Team," and "Leadership" pages — hand an attacker names, titles, headshots, and often enough biographical detail to construct a plausible pretext. Combined with a company's email format (easily inferred from a single published address, a press release, or a job posting that lists a contact email), an attacker can construct a highly plausible email address for anyone at the company without ever needing to breach anything.

Press releases and news coverage reveal recent mergers, new office openings, funding rounds, executive hires, and major project announcements — all of which give an attacker specific, current, verifiable-sounding details to reference in a message ("regarding the [Project Name] closing this week" lands very differently than a vague generic request, precisely because it demonstrates knowledge that feels like it could only come from someone genuinely involved).

Social media more broadly — company Instagram or Facebook posts, an executive's own public posts, even out-of-office auto-replies — can reveal travel plans and unavailability, which attackers use deliberately: a fake urgent wire transfer request timed to arrive while the real CEO is confirmed to be on a flight or in back-to-back meetings is far more likely to succeed, because the target can't simply walk down the hall to ask a clarifying question.

📊 IT Cares field note: A pattern we see constantly during incident reviews: the business is stunned by how much the attacker "knew," when in reality nearly everything referenced in the malicious email was sitting in plain view on the company's own website, a recent press release, or an employee's public LinkedIn profile. None of it required hacking anything — it required about twenty minutes of ordinary web research, which is exactly why this kind of attack is accessible to a huge range of attackers, not just sophisticated criminal groups.

This reconnaissance phase typically takes an attacker as little as twenty to thirty minutes for a straightforward target, and considerably longer — sometimes days — for a well-planned whaling attempt against a specific executive at a high-value target. The point isn't that this information shouldn't exist publicly; a company website and LinkedIn presence are legitimate business necessities. The point is that employees need to understand this research happens routinely and cheaply, so that a message referencing accurate, specific details isn't mistaken for proof of legitimacy — accuracy of detail proves the attacker did their homework, not that the request is real.

Generic Phishing vs. Spear Phishing vs. Whaling: A Side-by-Side Comparison

These three terms get used loosely and interchangeably in casual conversation, but they describe meaningfully different attacks with different risk profiles. Here's how they compare across the factors that actually matter for building a defense.

Factor Generic / Mass Phishing Spear Phishing Whaling (Executive-Targeted)
Targeting None — sent broadly to any address on a purchased or scraped list A specific individual or small group, chosen deliberately A specific senior executive (CEO, CFO, board member)
Volume Very high — thousands to millions of identical messages Very low — often a single email to one person Extremely low — usually one carefully constructed message
Personalization Minimal or none — generic greeting, generic company reference High — real name, title, manager, or project referenced Very high — often includes financial or deal-specific detail
Reconnaissance required None Light to moderate — LinkedIn, company site, press releases Extensive — financial filings, deal news, travel patterns
Typical financial loss per incident Usually low per victim, sometimes zero if only credentials are stolen Commonly $10,000–$100,000+ CAD when a wire transfer succeeds Frequently $100,000–$1,000,000+ CAD given executive-level authority
Detection difficulty Low — spam filters and link scanning catch most of it High — low volume and legitimate-looking detail evade filters Very high — highly customized, sometimes multi-message campaigns
Primary defense Spam filtering, link/attachment scanning, basic awareness Employee training, reporting culture, out-of-band verification Same as spear phishing, plus dedicated executive protection protocols

The pattern across this table is consistent: as targeting and personalization go up, technology-based detection goes down, and the financial stakes go up. That's exactly why the categories most likely to actually cost your business real money — spear phishing and whaling — are also the categories where employee judgment and verification habits matter more than any filter or scanner sitting in front of the inbox.

Five Realistic Spear Phishing Scenarios Employees Actually Face

These scenarios are composite and illustrative — patterns that show up repeatedly across real incidents, not accounts of any specific named business. They're presented in enough detail to make the mechanics concrete, because a vague description ("watch out for suspicious emails") is far less useful than understanding exactly how each scenario actually unfolds.

1

The Fake CEO Wire Transfer

An email arrives in the inbox of someone in accounts payable or finance, appearing to come from the CEO or another senior executive — either from a lookalike domain, a spoofed display name, or a genuinely compromised account. The message is short, urgent, and framed as confidential: "I'm in meetings all day and can't talk, but I need you to process a wire transfer for a time-sensitive acquisition. Please treat this as confidential for now, I'll explain once I'm free." It deliberately discourages the normal verification steps by invoking confidentiality and unavailability, and it's frequently timed to a moment — end of quarter, a known executive travel day — when a slightly unusual request feels more plausible.

2

The Fake Vendor Invoice With Changed Banking Details

An email appears to come from a real, existing vendor the business has paid many times before, referencing a real invoice number or project, and includes a routine-looking note: "Please note our banking details have changed effective this month — updated remittance information attached." The invoice itself may be entirely legitimate in every detail except the bank account number, which routes payment to the attacker instead of the real vendor. This scenario is particularly dangerous because it doesn't require compromising the business at all — often the vendor's own email account was compromised, and the attacker is simply intercepting and modifying genuine correspondence already in progress.

3

The Fake IT Helpdesk Password Reset

An email or even a phone call, styled as coming from internal IT support, claims a security issue was detected on the employee's account and asks them to "verify" their credentials on a link, or to read back a one-time passcode that was just texted to them. In reality, the attacker has already entered the employee's real username and triggered a genuine password reset or MFA prompt, and is now social-engineering the employee into handing over the one piece of information — the code — needed to complete the takeover. This scenario increasingly targets employees around known transition periods, like a company-wide software migration, when a message about "required account verification" fits naturally into what's actually happening.

4

The Fake Legal or Compliance Urgent Document Request

An email, often targeting an executive assistant, HR, or a manager, claims to come from outside legal counsel or a compliance authority and demands urgent action — reviewing and signing an attached document, or providing sensitive employee or financial records "before end of day" to avoid a stated penalty or legal consequence. The framing deliberately manufactures both urgency and a credible-sounding authority figure, betting that the recipient will prioritize compliance over caution when a request appears to carry legal weight.

5

The Fake Job Candidate With a Malicious Resume

An HR inbox or recruiting manager receives what looks like a normal application, tailored to an actual posted opening, with a resume attached as a Word document or PDF. The attachment contains malicious macros or an embedded exploit that, once opened, installs malware or establishes remote access — a technique that works precisely because opening resumes from strangers is a routine, expected part of an HR employee's job, unlike most other departments where an unsolicited attachment would already feel out of place.

Technical Red Flags vs. Human and Behavioural Red Flags

Employees are often trained to look exclusively for technical red flags — misspellings, a mismatched sender address, a suspicious link — and while these still matter, a well-run spear phishing attempt is frequently technically clean. The behavioural red flags, tied to how the request is framed rather than how the email is built, tend to be the more reliable signal in a genuinely targeted attack.

Technical red flags worth checking

Human and behavioural red flags — often the more reliable signal

The single most useful habit to teach

Train employees to treat "urgency plus a request to bypass normal verification" as the actual red flag, rather than trying to spot every technical trick. Attackers can fake a domain, a signature, and a writing style with enough effort — but they can't fake a phone call to the real person's real number, which is exactly why that one habit catches almost everything else on this list.

Why Spear Phishing Slips Past Traditional Spam Filters

Business owners are frequently surprised that a targeted attack made it through to an inbox at all, given that email security tools stop the vast majority of ordinary spam and phishing without any employee noticing. Understanding why spear phishing specifically evades these tools matters, because it explains why the technical layer alone will never be a complete answer.

Low volume defeats pattern-based detection. Spam filters are fundamentally statistical — they learn to recognize a threat by seeing the same or similar message sent to large numbers of recipients, or by identifying a sender that suddenly sends an unusual volume of mail. A spear phishing email sent once, to one person, from an account that otherwise looks and behaves normally, simply doesn't generate the pattern most filtering systems are built to catch.

Many spear phishing and BEC attempts contain no malicious payload at all. Link scanners and attachment sandboxes exist to catch malware and phishing URLs — but a BEC email requesting a wire transfer is, from a technical standpoint, just text. There's nothing to scan, nothing to detonate in a sandbox, and nothing that trips a malicious-content filter, because the entire attack is social rather than technical.

The sending domain frequently looks legitimate. Attackers achieve this three main ways: registering a lookalike or typosquatted domain that's visually close enough to pass a quick glance (a technique that also underscores why understanding domain spoofing generally matters as a baseline skill); genuinely compromising a real account at a vendor or partner company and sending from an entirely authentic address; or using a free email service with a display name manipulated to show a trusted name while the underlying address is unrelated. None of these trip the domain-reputation checks that catch obviously malicious or newly-registered spam domains.

The message is written to sound completely normal for the context. Modern spear phishing emails are frequently well-written, professionally formatted, and free of the grammar and spelling errors that used to be a reliable tell — removing one of the few signals that used to help both filters and humans catch a scam at a glance.

Spear Phishing Defense Checklist for Employees

Below is a condensed, practical checklist meant to be printed, saved, or distributed to every employee — particularly anyone in finance, HR, or with wire transfer or banking-detail authority. Nothing on this list requires specialized security knowledge; it's built around habits any employee can adopt immediately.

Spear Phishing Defense Checklist for Employees

Before You Act on Any Unusual Request

☐ Pause before responding to anything urgent, confidential, or unusual — urgency itself is a warning sign, not a reason to skip verification

☐ Check the actual sender email address, not just the display name

☐ Hover over any link before clicking to confirm where it actually leads

Verifying the Request

☐ Call the person using a phone number already on file — never a number provided in the email itself

☐ For any wire transfer or banking detail change, confirm verbally with a second person before processing

☐ Treat "don't tell anyone" or "skip the usual approval process" as an automatic reason to verify, not comply

Handling Attachments and Links

☐ Never open an unexpected attachment without confirming its origin first

☐ Never enter login credentials on a page reached by clicking a link from an email

Reporting

☐ Report anything suspicious immediately, even if you're not fully sure it's malicious

☐ Know exactly how to report — a specific button, address, or contact — before you actually need to use it

Employee Security Awareness Training: The Primary Defense

Because spear phishing is fundamentally a human-targeted attack, the single most effective investment a business can make against it isn't a piece of technology — it's training employees to recognize and correctly respond to a targeted attempt, reinforced regularly enough that the response becomes reflexive rather than something remembered only after the fact from a one-time onboarding session years ago.

Simulated phishing campaigns

Rather than a single annual training video, the most effective programs run ongoing simulated phishing campaigns — realistic, harmless test emails sent periodically to employees, styled after the exact scenarios covered in this guide (a fake CEO request, a fake invoice, a fake password reset). Employees who click are shown a brief, non-punitive learning moment immediately, explaining what red flag they missed; employees who correctly report the simulation are recognized for it. Over time, click rates on these simulations reliably drop as the specific patterns become familiar, and — just as importantly — report rates go up, which is the metric that actually matters most for real-world protection.

Building a reporting culture that actually works

The single biggest process failure in businesses that get hit by spear phishing isn't that an employee couldn't recognize something was off — it's that they noticed something felt wrong, hesitated, and didn't report it in time, often out of concern about looking foolish or wasting someone's time over a false alarm. A reporting culture that genuinely works treats every report as a success regardless of whether the email turns out to be malicious, makes the reporting mechanism a single obvious button or address rather than a multi-step process, and — critically — never punishes or embarrasses an employee who reports something that turns out to be legitimate. The cost of a false alarm is a few minutes of an IT person's time; the cost of a real attempt going unreported is potentially the entire incident this guide is trying to prevent.

Role-specific training for high-risk positions

Finance staff, accounts payable, HR, and executive assistants face meaningfully different — and generally higher-stakes — spear phishing attempts than the rest of the company, and training calibrated specifically to their role (wire transfer verification procedures for finance, malicious-attachment awareness for HR, executive-impersonation patterns for assistants) produces better results than a single generic training track applied uniformly across every department.

New employee vulnerability

New hires are disproportionately targeted, and for good reason from an attacker's perspective: they haven't yet learned the company's normal communication patterns, are motivated to be responsive and helpful, and are less likely to recognize when a request from "the CEO" feels unusual because they simply don't yet know what usual looks like. Building spear phishing awareness into the very first week of onboarding — not a module scheduled for "sometime in the first quarter" — closes this window meaningfully.

Technical Controls That Support the Human Defense

Training and reporting culture are the primary defense, but a handful of technical controls meaningfully reduce both how many spear phishing attempts reach an inbox in the first place and how much damage succeeds when one does get through.

Email authentication: DMARC, SPF, and DKIM

These three technical standards work together to make it much harder for an attacker to send email that appears to come from your own domain — SPF authorizes which mail servers can legitimately send on your domain's behalf, DKIM cryptographically signs outgoing mail so recipients can verify it wasn't altered in transit, and DMARC tells receiving mail servers what to do with messages that fail those checks (quarantine, reject, or simply monitor). Properly configured DMARC in particular closes off exact-domain spoofing — where an attacker sends mail that appears to come directly from "@yourcompany.com" rather than a lookalike domain — which is one of the more convincing techniques available to a spear phishing attacker. A full technical walkthrough of configuring these for Microsoft 365 or Google Workspace is beyond the scope of this guide; the practical takeaway here is simply that if your business hasn't confirmed DMARC is set to actively quarantine or reject failing mail (rather than just monitor it, which many domains are left at by default), that's a genuine, fixable gap worth raising with whoever manages your email infrastructure.

Out-of-band verification procedures

This is the single highest-value technical-adjacent control on this entire list: any request involving money movement, banking detail changes, or sensitive data release that arrives by email should be verified through a different channel — a phone call to a number already on file, not one provided in the email — before being acted on. This single habit defeats the overwhelming majority of BEC attempts, because an attacker who has compromised or spoofed an email account almost never also controls the real phone line of the person they're impersonating. Formalizing this as a written policy, rather than leaving it as an informal habit some employees happen to practice, is what makes it reliable under the exact pressure and urgency an attacker is counting on to short-circuit good judgment.

Banking detail change verification policy

Specifically for vendor invoice fraud, a written policy requiring verbal confirmation — through a previously established contact, not a number or email included in the change notice — before updating any vendor's banking details on file closes the single most common and costly BEC scenario. This should be a non-negotiable, no-exceptions process regardless of how routine or well-documented the change request appears, precisely because a well-executed vendor impersonation is designed to look exactly like routine correspondence.

Where a deeper email security stack fits

Beyond authentication and process, advanced email security add-ons — impersonation detection that flags when a display name matches an executive but the underlying address doesn't, banner warnings on external mail, and AI-assisted anomaly detection looking at unusual sending patterns — add a meaningful additional layer, particularly for businesses with dedicated finance teams or frequent high-value vendor payments. These tools work best as a supplement to trained employees and clear verification policy, not a replacement for either.

Want this actually built for your business, not just explained?

IT Cares' cybersecurity services cover employee awareness training, simulated phishing campaigns, and the email authentication and verification policies described above, built around your real environment. If you'd rather start by finding out exactly where your current gaps are, our security audit service reviews email authentication configuration and access controls as part of a full assessment.

Real-World Examples: How Spear Phishing Plays Out

These three examples are composite, illustrative case studies based on the kinds of incidents and outcomes common across Canadian SMBs — not accounts of specific named businesses. They're included because concrete numbers and timelines make the risk tangible in a way general warnings don't.

Case study 1: Fortin Construction & Contracting, Sherbrooke, QC — 34 employees

Fortin, a mid-size general contracting firm, received what looked like a routine email from one of its longtime concrete suppliers, referencing a real, active project and a genuine outstanding invoice number, noting that "due to a banking transition" future payments should go to an updated account. The accounts payable clerk processed the change and the next invoice payment — $47,500 CAD — without a phone call to confirm, since the email matched the supplier's usual format and referenced accurate project details. The fraud was discovered three weeks later when the real supplier called asking why payment was overdue. Fortin recovered roughly $6,200 CAD through the bank's fraud recall process, since most of the transferred funds had already been withdrawn by the time the fraud was flagged, leaving a net loss of approximately $41,300 CAD. The company's insurer covered a portion under a cyber-crime rider, but only after a lengthy claims process; Fortin subsequently implemented a mandatory phone-verification policy for any vendor banking change, with no exceptions regardless of how legitimate the request appears.

Case study 2: Northloop Analytics, Calgary, AB — 19 employees

Northloop, an early-stage software startup, had its acting head of finance receive an email that appeared to come from the CEO — travelling for investor meetings that week, a fact publicly visible from a recent LinkedIn post — requesting an urgent $28,000 CAD wire transfer to "secure a time-sensitive contractor arrangement," framed as confidential and asking that it be handled before the CEO landed and lost connectivity. The finance lead, trained six weeks earlier in a simulated phishing exercise that specifically covered this exact scenario, called the CEO directly on his personal cellphone — a number already on file, not one provided anywhere in the email — rather than replying. The CEO had sent no such request; the email had come from a lookalike domain with a single character swapped from the company's real domain. No funds were transferred. Northloop's founders specifically credited the recent training exercise, still fresh enough to be top of mind, as the reason the request was questioned rather than processed under pressure.

Case study 3: Whitfield & Sons Law Office, Fredericton, NB — 11 employees

Whitfield, a small family law practice, had its office manager receive an email appearing to come from a well-known local court registry, marked urgent, demanding an immediate response to an attached "compliance document" tied to an active case file — a plausible request given the firm's genuine caseload. The attachment, opened without hesitation given the apparent legal authority behind the request, deployed malware that spent several days quietly harvesting credentials before the firm's endpoint protection flagged unusual outbound network activity and isolated the affected machine. No client data was confirmed exfiltrated based on the firm's subsequent forensic review, but the incident response, credential resets across the firm, and forensic investigation cost approximately $14,000 CAD, and the firm was required to assess whether client notification obligations applied under provincial privacy rules given the sensitivity of legal files potentially exposed. Whitfield now runs mandatory annual security awareness training for all staff and has a written policy that any document claiming legal or regulatory urgency is verified by phone with the purported sender's publicly listed office number before being opened.

What these three cases have in common

Two of these three incidents resulted in real financial or operational damage; one was stopped entirely. The difference wasn't better technology in the case that succeeded — it was a trained employee, with a fresh, specific memory of exactly this scenario, choosing to verify through a separate channel rather than act under pressure. That's the throughline of this entire guide: the technical layer helps, but the decisive moment in nearly every real spear phishing incident is a single human decision about whether to pause and verify.

It's also worth being honest about what these cases don't show: none of the businesses involved were careless in any general sense. Fortin, Northloop, and Whitfield were all reasonably well-run organizations with competent staff — the difference between the incident that succeeded and the one that didn't came down to whether verification training had been recently reinforced, not whether the business was fundamentally negligent. That's precisely why ongoing, repeated training beats a single onboarding session: even a genuinely careful employee, six months removed from any reminder of these specific patterns, is meaningfully more vulnerable than one who ran through a realistic simulation a few weeks earlier.

Budget & Pricing: What Spear Phishing Defense Actually Costs

Cost is often the reason awareness training gets deprioritized against more visible IT spending, so here are honest, directional Canadian ranges for the tools and services that make up a real spear phishing defense program.

Weighed against these figures, the comparison that resolves most budget hesitation is the same one that applies to security spending generally: a full year of simulated phishing training and awareness content for a 25-person business, at the high end of the ranges above, costs meaningfully less than the $41,300 CAD net loss in the Fortin case study above — a single successful BEC incident that a modest, recurring training investment is specifically designed to prevent.

Canadian Government & Reporting Resources

Several free, credible Canadian resources exist for both preventing and responding to spear phishing and BEC fraud, and every business should know about them before an incident happens, not while scrambling to figure out who to call afterward.

If your business ever falls victim to a wire transfer fraud specifically, time matters enormously: contacting your bank's fraud department immediately — within hours, not days — meaningfully increases the odds of a successful recall before funds are fully withdrawn by the attacker, which is exactly what limited Fortin's losses in the case study above rather than leaving the full amount unrecoverable.

Frequently Asked Questions

What is spear phishing and how is it different from regular phishing?
Spear phishing is a targeted email attack aimed at a specific person or small group, built using real information about the target — their name, job title, manager, recent projects, or vendors — gathered from LinkedIn, company websites, and social media. Regular (mass) phishing sends the same generic message to thousands of random addresses hoping a small percentage click; spear phishing sends a handful of carefully personalized messages to specific people, which makes each one far more convincing and far more likely to succeed.
What is Business Email Compromise (BEC) and how does it relate to spear phishing?
Business Email Compromise (BEC) is the most financially damaging category of spear phishing, in which an attacker impersonates a trusted figure — typically a CEO, executive, or real vendor — to trick an employee into making a wire transfer, changing banking details, or sending sensitive data. BEC attacks often contain no malicious link or attachment at all, relying purely on a convincing, well-researched message and a sense of urgency, which is exactly why they slip past traditional spam filters built to catch malware and phishing links.
How do attackers research targets before sending a spear phishing email?
Attackers build a target profile using publicly available information: LinkedIn profiles reveal job titles, reporting lines, and recent job changes; company "About Us" and "Our Team" pages list executives and their email format; press releases and news mentions reveal recent projects, mergers, or events; and social media posts can reveal travel plans, useful for timing a fake urgent request when the real executive is known to be unreachable. This reconnaissance phase can take an attacker as little as 20-30 minutes and is what makes the resulting email specific enough to bypass a skeptical read.
Why do spear phishing emails get past spam filters that catch other phishing attempts?
Spam filters are built to catch patterns common in mass phishing: high send volume from a single source, known malicious links, flagged attachments, and generic language. Spear phishing emails are sent in very low volume, often to just one person, frequently contain no link or attachment at all, and are sent from a domain that looks legitimate — either a genuine but compromised account, a lookalike or typosquatted domain, or a free email service with a display name spoofed to match a real colleague. None of these individually trip the pattern-based rules a spam filter is designed to catch.
What should an employee do if they suspect a spear phishing email?
Don't reply, click any link, open any attachment, or take the requested action. Verify the request through a separate, known channel — call the person using a phone number you already have on file, not one provided in the email — and report the message to IT or through your company's designated reporting process immediately, even if you're not fully sure it's malicious. A reporting culture that treats "I wasn't sure, so I flagged it" as the correct response, rather than something to feel embarrassed about, is one of the strongest defenses a business can build.
How much does security awareness training cost for a small business in Canada?
Simulated phishing and security awareness training platforms for small businesses typically run $3-$8 CAD per employee per month, or roughly $30-$70 CAD per employee annually, depending on the platform and whether it includes ongoing simulated phishing campaigns. For a 25-person business, that's roughly $900-$1,750 CAD per year — a modest cost against the average financial loss from even a single successful BEC incident, which regularly runs into the tens of thousands of dollars.
What is out-of-band verification and why does it matter for wire transfers?
Out-of-band verification means confirming a request through a different communication channel than the one it arrived on — if a wire transfer or banking detail change request arrives by email, you verify it by phone, using a number you already had on file rather than one included in the email itself. This single habit defeats the vast majority of BEC wire transfer fraud, because the attacker who has compromised or spoofed an email account almost never also controls the real phone line of the person they're impersonating.
What Canadian resources exist for reporting or preventing spear phishing and BEC fraud?
The Canadian Anti-Fraud Centre is the national body for reporting BEC and wire fraud incidents. The Canadian Centre for Cyber Security publishes guidance on phishing and email security specific to Canadian organizations. The Business Development Bank of Canada (BDC) offers cybersecurity assessment resources and financing that can support awareness training. The Office of the Privacy Commissioner of Canada (OPC) provides guidance relevant if a spear phishing incident results in a personal information breach requiring notification under Canadian privacy law.

Ready to Build a Real Defense Against Targeted Attacks?

IT Cares helps Canadian businesses train employees, build a working reporting culture, and put the right technical controls in place — before a targeted attack tests them for real.

Comments (3)

JP
Julie P., Sherbrooke
July 24, 2026

The vendor invoice scenario is exactly what almost got us last spring. Now every banking change gets a phone call, no exceptions, regardless of how legitimate the email looks.

RD
Ryan D., Calgary
July 23, 2026

Forwarded this to our whole finance team. The comparison table made it click for people who thought "we already do phishing training" was enough — spear phishing is a different animal entirely.

MT
Melissa T., Fredericton
July 22, 2026

The out-of-band verification point is so simple but nobody had ever actually written it down as a real policy at our office until now. Doing that this week.

Leave a Comment

Need Help?