The invoice looked right. Same supplier, same layout, same contact name in the signature block.
The only thing that changed was the bank account. But it came with an email explaining the change from an address your accounts payable officer had been corresponding with for two years.
This is called spear phishing, and it looks nothing like the emails your staff were trained to spot.
It is also a large part of why the average cost of cybercrime for a medium-sized Australian business climbed 55% in a single year to $97,200. Those figures come from ASD’s Annual Cyber Threat Report 2024-25, which also found that “business email compromise resulting in financial loss” made up 15% of cybercrime reports from Australian businesses. A further 19% reported email compromise that was caught before money moved.
Many organisations respond to this by investing in cyber threat/security awareness training for their team. It feels like the right answer, because the threat target is person. The problem is the evidence supporting training as an effective defence against attacks is not as strong as the industry sometimes suggest.
Here is what spear phishing actually is, why it works on capable and experienced people, and which controls stop it when training does not.
What is spear phishing?
Spear phishing is a targeted email attack written for one person or one small group, using details about them that make the message believable.
Where a generic phishing email is sent to thousands of addresses and hopes a fraction respond, a spear phishing email is built after research. The attacker knows your finance manager’s name, knows which suppliers you use, knows your director is at a conference in Singapore this week because it was posted on LinkedIn, and knows your invoice approval sits with one person. The message arrives referencing all of it.
How do spear phishing attacks differ from standard phishing?
The difference is economics, and it changes everything about how you defend against it.
Standard phishing is a volume business. The attacker sends a thousand emails, accepts a response rate below one per cent, and still profits. The emails are generic because personalisation does not scale. That is why they are often easy to spot: wrong logo, odd grammar, a greeting that says, “Dear Customer”.
Spear phishing is a labour business. The attacker spends hours or days on a single target because the payout justifies it. They read your website, your team page, your LinkedIn, your published tender documents. Then they write one email with no spelling errors, correct branding, the right internal terminology, and a request that is entirely ordinary.
Whaling is the same technique aimed specifically at directors and executives, where the authority attached to the sender does part of the persuasion for the attacker.
The practical consequence is that with spear phishing, every visual cue your staff are taught to look for in electronic communications have been removed on purpose.
How does spear phishing work?
A targeted attack usually runs through five stages:
- Reconnaissance: The attacker builds a picture of your organisation from public sources. Team pages, LinkedIn, ABN records, media releases, job ads that name your systems, and supplier logos on your website all contribute.
- Access or impersonation: Either the attacker compromises a real mailbox somewhere in the chain, often at a smaller supplier with weaker controls, or they register a domain that reads almost identically to a legitimate one. A capital I in place of a lowercase l is invisible in most email clients.
- Observation: If they have real mailbox access, they wait. They read months of correspondence and learn the tone, the approval process, the payment terms, and who chases whom. This is the stage that makes the eventual email so convincing, and it is also the stage most organisations never detect.
- The request: The email arrives at the right moment in an existing thread. Updated bank details before end of month. An urgent payment the director has approved verbally. A shared document that needs sign-in to view.
- Extraction: Funds move, or credentials are captured and used to repeat the process further down your supply chain. Attackers frequently create inbox rules that auto-delete replies, so the fraud stays hidden for weeks.
Why phishing training will not stop spear phishing
A 2025 study of more than 19,500 employees over eight months measured whether security awareness training and simulated phishing actually reduce failure rates.
Embedded training, the short lesson people get after failing a simulation, reduced failure rates by 1.7% against the control group. There was no correlation between how recently someone completed their annual training and whether they failed a phishing test: staff trained last month performed no better than staff more than a year overdue. By month eight, 56% of users had failed at least one simulation.
The engagement numbers explain a lot. Between 37% and 51% of training sessions lasted zero seconds. People opened the module and closed it. Only 15% to 24% were completed.
None of this means you should stop training staff. Awareness has a role, reporting culture matters, and some regulatory and insurance requirements make training mandatory. What it means is that training is a very thin layer to be standing behind on its own, and a well-researched spear phishing email will get through it. Design your defences on the assumption that someone will click, because eventually someone will.
How to avoid spear phishing
Every control below removes the attacker’s payoff rather than relying on the recipient spotting the trick:
- Deploy phishing-resistant multi-factor authentication: Number matching in Microsoft Authenticator, or hardware keys for finance and executive accounts. Block legacy authentication protocols, which bypass MFA entirely. MFA is also one of the ASD Essential Eight mitigation strategies, so this work counts twice if you are pursuing a maturity level.
- Write down a verification rule for payment changes: Any change to bank details is confirmed by phone, on a number already held in your accounting system, never a number contained in the email. Make it a documented step in the approval process rather than a matter of individual judgement.
- Make reporting easier than deleting: A one-click report button in Outlook, and a standing rule that nobody is ever criticised for reporting a legitimate email. The research found reminders and reporting did more good than testing people.
- Alert on mailbox rule creation and impossible travel: Attackers create forwarding and delete rules almost immediately after gaining access. Alerting on that behaviour catches the compromise during the observation stage, before the money moves.
- Apply dual approval above a dollar threshold: One person should not be able to move a large payment alone, regardless of who appears to have authorised it.
Most of this is configuration rather than expenditure, and much of it sits inside licences you already hold.
If you are not certain which of these controls are switched on across your environment, talk to us about a security review. We will tell you where the gaps are before someone else finds them.
Windstil provides cyber security consulting for Australian businesses. Our active clients enjoy a structured, ongoing approach to Essential Eight, with clear prioritisation, consistent progress and guidance to improve their maturity over time.
