Key Takeaways
- Bulk phishing sends identical messages to millions; spear phishing is custom-built for a specific individual.
- Spear phishing relies on personal details gathered from social media and data breaches to appear credible.
- Both attack types can be resisted with the same core habits: verify senders, avoid clicking unexpected links, and use multi-factor authentication.
- Even tech-savvy users are vulnerable to spear phishing because the messages are deliberately hard to distinguish from legitimate ones.
- Recognising which type of attack you're facing helps you calibrate the right level of suspicion.
Option A
Bulk Phishing
The wide-net, high-volume mass campaign.
Best for: Understanding the everyday scam emails most people encounter — generic, impersonal, and sent in the millions.
Option B
Spear Phishing
The precise, personalised targeted attack.
Best for: Understanding sophisticated attacks crafted specifically for one individual, using real personal details to build false trust.
If you receive a vague, urgent email claiming your account is at risk
Bulk Phishing (recognition)
Generic urgency tactics and impersonal greetings are hallmarks of bulk campaigns. Go directly to the official site rather than clicking any link in the email.
If an email references your employer, recent activity, or a colleague by name
Spear Phishing (awareness)
Personal details signal a targeted attack. Verify through a separate, trusted channel before taking any action — even if the message looks legitimate.
If you want to protect yourself from both attack types
Both require the same defences
Multi-factor authentication, cautious link handling, and healthy scepticism toward unexpected requests are effective against bulk and targeted campaigns alike.
Two Very Different Playbooks
Not all phishing attacks are created equal. When most people imagine a phishing attempt, they picture a clumsy, mass-produced email warning that their password is about to expire or that a parcel is waiting for collection. That's bulk phishing — and it works by sheer volume. Attackers send tens of millions of near-identical messages, counting on a small percentage of recipients to click without thinking.
Spear phishing is something else entirely. Rather than casting a wide net, a spear phisher spends time researching a specific target — reading their LinkedIn profile, combing through social media, or drawing on details exposed in data breaches — then crafts a message that feels startlingly personal. For a broader foundation on how phishing works psychologically, see Phishing Attacks Explained.
| Criterion | Bulk Phishing | Spear Phishing |
|---|---|---|
| Target scope | Millions of random recipients | One specific individual or group |
| Personalisation | Generic, impersonal greeting | Uses real names, roles, or details |
| Attacker effort | Low — automated and mass-produced | High — requires prior research |
| Success rate per message | Very low (fraction of a percent) | Much higher per target |
| Ease of detection | Easier — common red flags present | Harder — red flags often removed |
| Common delivery method | Email, SMS blast | Email, sometimes voice or messaging apps |
| Primary defence | Recognise generic lure patterns | Verify via separate trusted channel |
How Attackers Prepare Each Type
Bulk phishing requires minimal preparation. Attackers purchase or compile large email lists, build a generic lure — often impersonating a bank, delivery service, or major tech platform — and automate delivery. The goal is throughput, not precision. The messages often contain subtle errors, but enough people overlook them that the campaign turns a profit.
Spear phishing demands real reconnaissance. An attacker might study your professional history, map your reporting relationships at work, note events you attended, or use details leaked in a previous breach to establish credibility. A message might reference a real project you're working on, a colleague's actual name, or a recent transaction. That groundwork is exactly why targeted attacks are so dangerous — and why even informed people fall for them.
~88%
Share of data breaches involving phishing
Phishing consistently ranks as a leading initial access vector in annual data breach investigations by security researchers.
3–5×
Higher click rate for targeted vs. bulk emails
Security awareness training research consistently shows personalised phishing simulations achieve significantly higher engagement than generic ones.
Spotting Each Attack in Practice
Bulk phishing messages tend to share recognisable patterns: generic greetings like "Dear Customer," mismatched sender domains, urgent language designed to suppress rational thought, and links that hover to reveal a suspicious URL. These signals aren't foolproof — attackers do improve — but they remain reliable starting points.
Spear phishing is harder to detect precisely because the attacker has removed most of those obvious red flags. The email may arrive from a spoofed address that looks nearly identical to a real one — differing by just one character. It may quote your real job title, your manager's name, or an internal company process. The strongest check you have is channel verification: if an unexpected request arrives by email, confirm it by phone or through a separate application before acting. Understanding how attackers collect the credentials they need to pull this off is covered in our guide on how attackers actually steal passwords.
It's also worth knowing that phishing isn't confined to email. Targeted attackers increasingly use SMS and voice calls — see Smishing, Vishing, and Phishing Compared for how those channels differ.
Defences That Work for Both
The good news is that the same core habits protect against both attack types. Multi-factor authentication (MFA) — requiring a second verification step beyond your password — significantly limits the damage even if an attacker captures your credentials. Pausing before clicking any link in an unsolicited message is effective against bulk campaigns. Verifying requests through a separate trusted channel is your best defence against targeted attacks.
Password hygiene matters too. Reusing passwords across accounts means a credential stolen via one phishing attack can be used to breach others — a technique called credential stuffing. Unique, strong passwords for each account close that door. For a complete starting point on avoiding online scams, the Consumer's Complete Starting Point covers the essential habits in one place.
What 'Whaling' Means in This Context
You may encounter the term 'whaling' — this is a subset of spear phishing aimed specifically at senior executives or high-value individuals within an organisation. The mechanics are the same as spear phishing, but the attacker invests even more research time and the potential payoff — access to financial systems or sensitive data — is correspondingly larger. The same verification habits apply.
