What is targeted phishing (spear phishing)
Unlike mass phishing, spear phishing targets specific individuals within an organisation. The attacker researches the victim (using LinkedIn, the company website, social media) to personalise the email: mentioning the boss’s name, the current project, or an internal tool you use.
For an SME, this is especially dangerous: teams are small, roles overlap, and trust between colleagues is high. An email saying “Hi Maria, client X asked for CRM access credentials” can go unnoticed in a team of 15 people.
Signs an email is phishing
- Urgency or pressure: “Your account expires in 24 hours” or “Access now or data will be lost”.
- Generic greeting: “Dear user” instead of your real name.
- Suspicious sender: the email looks official but the domain has a typo (rnulstrata.com instead of nullstrata.com).
- Unusual data requests or actions: they ask for credentials, to download a file, or to make a transfer.
- Spelling or design errors: distorted logos, wrong colours, links that do not match the displayed domain on hover.
- Unexpected attachment: a PDF or invoice you did not request.
What to do if an employee falls for phishing
The most important thing: do not panic and do not punish the employee. The goal is to contain the damage. This is the concrete protocol:
- Isolate the device: disconnect the machine from the network if you suspect communication with an external server. Do not shut it down — if a keylogger is active, powering off can destroy the evidence.
- Change credentials: if a password was compromised, change it immediately everywhere it was reused.
- Review access: check for unknown active sessions in your services (Google Workspace, Microsoft 365, online banking, CRM).
- Contact the bank if transfers were made: fraudulent transfers have a very short recovery window (up to 13 months for consumers, less for businesses).
- Notify the AEPD if personal data was compromised (deadline: 72 hours from becoming aware of the incident, art. 33 GDPR).
A typical case in this modality is impersonation of utility companies (electricity, gas, telecoms): an email with the subject “Final notice: your supply will be interrupted” that includes a link to a website mimicking the customer portal and asks for login credentials. The urgency of the situation — a service cut — blocks critical thinking. These campaigns are seasonal and intensify around billing periods.
Another frequent case is impersonation of the Tax Agency during tax season. An email with the subject “Your tax refund is pending” leads to a form that collects bank details. AEPD and the Tax Agency publish public warnings every year about this scheme, but employees without specific training still fall for it.
Training: the best defense
Technology helps (email filters, MFA, adaptive authentication), but the human factor remains the first line of defence. Well-designed security awareness training reduces phishing click rates from 30% to 5% in six months. These are the practices we see work in Spanish SMEs:
- Quarterly simulations: send internal test emails (ideally with a provider offering comparative metrics by sector) and measure click rates. Do not blame whoever clicks — use it as a signal to reinforce training for that person.
- Easy reporting channel: any employee should be able to report a suspicious email with one click. Outlook and Gmail have built-in “Report phishing” buttons; if your team uses a different client, create an address like phishing@yourcompany.es with an auto-reply.
- Continuous reinforcement: a once-a-year session is not enough. Send brief tips every two weeks: a real phishing example (anonymised), a quick rule, a reminder. Five minutes, not one hour.
- Security onboarding: include a phishing module in the training of any new employee, before they handle their first real invoice.
- Clear security policy: document in writing what to do in an incident and who is responsible. It should not depend on someone “knowing who to call”.
An illustrative example of this type of attack would be CEO fraud: the attacker impersonates a senior executive and requests an urgent transfer to a new supplier. The finance team executes the transfer because the email tone is consistent and the amount seems reasonable. SMEs are especially vulnerable because they often lack a formal out-of-band payment verification procedure. INCIBE documents this attack in its guide for businesses: attackers use OSINT to gather information about org charts and executives before launching a campaign. A simple procedure — confirming by phone any change of account or unusual transfer — would have stopped the attack.