I have spent more than twenty five years in network security, the last fifteen of them running a managed IT firm here in Central Florida. Plenty of technology has come and gone in that stretch. The one attack that has never stopped working is an email from somebody your team already trusts.
Most owners I sit down with believe phishing is handled. They bought a filter, they run the training, and their front desk can spot a fake Netflix receipt from across the room. Then one Tuesday the bookkeeper wires $47,000 to a vendor that never asked for it, and nobody can explain how it happened, because the email that caused it did not look like phishing at all.
That gap is the whole subject of this article. Regular phishing and spear phishing get lumped together because they share a word, but they are different businesses with different economics, and the controls that stop one do very little against the other.
Two emails, same inbox, same Tuesday
The first email says your Microsoft password expires in twenty four hours and asks you to click a button. It came from a domain registered nine days ago. Four hundred other people in Seminole County got the same message. Your filter quarantined it before anyone saw it, which is exactly what you pay it to do.
The second email reaches your office manager at 4:40 on a Friday. It is from your practice owner, or your managing partner, or the supply rep you have used for six years. It references the order you actually placed last week and uses the nickname only people inside the office use. The bank flagged an issue with the old account, it says, so please update the remittance details before the weekend. No link. No attachment. Clean grammar.
The first is phishing. The second is spear phishing. Your filter is excellent at the first one and structurally weak against the second, and it is worth understanding exactly why before you spend another dollar.
What actually separates spear phishing from regular phishing
If you only remember one line from this article, make it this one: the difference is not sophistication, it is economics.
| Regular phishing | Spear phishing | |
|---|---|---|
| Targeting | Anyone with an email address | A named person, chosen on purpose |
| Volume | Millions of identical messages | One message, sometimes a handful |
| Research | None | Hours of it, from public sources |
| Payload | Malicious link or attachment, almost always | Often nothing but plain text |
| Sender | Throwaway domain or spoofed address | Lookalike domain, or a real mailbox the attacker already controls |
| Goal | Credentials, or a malware install | A wire transfer, a payroll change, a patient or client file, a password reset |
| What stops it | Your spam filter, quietly, all day | Process, identity controls, and a person who slows down |
Regular phishing is a volume business. The attacker sends ten million messages, expects a fraction of a percent to convert, and does not care who you are. Everything about that model, the reused templates, the throwaway domains, the identical links, leaves fingerprints a filter can learn.
Spear phishing is a labor business. The attacker spends real hours on one target because the payout justifies it, and nothing in that message is reused, so there is nothing for a reputation engine to recognize. That is not a product failure. It is a different problem needing a different class of control. We went through what the filter does and does not catch in Email Filtering for Small Businesses.
The numbers an owner should actually care about
I am careful with statistics here, because cybersecurity marketing is full of numbers that trace back to nothing. These two sources you can open and check yourself.
The FBI Internet Crime Complaint Center logged 1,008,597 complaints in its 2025 Internet Crime Report and $20.877 billion in reported losses, a 26 percent jump over the prior year. Inside that report, two line items tell the story of this article.
- Phishing and spoofing: 191,561 complaints, $215,843,126 in reported losses. The most reported crime type by a wide margin.
- Business email compromise: 24,768 complaints, $3,046,598,558 in reported losses. Roughly one eighth the complaint volume, roughly fourteen times the money.
Do the division and the average reported loss per phishing complaint lands near $1,100. Per business email compromise complaint it lands near $123,000. Treat both as rough: these are averages of self reported losses, IC3 publishes no medians, and large outliers pull averages up. The ratio is the point, and it holds year after year. Mass phishing is a nuisance with a real cost. Targeted email fraud is the event that changes your year.
The 2026 Verizon Data Breach Investigations Report, which examined more than 22,000 confirmed breaches, adds the defensive half of the picture. The human element showed up in 62 percent of breaches. Social engineering was the third most common breach pattern at 16 percent. Credential abuse appeared somewhere in the chain of 39 percent of breaches.
The most useful thing in that report for a small business owner is a distinction the Verizon team drew deliberately this year. They separated phishing, which is a one way message sent at you, from pretexting, where the attacker is live on the other end of the thread building a believable scenario. Their point was blunt: the countermeasures for those two are not the same, and the phishing simulation program you already run does very little for the second one. If you want to see what that looks like on the ground, we walked through it in What Social Engineering Actually Looks Like Inside a Small Business.
Five reasons the targeted version gets through
1. There is often nothing to scan
Email security is built to inspect things. Links get detonated in a sandbox. Attachments get opened in a virtual machine. Domains get scored on age and reputation. A well built spear phishing email contains none of those. It is three sentences of plain English asking a human being to do something the human being is authorized to do. There is no verdict for a filter to render, because nothing in the message is technically malicious.
2. The infrastructure is often legitimate
The most effective version of this attack does not spoof anyone. The attacker already holds a real mailbox belonging to a vendor, a title company, a referring practice, or a co counsel firm compromised weeks earlier. The message passes SPF, DKIM, and DMARC because it genuinely is from that domain, and it lands inside an existing thread with correct history below it. Verizon found 48 percent of breaches now involve a third party somewhere in the chain. Your controls end at your perimeter. The attacker starts inside someone else’s.
3. The research is free and it is public
People assume this kind of targeting requires a nation state. It does not. Your Florida corporate filings and registered agent sit on Sunbiz. Attorney names and bar numbers are in the Florida Bar directory. Providers and practice affiliations are in the NPI registry. Your staff list, titles, and email format are on your own website. LinkedIn supplies who reports to whom, and an out of office reply announces that the owner is away until Monday and names whoever is covering. That is a complete attack brief, assembled in an afternoon, for free.
4. It arrives at the exact right moment
Timing is the tell most people miss. The fraudulent wire instruction shows up the week of a real closing. The payroll change lands two days before the pay run. The gift card request goes out while the owner is genuinely at a conference. That is not luck. It means somebody has been reading a mailbox, yours or a partner’s, and is waiting for the moment when verification is inconvenient.
5. The old warning signs are gone
For fifteen years we taught staff to look for broken English and clumsy formatting. Generative AI killed that advice. The Verizon team joked in this year’s report that the guidance needs updating from counting typos to spotting the punctuation habits of AI writing tools, and the joke has a serious edge: training that leans on spelling teaches people to trust exactly the messages that are most dangerous.
The FBI logged 22,364 complaints carrying an artificial intelligence descriptor in 2025, with $893 million in associated losses, the first year it tracked the category. Verizon separately found click rates on mobile vectors like voice and text running about 40 percent higher than on email. The pressure is moving toward the channels where your people are least able to verify.
Where whaling, BEC, and vishing fit
The vocabulary gets messy. Short version:
- Spear phishing is any targeted message aimed at a specific person or a small named group.
- Whaling is spear phishing aimed at the top of the org chart, the owner, the managing partner, the CFO. Same technique, bigger target.
- Business email compromise is the monetized outcome. The FBI defines it as a scam targeting businesses that perform wire transfers, carried out by compromising email or other communications to move funds without authorization. Most BEC starts as spear phishing.
- Vishing and smishing are the same play delivered by phone or text, increasingly paired with a cloned voice.
These are not four problems. They are one problem wearing different clothes, and the controls below address all of them.
The controls that actually stop it
Ranked by how much risk they remove per dollar for a business in the fifteen to seventy five person range. This is the order I deploy them in.
1. Phishing resistant multifactor authentication on email and remote access
Most targeted attacks either start with or end in a mailbox takeover. Multifactor authentication is the single highest value control you can buy, but not all of it is equal. Attackers routinely defeat SMS codes and app push approvals using adversary in the middle proxies that relay the real login page and steal the session token. CISA is explicit in its phishing resistant MFA fact sheet that FIDO and WebAuthn based authenticators, meaning hardware security keys and platform passkeys, are the gold standard, and that number matching on push is an interim step, not a destination.
Start with the accounts that can move money or touch protected records: owners, partners, billing, payroll, and anyone with administrative rights. Verizon found 37 percent of organizations had at least one admin account with multifactor authentication disabled entirely. Check yours before you assume. This is the same identity layer we made the case for in Identity Is the New Perimeter.
2. Conditional access and session protection
A stolen session token is worth as much as a password. Block legacy authentication protocols, restrict sign in to expected locations and compliant devices, shorten session lifetimes for privileged accounts, and enable token protection where licensing allows. This layer turns a successful credential theft into a failed login instead of a six week silent occupation of a mailbox.
3. A written out of band verification rule for money and data
This is the control that actually stops business email compromise, and it costs nothing but discipline. The rule, in plain language: no payment instruction, no banking change, no payroll update, and no bulk release of client or patient records is ever executed based on email alone.
- Verification is a phone call to a number already on file, never a number in the message and never a number in an email signature.
- Vendor banking changes require a callback to a known contact plus a second approver inside your firm.
- Any wire above a threshold you set requires two people, and the second person is empowered to say no to the owner.
- The rule is written down, it is part of onboarding, and it applies to the owner too. Attackers count on hierarchy suppressing the callback.
I have watched this one rule stop six figure losses at practices with far less technology than their competitors, and watched its absence cost a firm a closing. It is the highest return item on this list.
4. Turn on the impersonation protection you are already paying for
If you run Microsoft 365, a meaningful part of the defense against targeted mail is licensed and switched off. Microsoft’s own documentation notes that the default anti phishing policy provides spoof protection and mailbox intelligence, but the user impersonation and domain impersonation features are not configured out of the box. Someone has to go turn them on.
- Add your owners, partners, billing staff, and top vendor contacts to the protected users list so display name impersonation is caught.
- Protect your own domains and your highest volume partner domains against lookalikes.
- Enable mailbox intelligence and set impersonation detections to quarantine rather than to a warning tip.
- Turn on external sender tagging and first contact safety tips, so a first time sender is visually obvious.
None of this is a purchase. It is an afternoon of configuration that most small businesses never get around to, usually because nobody owns the tenant. That ownership gap is the same one we described in Microsoft 365 and Google Workspace Management.
5. Mailbox auditing, forwarding alerts, and somewhere for the alert to go
When an attacker takes a mailbox, the first move is quiet persistence: an inbox rule filing anything containing the word invoice into a folder nobody checks, or an auto forward to an outside address. Alert on inbox rule creation, new forwarding, impossible travel, and mass mailbox access. Then answer the harder question: who reads that alert at 9pm on a Saturday. An alert with no human attached is a log entry, not a control.
6. Lookalike domain monitoring and email authentication at enforcement
Publish SPF, DKIM, and DMARC, and move DMARC to an enforcement policy instead of leaving it in monitoring mode forever. We covered how to get there in How to Stop Someone From Sending Email in Your Company’s Name. Then be honest about what that buys: it stops mail claiming to be from your exact domain. It does nothing about a lookalike domain one character off, and nothing about a genuine mailbox at a compromised vendor. Watch for registrations that resemble yours.
7. Make reporting fast, easy, and blameless
Some targeted mail will reach your people no matter what you buy. Verizon’s advice is the right advice: assume it, and make it painless for somebody to tell you when they clicked, so you can contain the damage before it escalates. A one click report button in Outlook, a named person to call, and a culture where nobody gets humiliated for raising a hand will shorten your response time more than another appliance will.
8. Know your bank recall path before you need it
If a fraudulent wire goes out, the first hour matters more than everything else. The FBI’s Recovery Asset Team initiated 3,900 kill chain actions in 2025 against roughly $1.16 billion in attempted theft and froze $679 million of it, a 58 percent success rate, but only when victims moved immediately. Write down now who at your bank you call, what your institution requires, and that a complaint goes to ic3.gov the same day.
What none of this fixes
Honest tradeoffs, because you will not hear these from a vendor pitch deck.
- Verification rules add friction. Some vendors will find the callback annoying. A partner will occasionally be irritated that their own request got checked. That is the cost, and it is worth paying.
- Hardware keys and passkeys require a rollout, a lost key procedure, and a break glass account that is protected differently. They are not a checkbox.
- No configuration stops a compromised vendor mailbox from sending you a technically legitimate email. Your process is the only defense in that scenario, not your filter.
- Impersonation protection tuned aggressively will quarantine legitimate mail. Somebody has to review quarantine regularly or the complaints will push you into loosening it.
- Training helps and it plateaus. It does not survive a well researched message arriving at a plausible moment from a real account. Treat it as one layer, never the layer. We looked at the honest return on that spend in Does Employee Cybersecurity Training Actually Work?
What this looks like in a practice and in a firm
For a medical or dental practice, the exposure is not only the money. One compromised mailbox holding patient communications is potentially a reportable breach of protected health information, which triggers HIPAA notification obligations, generally without unreasonable delay and no later than sixty days from discovery. The wire fraud is expensive. The notification letters, the OCR reporting, and the conversation with your patients are expensive in a different way. Item one matters most here, because a mailbox that cannot be taken over is a breach that never happens. It is also why we argue that HIPAA compliance is not a binder.
For a law firm, the exposure is client funds and timing. Closings, settlement disbursements, and trust account activity all carry a visible date and a predictable beneficiary, which is exactly what a patient attacker waits for. The FBI recorded $275 million in reported real estate fraud losses in 2025, much of it fraudulent wire instructions delivered at closing. Legal services was also the most frequently reported non critical sector in IC3’s ransomware complaints. Item three, the verification rule, applied to every disbursement without exception, matters most here.
Why I have skin in this game
I should be direct about my own interest. Harmony MSP sells managed IT and security services, and several of the controls above are things my firm deploys and gets paid to manage. That is the business I am in, and you should weigh this article accordingly.
I will also tell you that the highest value item on the list, the written verification rule for money and data, requires no product, no license, and no vendor. You can implement it tomorrow morning at a staff meeting and I make nothing from it. It sits at number three only because identity controls prevent the mailbox takeover that makes most of these attacks possible. If you do nothing else after reading this, do that one.
Where to start this week
- Pull a list of every account with administrative rights and confirm multifactor authentication is on every one of them.
- Open your Microsoft 365 anti phishing policy and check whether user and domain impersonation protection are actually configured.
- Write the verification rule on one page, brief the staff, and tell them explicitly that it applies to requests that appear to come from you.
- Turn on alerting for new inbox rules and new mail forwarding, and decide who receives the alert.
- Put your bank’s fraud contact and ic3.gov on the same page as the verification rule.
Frequently asked questions
What is the difference between phishing and spear phishing?
Regular phishing is a mass campaign sent to anyone, built around a malicious link or attachment, and it is what your spam filter is designed to catch. Spear phishing is a researched message aimed at a specific person, often containing no link or attachment at all, which means there is nothing technically malicious for a filter to score. The difference is not sophistication, it is economics: volume versus labor.
Why does spear phishing get past email filters?
Three reasons. There is frequently no payload to inspect, the message often comes from a genuine mailbox at a compromised vendor so it passes SPF, DKIM, and DMARC, and nothing about it is reused, so reputation and pattern matching have nothing to recognize. Filters remove the noise. They do not remove the need for a verification process around money.
Is spear phishing the same as whaling?
Whaling is a subset of spear phishing aimed at senior people, typically the owner, managing partner, or finance lead. The technique is identical. The target and the potential payout are larger.
Does multifactor authentication stop spear phishing?
It stops the mailbox takeover that most targeted attacks depend on, but only if it is the right kind. SMS codes and app push approvals can be relayed by adversary in the middle proxies. CISA recommends FIDO and WebAuthn authenticators, meaning hardware keys or passkeys, as the phishing resistant standard.
What is the single most effective control against business email compromise?
A written rule that no payment instruction, banking change, or payroll update is executed on email alone, verified by a callback to a number already on file. It costs nothing, and it covers the exact scenario where every technical control is correctly silent.
If you want a second set of eyes
If you are reading this and quietly realizing you are not sure whether impersonation protection is configured in your tenant, or whether anyone would notice a forwarding rule appearing on your billing manager’s mailbox, that uncertainty is worth resolving. It usually takes less than an hour to find out.
We are based in Lake Mary and we work with small businesses, law firms, and medical and dental practices across Central Florida. If you want a straight answer about where your email and identity controls actually stand, call us at (407) 720-6540. No pressure, no pitch deck, just a conversation.
Sources
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report
- FBI press release on the 2025 Internet Crime Report
- Verizon 2026 Data Breach Investigations Report
- CISA, Implementing Phishing Resistant MFA
- CISA, multifactor authentication guidance
- Microsoft Learn, Anti phishing policies in Microsoft 365
- HHS, HIPAA Breach Notification Rule
A note on statistics: complaint counts and dollar figures come directly from the FBI IC3 annual report. Percentages come directly from the Verizon DBIR. The per complaint averages are our own arithmetic on IC3 totals and are labeled as such. We have deliberately excluded secondary source figures we could not trace to a primary document.



