Spear phishing
A phishing attack aimed at one specific person, written using real details about them to make it credible.
Where bulk phishing is a net, spear phishing is a rifle. The attacker researches the target first, usually through LinkedIn, the company website, and previous breach data, then writes a message that references a real project, a real colleague, or a real vendor relationship.
The hit rate is far higher than bulk phishing, and the targets are chosen for access rather than seniority. Finance staff, executive assistants, and IT administrators are the usual picks, because each of them can move money or grant access without anyone thinking it unusual.
Where this comes up
Spear phishing sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.