How Attackers Research Targets Before a Spear Phishing Campaign

In this blog

how spear phishing works

By the time a spear phishing email lands in someone’s inbox, the attacker has often already spent hours, sometimes just minutes with AI tools, learning who that person reports to, what project they are working on, which software their team uses, and how their CEO writes an internal announcement. None of that research touches a company network. None of it triggers a security alert. It happens entirely in public, using information organizations and employees post about themselves.

This guide walks through what attackers actually look for before building a spear phishing message, where they find it, how AI has changed the speed of that process, and what organizations can realistically do to reduce their exposed footprint.

In Short

Spear phishing reconnaissance uses publicly available information, called OSINT, to build a profile detailed enough to make a fake message feel routine. Understanding what attackers collect and where they find it is the first step to reducing how much material they have to work with.

What Attackers Actually Collect

Reconnaissance for a spear phishing campaign typically pulls from a predictable set of public sources, each contributing a different piece of the profile.

LinkedIn

LinkedIn is the primary tool for mapping an organization’s structure: who reports to whom, recent promotions, new hires, and job changes. A new CFO announcement becomes a trigger for finance-themed lures. A newly hired IT director becomes an opportunity for a credential-reset pretext.

Company Websites and Press Releases

Company websites and press releases reveal vendor relationships, technology partnerships, and recent announcements. A press release about a new acquisition or partnership becomes the exact plausible cover story for an “updated payment instructions” email.

Job Postings

Job postings quietly disclose an organization’s technology stack. A listing requiring experience with a specific security platform or cloud provider tells an attacker precisely which brand of impersonation email will look familiar to that team.

Employee Social Media Activity

Employee social media activity, including posts about projects, conferences, or even a recent vacation, supplies the small, specific details attackers use as what researchers call trust anchors, fragments of information that make a fabricated message feel personally relevant rather than generic.

Breach and Credential Databases

Breach and credential databases may surface previously exposed email addresses or passwords, giving attackers a starting point even before any targeted research begins.

None of these sources require hacking. They require reading. That is precisely what makes this phase invisible to technical security controls.

What Attackers Actually Collect

AI Has Compressed the Research Timeline

What used to take a skilled attacker hours or days of manual searching now takes minutes. Research from Trend Micro’s AI security research division documents how generative AI tools now turn public LinkedIn content, posts, images, and metadata into machine-readable intelligence that can be automatically enriched and ranked, allowing attackers to build a usable target profile and a tailored message from raw LinkedIn data in a fraction of the time manual research once required.

This shift matters for two reasons.

  1. First, it means reconnaissance is no longer a meaningful bottleneck limiting how many targets an attacker can pursue with genuinely personalized messages, a constraint that used to make quality spear phishing rare.
  2. Second, it means the volume of convincing, individually researched attacks an organization faces is likely to keep increasing, not because attackers are working harder, but because the tooling does the work for them.

How This Research Becomes an Attack

The profile an attacker builds does not stay as a spreadsheet of facts. It gets converted into a specific pretext, timed for maximum effect. A few patterns show up repeatedly:

A recently announced acquisition becomes a request to update payment details for a “new vendor” involved in the deal.

A newly promoted manager becomes the sender of a fake “welcome to the team” email carrying a malicious attachment.

A public conference appearance by an executive becomes the moment an attacker impersonates them, knowing they are traveling and harder to reach for verification.

A team’s public technology stack becomes the basis for a fake internal tool notification, styled to match software the target actually uses daily.

The research phase and the delivery phase are not separate concerns. The quality of the reconnaissance directly determines how convincing the eventual message will be, which is why spear phishing consistently outperforms generic phishing despite far lower volume. For more on how this plays out at the executive level specifically, see our guide on whaling attacks and why senior leaders require a different training approach, and for the broader picture of how organizations can test for this, our guide on spear phishing training covers how to build realistic, research-informed simulations.

How to Reduce What Attackers Can Find

Organizations cannot eliminate their public footprint, and trying to do so is neither realistic nor good for business. But a few practical steps meaningfully reduce the raw material available to an attacker:

Review Job Postings

Review what job postings disclose. Listing “5 years with CrowdStrike Falcon and Splunk required” tells attackers exactly what your security stack looks like. General skill requirements achieve the same hiring goal with far less exposure.

Set Clear Guidance

Set clear guidance on what employees share publicly, particularly around project names, client relationships, and travel plans, without discouraging normal professional use of platforms like LinkedIn.

Use Public Announcements as Training Triggers

Treat major public announcements as a training trigger. A new executive hire, an acquisition, or a funding announcement is a predictable moment when targeted attacks spike, and it is a good time to remind the specific teams involved to expect and verify unusual requests.

Verify Through a Trusted Channel

Encourage independent verification as a default habit, not just a policy line. As CISA’s guidance on recognizing phishing emphasizes, verifying a request through a separate, trusted channel remains one of the most effective defenses regardless of how well-researched the original message appears.

The goal is not to disappear from the internet. It is to make an attacker’s research take longer and produce a thinner, less convincing profile, buying employees more time to notice something feels slightly off.

Why This Matters for Testing, Not Just Awareness

Understanding the reconnaissance process changes what a useful phishing test actually looks like. A generic simulated phishing email tests whether someone clicks a suspicious link. A simulation built the way a real attacker would build it, referencing a plausible internal detail, timed around a real organizational event, tests something closer to reality.

Tracking how employees respond to well-researched versus generic simulated attempts, and feeding that into an employee phishing risk score , gives a far more honest picture of actual organizational exposure than click-rate data from generic templates alone.

Final Thoughts

The most dangerous part of a spear phishing attack often happens before anyone sees a single message. It happens quietly, in public, using information organizations and employees have already shared. Understanding exactly what that research looks like is not about becoming paranoid online. It is about recognizing that the personalization making an attack convincing did not come from luck. It came from a process that can be understood, anticipated, and at least partially defended against.

Frequently Asked Questions

What is OSINT in the context of phishing?

OSINT, or open-source intelligence, refers to publicly available information, such as LinkedIn profiles, company websites, press releases, and job postings, that attackers use to research a target before building a personalized spear phishing message.

How long does it take an attacker to research a target?

This has changed significantly with AI. What once took hours or days of manual research can now take a matter of minutes using AI tools that automatically process public LinkedIn content and other data sources into a usable target profile.

What information do attackers look for on LinkedIn?

Attackers typically map organizational hierarchy, reporting structures, recent job changes and promotions, and project or technology mentions, all of which help build a profile detailed enough to craft a convincing, personalized message.

Can an organization stop attackers from researching it?

Not entirely, since most of this information is inherently public and often necessary for normal business operations. Organizations can meaningfully reduce their exposure by limiting unnecessary detail in job postings and public communications, without trying to eliminate their online presence altogether.

Does understanding reconnaissance actually improve phishing defense?

Yes. Simulated phishing tests built the way a real attacker would build them, using realistic, research-informed pretexts rather than generic templates, produce a far more accurate picture of how employees would respond to an actual targeted attack.

Content Reviewed By

Mohammed Nawaz Sajjad, Sr. Security Analyst at PhishCare
Mohammed Nawaz Sajjad
Sr. Security Analyst at CyberSapiens | Phishing Simulation | Ethical Hacker | Bug Hunter | Red Team

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking.

He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.

View LinkedIn Profile

Ready to Test Real-World Phishing Readiness?

Understanding how attackers research your organization is the first step. Testing whether your employees would actually recognize a well-researched attempt is the next one. See how realistic, targeted phishing simulation works with a free PhishCare demo account, no credit card required.