Avatier

Phished or stolen credentials

Spear phishing

Spear phishing is a phishing attack aimed at a specific person or small group, written with details about the target's job, contacts or interests. The message often appears to come from someone the target knows. Its goal is usually to steal login credentials, deliver malware or start a conversation that leads to either.

How it works

The attacker researches the target through social media, company websites and earlier contact, then writes a message that fits the target's real work, such as a document to review or an event invitation. Because the lure looks personal and expected, the target is more likely to open the link and enter credentials on a fake sign-in page.

A real example

In December 2023 CISA and international partners reported that the Russia-based actor Star Blizzard continued to use spearphishing against targeted organizations and individuals in the UK and other areas of interest, creating email accounts that impersonated the targets' known contacts.

Source: Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spearphishing Campaigns (AA23-341A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-12-07

The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Use phishing-resistant MFA so captured passwords cannot be replayed, and alert on sign-ins from new devices or locations for accounts that hold sensitive data.

Related terms

Threat actors that use it

  • Akira

    Profile with government sources

  • Black Basta

    Profile with government sources

  • LockBit

    Profile with government sources

Sources

  1. Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spearphishing Campaigns (AA23-341A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-12-07

Last reviewed Oct 2, 2026