Spear phishing describes the practice of targeting specific individuals within an organization or business for the purpose of distributing malware or extracting sensitive information. As reflected in this year’s Internet Organized Crime Threat Assessment (IOCTA), spear phishing is the number one attack vector for the vast majority of cybercrime.
The report is the result of a two-day meeting with the European Cybercrime Centre’s 70 key partners, from internet, telecommunications and financial services. The joint advisory group meeting brought together industry and law enforcement representatives at Europol’s headquarters in The Hague to discuss what can be done to help mitigate this type of crime.

The report highlights the role of spear phishing as a primary attack vector for cybercriminals and defines the main modifications that criminals to deceive the target (including emails originating from trusted accounts, malicious attachments or links to fraudulent websites).
Furthermore, the document compiles conclusions and recommendations for organizations on how to effectively combat this threat at a technical, educational and operational level – enforcing security policies, implementing artificial intelligence and raising public awareness on the issue.
At the same time, the report highlights some of the challenges associated with sharing information and investigating spear phishing attacks. A collaborative effort with law enforcement and the private sector must be done collectively.
Steven Wilson, Head of Europol's European Cybercrime Centre, said: “Spear phishing is a major enabler of some of the most serious forms of cybercrime, particularly ransomware, and can cause real harm to European citizens and organisations.
“We can only effectively address a threat of this scale by working closely with key partners from across the industry. The EC3 Advisory Groups and this report reflect our ongoing collaboration to address the threat from cybercrime.”
