Skip to content
English
  • There are no suggestions because the search field is empty.

What is spear phishing, watering holes, and evil twin attacks?

What are spear phishing, watering hole and evil twin attacks?

Spear phishing, watering hole and evil twin attacks are cyberattacks that trick people into handing over login credentials, financial information or access to company systems. All three work by imitating something you trust, whether a colleague, a familiar website or a Wi-Fi network. That makes them hard to spot, even for experienced technology users.

These attacks are a particular risk for financial firms, which regularly exchange payments, account details and sensitive information with clients and vendors. The good news: a combination of clear processes, employee training and the right security tools greatly reduces the risk.

Spear phishing

What it is: regular phishing sends the same fake message to thousands of people. Spear phishing is targeted: the attacker researches a specific person or company, then sends a personalized message that appears to come from someone they trust, such as a colleague, executive, vendor or client.

Attackers gather details from LinkedIn, company websites and social media to make their messages convincing. Their goal is usually to:

  • Steal login credentials through a fake sign-in page.
  • Redirect payments, for example by asking finance staff to wire money or update a vendor's bank details.
  • Install malware through a link or attachment.

Related terms:

  • Business email compromise (BEC) or CEO fraud: an attacker poses as an executive or vendor to request a payment or sensitive data. BEC is one of the costliest cybercrimes. The FBI received nearly 25,000 BEC complaints in 2025, with over $3 billion in reported losses.
  • Whaling: spear phishing aimed at senior executives.
  • Smishing and vishing: the same tactics by text message (smishing) or phone call (vishing).

Why it's getting harder to spot: attackers now use AI to write polished, error-free messages, and even to fake a familiar person's voice or video on a call. Spotting typos is no longer enough. Verifying unusual requests is the most reliable defense.

Real-world example: in 2016, a finance employee at wire manufacturer Leoni AG transferred about €40 million (roughly $44 million) after receiving emails that appeared to come from company executives.

How to protect your organization:

  • Verify payment and banking requests. Confirm any request to send money or change bank details by calling the person at a phone number you already have, never one in the email.
  • Turn on multi-factor authentication (MFA) for email and key systems. Phishing-resistant options, such as passkeys or hardware security keys, are strongest.
  • Train employees regularly, and run phishing simulation tests.
  • Make it easy to report suspicious emails, and never punish people for reporting.
  • Tag external emails with an "External" label.
  • Protect your email domain. Set up SPF, DKIM and DMARC so attackers can't easily send email pretending to be your company.
  • Keep software updated and use email filtering and endpoint protection.

Tips for individuals:

  • Be cautious of messages that are urgent, secretive, or ask for money or credentials, even from someone you know.
  • Go directly to websites by typing the address, rather than clicking links in messages.
  • Never share your password or MFA codes with anyone.
  • Use a password manager and unique passwords for each account.
  • Limit the personal and job details you share publicly online.

Watering hole attacks

What it is: named after predators waiting at a watering hole for their prey, this attack targets a group rather than an individual. Attackers identify websites a certain group visits often, such as an industry association, news site or vendor portal. They compromise that website with malware, which then infects visitors' devices and can give the attacker access to their organizations' networks.

How to protect your organization:

  • Keep browsers, operating systems and plugins updated to close the security gaps these attacks exploit.
  • Use web filtering or secure web gateway tools that block known malicious websites.
  • Use endpoint protection with behavior-based threat detection that can catch unusual activity.
  • Limit administrator rights on employee devices, so malware can't easily install itself.

If you run a website: your own site could be used as a watering hole. Keeping WordPress, plugins and themes updated, and using a website firewall, helps prevent your site from being compromised and used to attack your visitors.

Evil twin attacks

What it is: an attacker sets up a fake Wi-Fi network with the same name as a legitimate one, such as a coffee shop, hotel, airport or conference network. When people connect, the attacker can monitor their activity, show fake login pages to steal credentials, or try to install malware. Attackers may even disrupt the real network so devices reconnect to the fake one.

How to protect your organization:

  • Use a VPN whenever connecting to public or shared Wi-Fi.
  • Use your phone's hotspot instead of public Wi-Fi for work tasks.
  • Turn off automatic Wi-Fi connections on laptops and phones.
  • Check for HTTPS (the padlock) and never enter credentials on a site showing security warnings.
  • Use MFA, ideally passkeys or security keys, so stolen passwords alone aren't enough.
  • For company networks, use wireless intrusion prevention to detect fake access points.

The bottom line

All three attacks rely on tricking people into trusting something fake. The strongest protection combines:

  • Processes, such as verifying payment requests.
  • Training, so employees know what to look for.
  • Technology, such as MFA, email authentication, updates, filtering and VPNs.

Need help strengthening your security? Contact the Gate 39 team through the Customer portal.

 

 References
[1] Bitdefender – Leoni loses €40m in email impersonation scam (Aug 31, 2016)
[2] Tripwire – $44 Million Email Scam
[3] ZeusNews / Softpedia – Leoni falls victim to BEC scam
[4] McDonald Hopkins – The FBI's 2025 IC3 Report