The email lands at 4:42 on a Friday. It is from the Chief Medical Director of a Lagos hospital, or so it appears, and it goes straight to the finance officer. A vendor has to be paid today or the theatre equipment order falls through, the message says, and the CMD is in a meeting and cannot take calls. Account details are attached. Please treat as urgent and keep it discreet. Nothing about the email is broken. The name is right, the project is real, the tone matches how the boss actually writes. That is the whole point of spear phishing. The attacker did not send ten thousand of these. They sent one, to the person who can move the money, after reading enough of the hospital's website and LinkedIn to sound like family.
Ordinary phishing is a net thrown over a crowd. Spear phishing is a single line dropped in front of one fish that someone studied first.
// 01 How a Spear-Phishing Attack Unfolds
The reconnaissance is the work, and it is patient. Before a word of the email is written, the attacker reads the hospital's website, scrapes LinkedIn for who reports to whom, and notes the recent inventory drive or the new theatre wing that featured in a local paper. That detail is what makes the request believable. The email borrows the letterhead, names a real project, and then adds the one ingredient that overrides judgement: a deadline. "Immediate action required." "Settle before close of business or we lose the slot." Click the link and you either hand over a login on a page that looks exactly like the hospital portal, or you run an attachment that quietly installs malware. Either way the attacker now has what the finance officer has.
Here is where it stops being one email. With a valid login, the attacker moves sideways into the systems the account can reach. Sometimes that is the patient record system, where data can be copied or altered. Sometimes it is the file shares, which get encrypted and held for ransom. When the screens go dark, the ward falls back to paper, and a hospital running on paper at 2am is a hospital making mistakes it would not make otherwise. The money loss is the obvious harm. The quieter one is what happens after, when patients learn their records were exposed and the NDPC starts asking under the Nigeria Data Protection Act why the breach was possible. One Friday email, and the bill arrives in three currencies: cash, care, and trust.
// 02 Lessons Learned and Key Takeaways
- Treat urgency plus secrecy as the tell: a real CMD asking for a payment will survive a phone call to confirm it. The fraudster's whole game depends on you not making that call. So make it. Verify a payment instruction on a number you already had, not the one in the email, and never on the strength of pressure alone. Two genuine signatures rarely arrive with "keep this between us" attached.
- Put multi-factor authentication on anything that matters: with MFA on the email and the payment systems, a stolen password is no longer a stolen account, because the attacker still needs the second factor on the staff member's own phone. Patch and back up alongside it, so that if malware does land, the damage has a floor.
- Report the near misses, not just the hits: the email that someone nearly clicked is worth more as a teaching example than the one that got blocked silently. When staff report attempts without fear of blame, the next person recognises the pattern. OWASP's guidance on phishing-resistant controls makes the same point: the human who pauses is a control, and that control improves with practice.
Spear phishing works because it skips the firewall and goes to a person who is busy, trusted, and trying to be helpful. No tool catches all of it. What catches it is a finance officer who picks up the phone before moving the money, and an organisation that has told her, in advance and in writing, that doing so will never get her in trouble. Decide today who is allowed to authorise a payment, and what proof they must produce. The next urgent email is already being written.
- Urgency plus secrecy is the tell -- confirm any payment on a number you already had, never the one in the email.
- MFA turns a stolen password into nothing -- the attacker still needs the second factor on the staff member's own phone.
- Reward the near miss -- the email someone nearly clicked teaches the next person, but only if reporting it carries no blame.
- Shrink the recon surface -- every name and reporting line you publish is a sentence the attacker can borrow.
Could your staff spot a spear-phishing email?
We help healthcare organisations test their defences with realistic phishing simulations and targeted staff training.
Contact Us