Loading summary
A
You're listening to the Cyberwire Network powered by N2K. AI is making phishing attacks faster, more convincing, and harder for people to spot, and traditional security awareness and phishing training weren't designed for this level of attack. HOX Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's H O x h u n t.com cyberwire. You're listening to the Cyberwire network powered by N2K foreign. AI is transforming every industry, but it's also creating new risks that traditional frameworks can't keep up with. Assessments today are fragmented, overlapping, and often specific to industries, geographies or regulations. That's why Black kite created the BKGA3AI assessment framework to give cybersecurity and risk teams a unified, evolving standard for measuring AI risk across their own organizations and their vendors. AI use it's global, research driven, built to evolve with the threat landscape and free to use because Black Kite is committed to strengthening the entire cybersecurity community. Learn more@blackkite.com.
B
The word is spearfishing, Spelled spear for a specific target and fishing for the act of compromising victims. A type of cyber attack where an attacker sends a targeted and personalized email or other form of communication to a specific individual or a small group of individuals with the intention of tricking them into divulging sensitive information such as a password or convincing them to click a malicious link that will enable the attacker to take control of the victim's machine. Example Sentence Kevin, the fry chef in the company cafeteria became a victim to a spear phishing attack when he received an email that appeared to be from his boss requesting login credentials to the electronic cash register. Origin and context According to Russell Kay in the 19 January 2004 edition of Computer World, hackers may have started using the word phishing in the Alt 2600 Hacker News Group in January of 1996, but the term also might have arrived earlier from the print journal 2600 the Hacker Quarterly. According to Kay, hackers used email lures to hook digital fish for their American online passwords. They would blast phishing emails to everybody in the American online pool to see who would buy. It's unclear when hackers sent the first spear phishing email to target a specific user or a small group of users but according to Daniel Brecht at infoSec Online in 2015, people started to notice the attack technique when the news of the RSA security company breach in 2011 became public. The attack where the Chinese military used a spear phishing attack to establish a beachhead inside RSA security that eventually allow them to compromise the company's two factor authentication token product. Nerd reference. In 2013, the McKinsey Institute asked Tim Richardson, the University of Toronto management professor, about the difference between fishing and spearfishing.
C
So most people have heard of fishing spelled P H I s, fish H I n G. Let me just repeat why that slang word is used when you're actually standing on a dock and trying to fish. You can't see with laser vision where the fish actually are. So you cast your rod into water, reel it back in, cast your rod in the water, reel it back in, et cetera. So that's why it's a slang word used to describe a situation where you send out spam email to thousands of thousands of people saying, dear XX bank customer, please log into here because of a threat, et cetera, et cetera. They may or may not actually be a customer of that bank, but if you send out enough emails, you'll capture some people who are actually customers of the bank. Then if you have a large enough number, the percentage that will respond will be large enough that you could then engage them in some type of trickery to commit identity theft. But since so many people know about this, their percentage response rate is quite low. So what they're doing is spear phishing. Spear phishing is a slang expression to say instead of sending out a spam email to tens of thousands of people about XX bank, they'll send an email specifically to John smithoilbank in Aurora, because we know that you bought something at the New Market Store, et cetera, et cetera. And then please be aware of this opportunity. So log into the website before 5 o' clock today to check something, something, something. So those type of attacks are very successful because when people do receive that email, they say, well, this couldn't be a scam. It actually has my real name, it has something that I actually know I did. And there's a much higher response rate. At the same time, these attacks are being done by people in a very select way. They can't contact tens of thousands and try to do follow up. They just contact a few people and then they work the situation. These are with people that they get profile information about through social media. They find out some purchase that they did because they boast about it on Facebook or some other thing that they tweeted or they have a YouTube video talking about it so the response rate is much, much higher. And they do this with high net worth individuals in order to be able to make a lot of money because it's easier to rob rich people than poor people.
B
Wordnotes is written by Tim Nodar, executive produced by Peter Kilpe, and edited by John Pettrick and me, Rick Howard. The mixed sound, design and original music have all been crafted by the ridiculously talented Elliot Peltzman. Thanks for listening.
A
Most environments trust far more than they should, and attackers know it. ThreatLocker solves that by enforcing default deny at the point of execution. With Threat Locker allow listing, you stop unknown executables cold. With ring Fencing, you control how trusted applications behave. And with Threat Locker DAC defense against configurations, you get real assurance that your environment is free of misconfigurations and clear visibility into whether you meet compliance standards. ThreatLocker is the simplest way to enforce zero trust principles without the operational pain. It's powerful protection that gives CISOs real visibility, real control, and real peace of mind. ThreatLocker makes zero trust attainable even for small security teams. See why thousands of organizations choose ThreatLocker to minimize alert fatigue, stop ransomware at the source, and regain control over their environments. Schedule your demo at threatlocker today. Maybe that's an urgent email from your CEO, or maybe it's a deepfake targeting your business. Doppel is the AI native social engineering defense platform, fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Doppel uses it to fight back, automatically dismantling cross channel attacks, building team resilience and providing agentic email protection. Doppel outpacing what's next in social engineering? Learn more@doppel.com that'S-O-P P E L dot com.
Podcast by N2K Networks – August 11, 2026
Theme: Deception, influence, and social engineering in the world of cyber crime.
This episode of Hacking Humans focuses on the term spearphishing, delving into its definition, evolution, and significance in modern cybersecurity. Through clear explanations and expert commentary, the hosts unpack how spearphishing differs from traditional phishing and why it poses escalating threats in the age of pervasive digital information and advanced targeting, especially as enabled by AI.
This episode demystifies spearphishing by rooting the concept in real cybercrime tactics, tracing its evolution from mass phishing, and highlighting the sophistication and danger posed by attackers leveraging data and social engineering. Understanding spearphishing is crucial for anyone responsible for cybersecurity in a world where attacks are ever more targeted, convincing, and potentially devastating.