What is Spear Phishing? Targeted Attacks on Defense Contractors

by Jordan Dean on Sep 23, 2026

email-envelope-on-a-fishing-hook-on-laptop-2026-03-24-08-02-57-utc

Most people picture phishing as the email that’s almost too obvious to be real. A surprise lottery win. An urgent password reset. A strange link from a company you have never heard of. Those attacks still exist, but the phishing attempts targeting the defense industrial base and other government contractors can look very different.

Spear phishing is deliberate. Attackers may research your company, your role, the people you work with, and the organizations you trust before they ever hit send. The message might appear to come from a colleague, supplier, executive, or government contact. It may reference a real project or use just enough familiar information to make clicking feel routine.

And if your company handles Controlled Unclassified Information (CUI), builds hardware for the Pentagon, or operates anywhere in the defense supply chain, you’re a particularly juicy target. You are not just another email address on a massive phishing list. Your access, relationships, and information can move you to the top of their list of targets, which is exactly why spear phishing deserves a closer look.

Spear Phishing vs. Phishing: What's the Difference?

Ordinary phishing is a numbers game. Attackers blast out generic, malicious messages to as many inboxes as possible, betting that a small percentage of recipients will click a bad link or hand over credentials. Spear phishing instead targets specific individuals with personalized deception, using personal details, company context, or role-specific information to make the attack more believable and harder to detect.

That personalization is what makes spear phishing so dangerous. An attacker who has spent time researching your program manager, contracting officer, facility security officer, or other key employees can create an email that feels surprisingly legitimate. Instead of just blasting a generic message, they can build it around information you recognize and trust.

That might include:

  • A real project, contract, or program
  • A vendor or partner your company actually works with
  • A colleague, executive, or government contact by name
  • A familiar request, document, or login page

Spear phishing now dominates high-value breaches, with an estimated 91% of successful breaches starting this way, and roughly 65% of attackers now favoring spear phishing as their primary method of attack, according to a 2026 security audit.

At the same time, the warning signs are getting harder to spot. The days of relying on bad grammar, awkward wording, or an obviously fake story (ever hear from a Nigerian prince?) to identify a phishing email are over. AI has made it easier for attackers to eliminate the grammatical errors, implausible contexts, and cultural mismatches employees were trained for years to recognize.

The result is a message that can look professional, reference the right people, and fit naturally into an employee’s workday. That is what makes modern spear phishing so effective.

Why Defense Contractors Are a Preferred Target

If you work in or around the Defense Industrial Base (DIB), you're not an incidental target, you are the target. A few reasons why:

You're a shortcut to classified and controlled information

State-sponsored APT groups are often more focused on intelligence gathering and stealing sensitive data than making an immediate financial profit. When targeting the DIB, their spear phishing campaigns may pose as cleared personnel, imitate trusted defense contractors, or use fake requests to access or share secure documents as a way to gain initial access.

You're a supply chain doorway

Large prime contractors typically have mature cybersecurity programs. Smaller subcontractors, machine shops, and specialty manufacturers often have fewer security resources, which can make them easier targets.

That creates a risk across the entire defense supply chain. If an attacker compromises a subcontractor, they may use that access to move toward a larger prime contractor. Or, they may simply steal the CUI the subcontractor already stores or handles.

This supply chain risk is one of the reasons the Pentagon established the Cybersecurity Maturity Model Certification (CMMC) program. After sensitive data was stolen from companies handling CUI, the Department of Defense sought a stronger way to verify that contractors were actually meeting NIST SP 800-171 cybersecurity requirements, rather than relying primarily on contractors to attest to their own compliance.

Nation-states have already proven the playbook works

This isn't theoretical. North Korea's Lazarus Group has run spear phishing campaigns against the U.S. defense industry by posing as recruiters advertising job opportunities at major defense contractors such as Lockheed Martin, a lure specifically designed to catch engineers and program staff off guard.

Incident responders have also handled real DIB breaches tied to nation-state campaigns. In one case, a U.S. defense and technology manufacturing company was breached by a threat actor associated with the "TiltedTemple" campaign, requiring a full incident response engagement to identify, contain, and evict the attacker.

The cost of getting it wrong keeps climbing

The average cost of a data breach involving phishing has reached into the millions, and that price tag can grow quickly. A successful spear phishing attack can lead to incident response expenses, forensic investigations, system recovery, legal costs, operational downtime, and lost productivity. If sensitive data is stolen, the financial impact can continue long after the initial attack is contained.

AI is making that risk even more concerning. Attackers can now create highly personalized spear phishing messages at a fraction of the time and effort previously required, while achieving click rates comparable to those of skilled human attackers. That allows convincing campaigns to be launched at greater scale without the same investment of resources.

What Makes a Spear Phishing Email Convincing

Modern spear phishing against contractors tends to share a few traits:

  • A believable pretext tied to your actual work: a "secure portal" login request, a fake RFP amendment, a spoofed message from a known subcontractor or prime.
  • Impersonation of someone with authority: a contracting officer, a security officer, or an executive requesting an urgent action.
  • Urgency and isolation: pressure to act fast, often outside normal channels, so the target doesn't have time to verify.
  • AI-polished language: no more telltale typos or awkward phrasing to rely on as a tell.

How Defense Contractors Can Defend Against It

There's no single control that stops spear phishing; it requires layered defense across people, process, and technology:

  1. Security awareness training with real phishing simulations, not just an annual slideshow. Employees need repeated, realistic practice recognizing pretexts specific to your industry.
  2. Phishing-resistant multi-factor authentication, so a stolen password alone isn't enough to get an attacker in.
  3. 24/7 monitoring and threat hunting to catch the attacker who gets past the inbox, because eventually someone will click.
  4. A tested incident response plan so that if a compromise happens, containment is fast and evidence is preserved for both your investigation and your compliance obligations.
  5. Alignment to NIST 800-171/CMMC controls, which already require awareness training, access control, and incident response as part of protecting CUI.

The Bottom Line

Spear phishing isn't going away, and for defense contractors it isn't optional to defend against. It's often the difference between passing a CMMC assessment and explaining a breach to a contracting officer. The attackers targeting the DIB are patient, well-resourced, and increasingly aided by AI. Matching that requires more than a training video once a year.

Protecting your organization from targeted phishing attacks takes more than good instincts: it takes 24/7 monitoring, expert-led threat hunting, and security awareness training built around the real threats facing defense contractors.

RADICL's Cybersecurity-as-a-Service platform was built specifically to defend the Defense Industrial Base against nation-state-grade adversaries, combining Managed Security Awareness, Managed Detection & Response, and end-to-end incident response in one transparent platform.

Connect with us to help your organization prevent phishing attacks.

Get Email Notifications

No Comments Yet

Let us know what you think