Spear-phishing: 'I was targeted by this highly manipulative scam'

This was a masterclass of polite, friendly professionalism.
An HR manager at an overseas university invited me to 'deliver a guest lecture on your area of expertise'.
That expertise was described, accurately, as 'investigating scams, protecting consumer data [and] how financial journalism holds large organisations to account'.
There were also flattering words about the way I 'translate complex consumer finance issues into clear, evidence-based reporting'. (I'd like to think that's true, too.)
And finally, the universal clincher: money. I was assured that it's a 'paid engagement with a clearly defined scope, and we are happy to work entirely around your schedule'.
Unfortunately, this gratifying offer was a total lie devised by fraudsters and crafted, almost certainly, using artificial intelligence (AI) to build a profile and prompt the conversation.
It's part of a wave of incredibly sophisticated, targeted scams in which the criminals research your public profile and tailor their approach.
And although Which? journalists have been targeted before, these attacks can be launched against anyone, with people's digital footprint providing a wealth of information and AI turbocharging the threat.
But I spotted this scam before it could harm me, and you can learn how to do the same.
What is spear-phishing?
Most of us have heard of phishing, which is where scammers send emails or messages to manipulate us into making a payment or sharing our personal data.
One classic example of a phishing scam is an email impersonating your bank, which links to a fake login page designed to steal your credentials.
Often, hundreds or even thousands of these are sent at once, in a 'spray and pray' approach. Many recipients may not even be customers of the bank being impersonated. But even if only a small percentage of recipients are defrauded, that could prove lucrative.
These mass attacks are nothing new, and neither is spear-phishing – a slightly more sophisticated version in which criminals single out smaller numbers of people and adapt their approach based on individuals' identities.
Carefully tailored approaches may have a higher success rate than the more generic versions. And crafting them is now quicker and easier than ever, thanks to chatbots and AI summaries.
The role of AI
Phishing attacks are on the rise. The UK government's 2025/26 Cyber Security Breaches Survey found that a quarter of charities and more than a third of companies experienced them.
AI tools are a major factor in this increase, and they can be especially helpful in creating spear-phishing attacks.
Building a profile of someone might once have taken hours of carefully piecing together their social media, professional profiles, news articles and information dumps from large data breaches.
Now, AI does this in seconds and will frequently even create a summary in your internet browser if you search someone's name.
That profile can then be used by the AI chatbot to write highly professional emails like the one I received.
How I foiled the attack

Once the email has reached the victim, AI features can even continue to help criminals unwittingly. That's because many email providers now generate suggested responses for you.
This time-saving feature can put you on autopilot and is the opposite of what's needed in spotting and avoiding spear-phishing.
In my case, my email provider drafted: 'Thanks for reaching out and for your kind words about my work. It sounds like an interesting opportunity. Could you please send over some further details regarding the scope, timing, and format you have in mind for the guest lecture?'
All I needed to do was click 'reply' to send, and the criminals would have been well on their way to extracting whatever data or payment they were seeking.
But while I was momentarily flattered by the approach, a decade spent investigating fraud has made me very cautious. So I did what I advise others to do in this situation – stop and verify the claims.
I noticed that the university the email was from, while real, was emailing me from a '.edu' email address mainly associated with the United States. When I looked it up, I found the real college was based in Singapore with a .sg email address.
Moreover, it had recently published a warning on its site about 'fake job offers (...) from unofficial domains'.
Are you at risk?
Anyone can be a spear-phishing target, even if you have a very low public profile and/or your social media accounts are locked down tight.
That's because your data can also be stolen through data breaches – of which there have been several high-profile instances in recent years.
However, people with lots of information available online may be more at risk – particularly if their contact details are widely available.
Those with professional profiles on company sites or LinkedIn, charity trustees and/or company directors may be targeted as potential gateways into an organisation's IT systems, which can then be encrypted and held to ransom.
And in a particularly high-profile recent case, UK Prime Minister Andy Burnham exchanged messages with someone impersonating Donald Trump's chief of staff.
But there are several ways you – and Mr Burnham – can reduce the risk:
- Limit your online presence: Ideally, strangers looking at your personal social media should hardly be able to see anything about you.
- Recognise the warning signs: Fraudsters often deliberately evoke strong emotions such as excitement, fear or panic, to stop you from analysing what they say.
- Take 5 minutes before replying: Copycats impersonate trusted organisations in emails, texts and instant messages. Avoid clicking on links and use trusted contact details to verify the request.
- Put the phone down on unsolicited callers: Calmly hanging up is not rude. As with emails and texts, verify contact using trusted means.
- Use antivirus: A good antivirus helps protect you from phishing scams and your PC from malware, and some of the best are free, as our lab tests uncovered.
- Report attempts: Forward emails to the National Cyber Security Centre at report@phishing.gov.uk, and flag scam calls and texts to your phone network by forwarding the message or number to 7726. You can also share them with Which? using our Scam Sharer tool:
Seen or been affected by a scam? Help us protect others
Sharing details of the scam helps us to protect others as well as inform our scams content, research and policy work. We will collect information relating to your experience of a scam, but we won't be able to identify your responses unless you choose to provide your contact details.
Share scam details


