← Glossary

Whaling Attack

Whaling is a highly targeted phishing attack aimed at senior executives (CEOs, CFOs) whose authority can move money and unlock data. It is the executive tier of spear phishing and a core BEC technique.

Updated

Whaling is a highly targeted phishing attack aimed at an organization's most senior people, the "whales": CEOs, CFOs and other executives whose authority can move money and unlock data. One deceived executive, or one attacker convincingly posing as one, can authorize what a thousand ordinary phishing victims cannot.

Key facts:

  • Whaling is the executive tier of spear phishing and a core technique in business email compromise, a crime category that generated over $2.7 billion in reported losses in 2024 alone according to the FBI's IC3 Annual Report.
  • Attacks are researched, individually written and usually payload-free, which is why they pass filters looking for malicious links.
  • The escalation path is multi-channel: fraudulent email reinforced by deepfake voice or video "confirmation".

Two directions of whaling

Whaling works both ways. Attacks on executives target the whale directly: a fake lawsuit notice, board document or M&A inquiry crafted for one reader. Attacks as executives impersonate the whale toward staff: the "CEO" instructing finance to pay urgently and confidentially. The second form is more common because authority flows downward; few employees interrogate an instruction from the top. Both rely on pretexting: a story plausible enough that the request feels routine.

Anatomy of a whaling attack

  • Research. Executive names, roles, travel, deals and even writing style are public or breachable: LinkedIn, press releases, earnings calls, conference agendas.
  • The setup. A spoofed or lookalike sender, or a compromised real mailbox. Timing is chosen for vulnerability: quarter close, the CEO's flight, a public acquisition.
  • The ask. Wire transfer, gift card purchase, payroll change, or confidential documents. Urgency and secrecy discourage verification.
  • The reinforcement. Increasingly, a follow-up call or video where AI-cloned voice or deepfake video "confirms" the instruction. In one widely reported 2024 case, engineering firm Arup lost about $25 million after a finance employee joined a video call in which every other "executive" was a deepfake (CNN).

Whaling vs spear phishing vs BEC

Spear phishingWhalingBEC
TargetOne researched person, any levelSenior executivesWhoever can move money or data
Who is impersonatedA colleague, vendor or serviceA peer executive, board member, lawyer or regulatorThe CEO, CFO or a supplier
PayloadOften a link or attachmentFrequently none; a document request or a call to actUsually none
ObjectiveAccess, credentialsLarge transfers, deal or legal data, executive credentialsFraudulent payments
OverlapWhaling is spear phishing at the executive tierOften the first step of a BEC chainUses whaling and spear phishing as techniques

How to defend

Executives need harder controls, not just training: enforced MFA and phishing-resistant authentication on executive accounts, payment verification procedures that no single email can override (two-person approval, callback on known numbers, no exceptions for urgency or secrecy), minimized public detail about internal reporting lines, and a culture where questioning an odd "CEO request" is rewarded. On the technical side, behavioral email security matters most at the top: executive impersonation is exactly the attack that clean-looking, payload-free messages deliver.

How Sentaro stops whaling

Sentaro's Behavioral Defense learns each executive's real communication patterns: devices, threads, tone, who they instruct and how. Message Defense catches lookalike domains the moment they appear in mail flow and reads intent, flagging the urgent-confidential-payment pattern even when the message contains no link, no attachment and no spelling errors.

Questions we get asked.

What is whaling in cybersecurity?

Phishing aimed specifically at senior executives, either to deceive them directly or to impersonate them toward employees. The name comes from targeting the biggest "fish" in the organization.

What is the difference between whaling and spear phishing?

Spear phishing targets any researched individual; whaling is spear phishing whose target or impersonated persona is a senior executive, where authority makes the payoff larger.

Why do whaling attacks work?

Authority and urgency suppress verification. An instruction that appears to come from the CEO, timed when they are unreachable and marked confidential, exploits organizational psychology rather than technical vulnerabilities.

Are whaling emails detectable by spam filters?

Usually not by traditional filters: they are individually written, carry no malicious payload and often come from lookalike or compromised accounts. Detection requires behavioral analysis of sender, relationship and intent.

How does AI change whaling?

Generative AI writes fluent executive-style messages at scale, and voice/video deepfakes now provide fake "confirmation" of fraudulent instructions. Defense has to assume the content and even the voice can be synthetic, and rely on procedure plus behavioral detection.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.