Whaling is a highly targeted phishing attack aimed at an organization's most senior people, the "whales": CEOs, CFOs and other executives whose authority can move money and unlock data. One deceived executive, or one attacker convincingly posing as one, can authorize what a thousand ordinary phishing victims cannot.
Key facts:
- Whaling is the executive tier of spear phishing and a core technique in business email compromise, a crime category that generated over $2.7 billion in reported losses in 2024 alone according to the FBI's IC3 Annual Report.
- Attacks are researched, individually written and usually payload-free, which is why they pass filters looking for malicious links.
- The escalation path is multi-channel: fraudulent email reinforced by deepfake voice or video "confirmation".
Two directions of whaling
Whaling works both ways. Attacks on executives target the whale directly: a fake lawsuit notice, board document or M&A inquiry crafted for one reader. Attacks as executives impersonate the whale toward staff: the "CEO" instructing finance to pay urgently and confidentially. The second form is more common because authority flows downward; few employees interrogate an instruction from the top. Both rely on pretexting: a story plausible enough that the request feels routine.
Anatomy of a whaling attack
- Research. Executive names, roles, travel, deals and even writing style are public or breachable: LinkedIn, press releases, earnings calls, conference agendas.
- The setup. A spoofed or lookalike sender, or a compromised real mailbox. Timing is chosen for vulnerability: quarter close, the CEO's flight, a public acquisition.
- The ask. Wire transfer, gift card purchase, payroll change, or confidential documents. Urgency and secrecy discourage verification.
- The reinforcement. Increasingly, a follow-up call or video where AI-cloned voice or deepfake video "confirms" the instruction. In one widely reported 2024 case, engineering firm Arup lost about $25 million after a finance employee joined a video call in which every other "executive" was a deepfake (CNN).
Whaling vs spear phishing vs BEC
| Spear phishing | Whaling | BEC | |
|---|---|---|---|
| Target | One researched person, any level | Senior executives | Whoever can move money or data |
| Who is impersonated | A colleague, vendor or service | A peer executive, board member, lawyer or regulator | The CEO, CFO or a supplier |
| Payload | Often a link or attachment | Frequently none; a document request or a call to act | Usually none |
| Objective | Access, credentials | Large transfers, deal or legal data, executive credentials | Fraudulent payments |
| Overlap | Whaling is spear phishing at the executive tier | Often the first step of a BEC chain | Uses whaling and spear phishing as techniques |
How to defend
Executives need harder controls, not just training: enforced MFA and phishing-resistant authentication on executive accounts, payment verification procedures that no single email can override (two-person approval, callback on known numbers, no exceptions for urgency or secrecy), minimized public detail about internal reporting lines, and a culture where questioning an odd "CEO request" is rewarded. On the technical side, behavioral email security matters most at the top: executive impersonation is exactly the attack that clean-looking, payload-free messages deliver.
How Sentaro stops whaling
Sentaro's Behavioral Defense learns each executive's real communication patterns: devices, threads, tone, who they instruct and how. Message Defense catches lookalike domains the moment they appear in mail flow and reads intent, flagging the urgent-confidential-payment pattern even when the message contains no link, no attachment and no spelling errors.