What Is Whaling in Cyber Security? How CEO Fraud Works and How to Stop It
In the world of phishing, “whaling” refers to attacks that target the biggest fish — senior executives, CEOs, CFOs, board members, and other high-value individuals within organizations. The term captures the intent precisely: where spear phishing targets any individual, whaling specifically targets those with the authority to authorize large financial transactions, access sensitive systems, or make decisions that can be exploited for significant gain.
Also called CEO fraud or Business Email Compromise (BEC), whaling is the most financially damaging category of cybercrime. In 2023, the FBI’s IC3 reported that BEC scams — the category that encompasses whaling — caused $2.9 billion in losses, more than any other type of internet crime.
—
What Is Whaling in Cyber Security?
Whaling is a highly targeted spear phishing attack directed at senior executives or other high-profile individuals within an organization. The attacker impersonates the executive themselves, a trusted colleague, a board member, or a key vendor to manipulate employees — typically in finance, accounting, or operations — into taking a high-value action: wiring money to a fraudulent account, changing payroll direct deposit information, or providing access to sensitive systems.
In some variants of whaling, the attacker targets the executive directly — impersonating their bank, their attorney, or a government official to manipulate them into divulging information or authorizing a transaction.
—
How Whaling Attacks Are Executed
Phase 1: Target research.
The attacker identifies their targets — both the executive they’ll impersonate and the employee(s) they’ll manipulate. Corporate websites, LinkedIn, annual reports, press releases, regulatory filings, and news articles provide extensive information about executive identities, organizational structure, financial relationships, and pending business activities.
Phase 2: Timing and context.
Effective whaling attacks are timed to coincide with real business events — an acquisition, a vendor payment cycle, a board meeting, a tax filing deadline. Attackers monitor news about their target organizations to identify these windows.
Phase 3: The impersonation email.
The attacker sends an email that appears to come from the CEO, CFO, or another executive, directed at a finance team member with payment authority. The email typically:
– References a real business deal or situation
– Creates urgency — “I need this done today before my flight”
– Asks for secrecy — “Don’t process this through normal channels”
– Provides wire transfer instructions to a fraudulent account
Phase 4: The follow-up.
If the initial email doesn’t generate the desired action, attackers often follow up with a phone call — sometimes using voice cloning — to create additional pressure.
—
Real Examples of Whaling Attacks
The Ubiquiti Networks Attack (2015): A finance employee was targeted with an impersonation email appearing to come from executives, resulting in $46.7 million in wire transfers to fraudulent accounts overseas. $8.1 million was ultimately recovered.
The Mattel Attack (2015): A finance executive received what appeared to be a request from the newly hired CEO to transfer funds to a vendor in China. A single wire transfer of $3 million was executed before the fraud was discovered. Mattel eventually recovered the funds.
The Pathé Attack (2018): The CEO of a regional division of film company Pathé was manipulated through a series of emails appearing to be from the company’s CEO into authorizing a series of wire transfers totaling €19.2 million ($21 million) over several weeks.
—
The Role of AI in Modern Whaling Attacks
Generative AI has dramatically lowered the barrier to entry for whaling attacks. Attackers can now:
– Use AI to generate perfectly written, contextually appropriate emails based on research about the target
– Use AI voice cloning to create audio that sounds exactly like the target executive
– Use AI-generated deepfake video in video calls to impersonate executives visually
In 2024, a finance employee at a multinational firm in Hong Kong was manipulated into transferring HK$200 million (approximately $25 million USD) after participating in a video call in which multiple “colleagues” appeared — all of whom were AI-generated deepfakes of real company employees.
—
How to Protect Your Organization From Whaling
Implement dual authorization for large transactions.
No single person — regardless of seniority — should be able to authorize a wire transfer above a set threshold without a second approval from an independent party. This single procedural control would prevent the majority of successful whaling attacks.
Verify all unusual payment requests by phone.
Any request to wire money, change bank account information, or take a financial action that comes via email — regardless of who it appears to be from — should be verified by calling the requestor at a known number before acting.
Implement DMARC, DKIM, and SPF on your email domain.
These technical controls prevent attackers from spoofing your company’s own email domain — which is one of the most common impersonation techniques in whaling attacks.
Limit executive digital footprint where possible.
The less publicly available information about your senior leadership team’s travel schedules, business relationships, and financial activities, the harder it is for attackers to construct a believable lure.
Train finance and operations staff specifically.
The employees most at risk in whaling attacks are those with payment authority — finance, accounting, and executive assistants. These teams need specific training on BEC and whaling, not just general phishing awareness.
Flag emails from external domains that contain executive names.
Many email systems can be configured to display a warning when an email contains an executive’s name but originates from an external domain — a strong indicator of impersonation.
—
Frequently Asked Questions
Q: What is the difference between whaling and spear phishing?
A: All whaling is spear phishing, but not all spear phishing is whaling. Whaling specifically targets senior executives (the “big fish”). Spear phishing is the broader category of targeted, personalized phishing attacks against any specific individual.
Q: How do I report a whaling attack?
A: Report to the FBI’s Internet Crime Complaint Center at ic3.gov. If a wire transfer was involved, also contact your bank’s fraud department immediately — wire recalls are sometimes possible if acted upon quickly (often within 72 hours). Also notify your company’s cybersecurity or IT team.
Q: Is whaling only a risk for large companies?
A: No. Small and medium businesses are frequently targeted in BEC attacks precisely because their internal controls (like dual authorization) are often less rigorous than those of large corporations. Any organization that processes wire transfers is a potential whaling target.
→ Back to Pillar: https://www.scammed.org/phishing/
→ See also: https://www.scammed.org/phishing/spear-phishing/