← Back to glossary Offensive techniques

Whaling

What is whaling?

Whaling is a variant of spear phishing aimed specifically at senior executives and people with decision or signing authority —CEO, CFO, board members, finance and legal leadership— with the goal of stealing their credentials, inducing payments or obtaining approval for critical actions. The "whale" is the victim: the attacker invests weeks in reconnaissance and builds a bespoke pretext (a corporate transaction, a lawsuit, an audit request) because the return on compromising a single executive mailbox exceeds that of a thousand ordinary ones. Not to be confused with CEO fraud: there the executive is the impersonated sender; in whaling, the executive is the target.

Why does it matter?

Because the leadership layer combines the three things an attacker wants: maximum privilege (access to results, corporate transactions, the power to order payments), maximum public exposure (interviews, LinkedIn, company registries, press releases that feed the attacker's OSINT) and, frequently, minimum controls, because it is the group granted the most exceptions: relaxed filtering, no MFA "because it gets in the way", personal devices mixed with corporate ones. A compromised executive mailbox is the perfect platform for the next step: reading email for weeks, learning the house style and launching an internal Business Email Compromise against the finance team or the company's suppliers. The FBI attributes billions of dollars in annual losses to BEC, and deepfakes have raised the stakes: in the Arup case (2024), an employee in Hong Kong wired 25 million dollars after a video call with synthetic recreations of the CFO and other executives. Social engineering against executives is no longer a badly written email: it is an operation with a budget.

Key points

Difference from CEO fraud: in whaling the executive is the victim who receives the attack; in CEO fraud the executive is the impersonated sender used to pressure an employee. Both belong to the BEC family and are often chained: first the executive is compromised, then the fraud is sent from their own mailbox.

Intensive prior reconnaissance: public agendas, press coverage, LinkedIn, company registries, leaked email signatures and the team's own posts feed the pretext. The more credible the context (a real due diligence, a dated board meeting), the less likely the human filter is to trigger. Reducing the board's OSINT footprint is part of the defence.

Multi-channel vectors: email from look-alike domains, smishing and vishing to personal phones, LinkedIn or WhatsApp messages and, increasingly, voice and video deepfakes to deliver the final instruction. Personal channels sit outside the corporate perimeter, and attackers know it.

Typical objectives: mailbox and corporate SSO credentials (with AiTM proxies that steal the session token and defeat weak MFA), authorisation of wire transfers, privileged information about ongoing transactions, and material for extortion or for the next link in the fraud chain.

VIP-specific technical protections: phishing-resistant MFA (passkeys/FIDO2) mandatory for the leadership layer, DMARC/DKIM/SPF with a reject policy, external-sender banners, look-alike domain monitoring, alerts on forwarding rules in VIP mailboxes and strict conditional access. Domain and identity spoofing underpins most of these attacks.

Process protections: out-of-band verification (a call to a known number) for every payment or bank account change, dual approval above a threshold, agreed code words for urgent instructions, and targeted training for the executive committee with simulations built around their real pretexts, not the generic company-wide phishing campaign.

Example: whaling a CFO in the middle of an acquisition

A mid-size company is negotiating the acquisition of a competitor and the story reaches the financial press. A criminal group builds the operation in two weeks: it identifies the CFO and the law firm advising the deal on LinkedIn, registers a look-alike domain of the firm (one letter changed) and sends the CFO a flawless email with the pretext of an "updated data room with the revised figures". The link leads to a replica of the Microsoft 365 login built on an AiTM proxy: the CFO types the password, approves the MFA prompt, and the attacker captures the session token. No technical vulnerability was exploited: only context, urgency and a similar-looking domain.

For three weeks the attacker reads the mailbox in silence, creates a rule diverting the bank's emails to a hidden folder and learns how the CFO signs off. With that material the second phase begins —now as CEO fraud— ordering, from the CFO's genuine mailbox, a change of bank account for the next payment to one of the deal's suppliers. What breaks the chain is a process control, not a technical one: the treasury manager calls the supplier's number on file —not the one in the email— before executing the change. The follow-up review with the incident response team finds the mailbox rule, revokes sessions and tokens, enforces FIDO2 for the executive committee and turns out-of-band verification into written policy for any banking change.

Common mistakes

  • Exempting executives from controls out of convenience or hierarchy: no strong MFA, exceptions in the mail filter, no training. This is precisely the group with the most privilege and the most exposure; the exceptions should run the other way: more control, not less.
  • Confusing whaling with CEO fraud and training only the finance department. The leadership layer needs its own training as the target of the attack, with dedicated simulations built on their real pretexts (board meetings, transactions, press coverage).
  • Relying on generic anti-phishing training. Executive lures are not mass-campaign lures: they arrive with genuine context, clean prose and plausible urgency. If the simulation does not resemble the attack, the reflex will not exist when the real one lands.
  • Ignoring personal channels: executives' mobiles, WhatsApp, LinkedIn and personal email sit outside the perimeter and outside corporate telemetry, and they are exactly the preferred channels for first contact and for cloned-voice vishing.
  • Having no payment verification procedure independent of email. If the mailbox is the single source of truth for ordering a transfer, when the mailbox falls, the whole process falls with it: out-of-band verification against known numbers must be written policy, also —especially— when the order comes 'from the top' and is urgent.

Related services

This concept may be related to services such as:

Frequently asked questions

I am the CEO of an SMB and I appear in the press regularly: what should change in my day-to-day?

Four concrete things. First: move your MFA to passkeys or FIDO2 keys on email and corporate SSO; push notifications get approved out of fatigue and AiTM proxies defeat them. Second: assume that any urgent request for a payment, account change or sensitive data gets verified through a different channel than the one that brought it, with no exceptions for hierarchy. Third: review your public footprint with an attacker's eyes —agenda, travel, live transactions— and delay whatever you can publish afterwards. Fourth: agree with your finance team that nobody will ever be penalised for delaying a payment to verify it; the pressure of 'the CEO wants it and it is urgent' is exactly how the fraud works.

What exactly is the difference between whaling and CEO fraud?

The role the executive plays. In whaling, the executive is the target: they receive the attack, and it is their credentials or signature the attacker wants. In CEO fraud, the executive is the disguise: the attacker impersonates them (by email, voice or video) to pressure an employee with payment authority. Both belong to the BEC family and are frequently chained: a whaling attack that compromises the CFO's mailbox enables a later CEO fraud sent from the legitimate account — the hardest version to detect, because the sender, the thread and the style are all real.

How do I protect my executive committee if I have no in-house security team?

With platform and process controls, none of which require your own SOC. In Microsoft 365 or Google Workspace: phishing-resistant MFA for the committee, DMARC at a reject policy, external-sender banners, alerts on new forwarding rules and conditional access. On process: out-of-band verification for payments and banking changes, and dual approval above a threshold. Plus executive-specific training with realistic social engineering simulations. If nobody is available to configure and watch all this, an external Microsoft 365 security service covers exactly that gap.

Are deepfakes changing whaling?

Yes, and in one specific direction: the closing phase. Email still opens the door, but the final instruction now arrives by phone or video call with cloned voice or imagery — which is what defeated the controls in the Arup case: the employee distrusted the initial email, and the video call with the 'executives' dissolved that doubt. The practical consequence is that seeing and hearing no longer equals verifying. Processes must rest on channels and data the attacker does not control: call-backs to known numbers, agreed code words, and thresholds that require a second approval regardless of who orders the payment or through which medium. Social engineering evolves; the principle of independent verification does not.