Whaling Attack
Learn how whaling attacks work, how cybercriminals target CEOs and senior executives for large financial transfers, and how organisations can protect their leadership. Includes real-life examples, warning signs, and expert safeguarding tips.
Overview
What is a whaling attack?
A whaling attack is a highly targeted form of phishing aimed exclusively at the most senior individuals within an organisation — chief executive officers, chief financial officers, board members, managing directors, and other C-suite executives. The term "whaling" deliberately contrasts with ordinary phishing: where standard phishing casts a wide net for any available catch, whaling goes after the biggest fish.
The objective is typically financial. Attackers invest significant time researching their target — their role, their communication style, their direct reports, their ongoing business dealings, and their organisational authority — before crafting a message that is personalised, plausible, and precisely timed. The most common attack scenario involves a fraudulent email impersonating the CEO or CFO, sent to a finance employee, authorising an urgent and confidential wire transfer. Alternatively, the executive themselves is targeted directly to extract login credentials or sensitive corporate data.
Because whaling attacks are built on deep research rather than mass distribution, they bypass many of the signals that trained employees use to identify generic phishing. There is no suspicious attachment, no unfamiliar brand, no obvious urgency cliché — just a well-written, contextually accurate email that appears to come from exactly the person it claims to.
Who is targeted: C-suite executives are both the impersonated party and the direct target, depending on the attack variant. Finance directors, accounts payable teams, and executive assistants are also frequently targeted as the operational conduit between the executive and the company's financial systems.
Why it works: Senior executives are high-value, time-pressured, and accustomed to making large decisions quickly and independently. They are often less subject to the internal verification procedures that govern lower-level financial transactions — and their requests carry the authority to bypass those controls entirely.
Scale & Statistics
How common is this scam?
Whaling and its close relative — business email compromise (BEC) — represent the most financially damaging category of cybercrime, consistently outstripping ransomware in total reported losses.
- $2.9 billion in losses were reported to the FBI from business email compromise and executive impersonation fraud in 2023 — the highest figure for any cybercrime category that year
- $4.83 million is the average cost of a BEC-related breach per incident in 2024, including financial loss, legal costs, and reputational damage, according to IBM
- Whaling and BEC attacks increased by 28% year-on-year in 2023, with the number of reported incidents rising across every major economy
- $55,000 is the median wire transfer requested in a single whaling incident — but individual cases routinely reach into the millions
- 33% of all financial losses from cybercrime in the US in 2023 originated from BEC and executive fraud, despite representing a fraction of total cybercrime volume
- 17% of all phishing emails detected in enterprise environments in 2024 were classified as targeted executive or C-suite attacks, up from 9% in 2021
- Zero malware is used in the majority of whaling attacks — they rely entirely on social engineering, making them invisible to antivirus and endpoint detection tools
Most affected sectors: financial services, legal, real estate, manufacturing, and any organisation involved in high-value transactions or international wire transfers.
Sources: FBI IC3 2023 Internet Crime Report; IBM Cost of a Data Breach Report 2024; Proofpoint State of the Phish 2024; Verizon Data Breach Investigations Report 2024; APWG Phishing Activity Trends Report Q4 2024
How It Works
How does it work?
Whaling attacks are distinguished from other phishing by the depth of preparation that precedes them. A successful whaling campaign may involve weeks of reconnaissance before a single email is sent.
-
The target is selected and researched — The attacker identifies a high-value organisation and focuses on its senior leadership. LinkedIn profiles, company websites, press releases, annual reports, Companies House filings, regulatory disclosures, and social media accounts are systematically mined for information about the CEO's name, role, communication style, travel schedule, ongoing projects, key relationships, and the names of direct reports with financial authority.
-
A specific attack scenario is constructed — Using the gathered intelligence, the attacker designs a scenario that will feel entirely routine to the target or to those who will receive the fraudulent instruction. Common scenarios include: a CEO authorising an urgent and confidential acquisition payment; a CFO requesting an emergency supplier transfer while travelling; or a senior executive whose email account is impersonated to instruct a finance team member to process an invoice immediately.
-
A convincing sender identity is established — The attacker registers a lookalike domain (e.g.
ceo@acme-corp.cominstead ofceo@acmecorp.com) or uses display name spoofing to make the email appear to come from the real executive's address. In more sophisticated operations, the executive's actual email account is compromised first, allowing the attacker to send the fraudulent instruction from the genuine address. -
The email is sent at a strategically chosen moment — Timing is deliberate. Whaling emails are frequently sent late on a Friday afternoon, when senior staff are less available for verification and finance teams are under pressure to process transactions before the weekend. They are also timed to coincide with known travel, board meetings, or active business negotiations — events the attacker has identified during reconnaissance.
-
Urgency and secrecy are imposed — The message stresses that the transfer must be completed immediately and kept confidential — framed as a sensitive acquisition, a regulatory requirement, or an active legal matter. Both conditions are designed to prevent the recipient from seeking a second opinion or following standard verification procedures.
-
Funds are transferred and rapidly moved — Once the victim authorises the transfer, funds are immediately routed through a chain of intermediary accounts — often across multiple jurisdictions — making recovery extremely difficult. The average window between transfer and point of unrecoverability is under 24 hours.
Platforms and tools commonly used: Lookalike domain registration, display name spoofing, open-source intelligence (OSINT) tools for reconnaissance, AI writing assistants for tone matching, and international wire transfer networks for rapid fund movement.
Recent variations in 2024–2025:
- AI-generated whaling emails use scraped samples of an executive's writing — from public speeches, LinkedIn posts, or leaked correspondence — to replicate their tone and vocabulary with high precision, eliminating the stylistic cues that previously helped recipients identify impersonation
- Deepfake audio and video calls are increasingly used to supplement the initial email — a fraudulent follow-up call appearing to come from the CEO provides a second layer of false validation before a finance team member processes a large transfer
- Multi-stage whaling begins with a lower-stakes email to establish a correspondence thread, then escalates to a financial request once a dialogue has been normalised
- Vendor and lawyer impersonation presents the fraudulent wire transfer as a routine payment to a law firm handling a confidential acquisition — a framing that simultaneously justifies the secrecy and the size of the transfer
Psychological Tactics
What psychological tactics are used?
Whaling is among the most psychologically sophisticated forms of fraud because it exploits the specific dynamics of organisational hierarchy — the deference, urgency compliance, and loyalty that structure how employees respond to senior leadership.
| Tactic | How it is used |
|---|---|
| Hierarchical authority | A request from the CEO or CFO carries an implicit instruction to comply without question. Challenging or verifying such a request can feel professionally risky — as if doubting the executive's judgement or competence. |
| Confidentiality as a control mechanism | Framing the transaction as sensitive, legally privileged, or commercially confidential gives the target a reason to bypass normal verification channels. "Do not discuss this with anyone" neutralises the most effective safeguard. |
| Urgency and deadline pressure | "This must be processed before close of business today." Time pressure prevents deliberate thinking and discourages the target from taking the time to verify through independent channels. |
| Manufactured context | References to real events — an acquisition the attacker learned about through OSINT, a supplier the target genuinely uses, a conference the executive is publicly attending — make the request feel grounded in reality the target can verify without checking the email itself. |
| Flattery and exclusivity | Being entrusted personally by the CEO with a sensitive matter is presented as a mark of confidence. The target is implicitly told they were chosen because they are trusted and capable — creating a motivation to deliver. |
| Fear of professional failure | Failing to act on a direct executive instruction — especially one framed as time-critical — carries an implied consequence for the target's professional standing. The cost of inaction is made to feel greater than the cost of compliance. |
What makes whaling psychologically distinct is that it does not primarily target personal fear or greed. It targets professional identity — the desire to be competent, trusted, and responsive to leadership. These are motivations that are far harder to train away than susceptibility to a suspicious link or an implausible prize.
Real-Life Example
A real-life case
Case: Ubiquiti Networks loses $46.7 million in whaling and BEC attack (2015, landmark case with enduring relevance)
In 2015, Ubiquiti Networks — a US-based networking technology company — disclosed that it had lost $46.7 million to a whaling and business email compromise attack. The fraud was conducted entirely through email, with no malware, no system breach, and no technical intrusion of any kind.
Attackers impersonated senior Ubiquiti executives and engaged the company's finance department with a series of emails requesting a sequence of wire transfers to accounts controlled by the fraudsters, framed as payments relating to a confidential acquisition. The finance team, believing the instructions came from legitimate leadership and perceiving the transactions as commercially sensitive, processed the transfers without triggering standard verification procedures.
The fraud was discovered only when Ubiquiti was contacted by law enforcement. By that point, $46.7 million had been transferred across accounts in multiple countries. Through urgent legal action and cooperation with international authorities, approximately $8.1 million was recovered — leaving a net loss of $38.6 million. The company disclosed the incident in a regulatory filing with the US Securities and Exchange Commission.
The outcome: No malware was ever found on Ubiquiti's systems. No technical vulnerability was exploited. The attack succeeded entirely through the impersonation of authority and the exploitation of organisational deference. The case remains one of the most cited examples in corporate cybersecurity training globally, precisely because it demonstrates that no technical defence alone can protect against a well-executed whaling attack.
Source: Ubiquiti Networks SEC Filing (Form 10-Q), August 2015; FBI Public Warning on Business Email Compromise, 2015; Krebs on Security, "Ubiquiti Networks Suffers $46M Cyberheist," August 2015
Red Flags to Watch
Red flags to watch for
- An email from a senior executive — CEO, CFO, or board member — requests an urgent wire transfer, change of payment details, or access to sensitive financial accounts, particularly if it arrives outside normal business hours
- The request is explicitly marked as confidential and you are told not to discuss it with colleagues, legal, or compliance teams — framed as a sensitive acquisition, legal matter, or regulatory requirement
- The executive's email address looks almost correct but contains a subtle difference — a missing letter, an added character, a different top-level domain, or a lookalike spelling
- The transfer must be processed immediately, with a deadline of today or before end of business — and the normal approval or verification process is presented as unnecessary given the circumstances
- The request comes while the executive is known to be travelling, in meetings, or otherwise difficult to reach by phone — a situation the attacker has identified and deliberately exploited
- A follow-up call or voicemail appears to confirm the email request, but comes from an unknown number or a number that does not match the executive's known contact details
- The payment is directed to a new supplier, a law firm you have not previously dealt with, or an overseas account — particularly one in a jurisdiction not previously used in your organisation's transactions
- The email asks you to act before informing your manager, the finance director, or any other oversight function
How to Identify
How to identify a whaling attack
Ask yourself before acting:
- Would this executive normally contact me directly by email to authorise a transfer of this size — or would it go through the standard approval process?
- Is there a genuine reason this transaction cannot be verified through our normal channels, or has the email simply asserted that it cannot be?
- Can I call the executive directly on a number I already have — not one provided in this email — to confirm the request before taking any action?
Verification steps:
- Never process a large or unusual financial transaction based solely on an email instruction, regardless of who it appears to come from — this is the single most important control to have in place
- Call the executive directly using a phone number from your own records or the company's internal directory — not a number provided in or alongside the email
- Check the sender's full email address character by character — whaling emails often use domains that are visually almost identical to the real one and are designed to be overlooked at speed
- Apply your organisation's out-of-band verification procedure for high-value transfers — a verbal confirmation from the authorising executive via a known, independent channel should be mandatory for any transaction above an agreed threshold
- Escalate to your line manager or compliance team immediately if something feels unusual — the confidentiality framing in a whaling email is specifically designed to prevent you from doing exactly this
- Report the suspicious email to your IT or security team before taking any further action, even if you are uncertain whether it is fraudulent
Legitimate vs fraudulent — how to tell:
| Legitimate executive request | Whaling email |
|---|---|
| Follows the organisation's standard approval and verification process | Asks you to bypass normal procedures due to urgency or confidentiality |
| The executive is reachable by phone to confirm the instruction | Calls or messages to verify are discouraged, unavailable, or go unanswered |
| Payment goes to a known, established supplier or account | Payment is directed to a new, unfamiliar, or overseas account |
| There is adequate time to verify and process through normal channels | A same-day or immediate deadline is imposed with no flexibility |
| The email address exactly matches the executive's known, verified address | The address contains a subtle misspelling or uses a lookalike domain |
How to Protect
How to protect yourself
Preventive habits:
- Implement a mandatory dual-authorisation or out-of-band verification policy for all wire transfers above a defined threshold — no single email instruction, regardless of its apparent source, should be sufficient to initiate a large payment
- Establish a clear, organisation-wide protocol: any request to bypass standard financial controls — regardless of how senior the requestor — must be verified by phone using a number from internal records before action is taken
- Train finance, accounts payable, and executive assistant teams specifically on whaling and CEO fraud scenarios — these roles are the most frequent operational targets and require dedicated awareness
- Configure email authentication standards — DMARC, DKIM, and SPF — on your domain to make it harder for attackers to convincingly spoof your organisation's email addresses
- Enable email banner warnings for messages originating from outside your organisation, particularly when the display name matches an internal executive
- Conduct regular simulated whaling exercises with finance and executive support staff — real-world practice is significantly more effective than passive training materials
- Limit the volume of information published about senior executives on company websites and social media — OSINT reconnaissance depends on publicly available data, and reducing its availability raises the cost of a targeted attack
If you have already been targeted:
- If a transfer has already been initiated, contact your bank immediately — many institutions can halt or recall international wire transfers if notified within hours of the transaction
- Report the attack to your organisation's IT security team and senior management immediately — do not attempt to manage the incident alone
- Preserve all emails, headers, and correspondence related to the attack without modification — these are critical for law enforcement investigation
- File a report with the FBI's IC3 (US), Action Fraud (UK), or your national cybercrime authority as quickly as possible — speed significantly affects the likelihood of fund recovery
- Notify your cyber insurance provider if your organisation holds a relevant policy
- Conduct an internal review of how the attack bypassed existing controls and implement corrective measures before resuming normal operations
Useful tools:
| Tool | What it does | Cost |
|---|---|---|
| MXToolbox | Verifies DMARC, DKIM, and SPF configuration on your domain to assess email spoofing risk | Free |
| Have I Been Pwned | Checks whether executive email addresses have been exposed in known data breaches — a common source for attacker reconnaissance | Free |
| VirusTotal | Scans suspicious links and attachments before opening | Free |
| Proofpoint Email Protection | Enterprise-grade email filtering with specific detection for impostor and executive spoofing threats | Paid |
Video Lesson
Watch: Whaling attacks explained
A clear, practical explanation of how whaling attacks differ from standard phishing, how attackers research and impersonate senior executives, the role of urgency and authority in making fraudulent requests convincing, and the organisational controls that are most effective at preventing large-scale financial losses. Suitable for viewers with no prior cybersecurity knowledge.
Further Reading
Further reading
Official resources
- FBI Internet Crime Complaint Center (IC3) — Report whaling and CEO fraud; access the latest BEC statistics and recovery guidance → ic3.gov
- CISA (Cybersecurity & Infrastructure Security Agency) — Guidance on business email compromise, executive impersonation, and technical email authentication controls → cisa.gov/bec
- NCSC (National Cyber Security Centre, UK) — Practical guidance for organisations on defending against CEO fraud and BEC → ncsc.gov.uk
- Action Fraud (UK) — Report whaling and executive fraud incidents and access victim support → actionfraud.police.uk
Research & reports
- FBI IC3 — "Business Email Compromise: The $50 Billion Scam" — the FBI's definitive public advisory on CEO fraud, BEC mechanics, and global loss data → ic3.gov/Media/Y2023/PSA230609
- Proofpoint — "State of the Phish 2024" — includes dedicated analysis of executive-targeted phishing, impersonation attacks, and voice-assisted whaling variants → proofpoint.com/state-of-the-phish
- Verizon — "Data Breach Investigations Report (DBIR) 2024" — annual benchmark on BEC and pretexting attacks, which account for a significant and growing share of all breaches → verizon.com/dbir
Investigative coverage
- KrebsOnSecurity — "Ubiquiti Networks Suffers $46M Cyberheist" — detailed reporting on the landmark whaling case and the mechanics of the attack → krebsonsecurity.com
- SEC EDGAR — Ubiquiti Networks 10-Q filing disclosing the incident, illustrating the regulatory reporting obligations triggered by whaling losses → sec.gov/edgar
Related articles on this platform
- Phishing Email — fraudulent emails impersonating trusted organisations to steal credentials
- Spear Phishing — targeted phishing using personal details harvested from data breaches or social media to appear credible
- Business Email Compromise (BEC) — phishing that targets payment authorisation processes within organisations
- Vishing (Voice Phishing) — phone calls impersonating banks, government agencies, or senior executives to extract information or authorise transfers