Whaling Phishing: What It Is, Examples, and Prevention Tips

All the know-how you need to protect your organization from this growing threat - how whaling works, how to spot attacks and the best practices you can use to strengthen your defences.

Post hero image

Table of contents

See Hoxhunt in action
Drastically improve your security awareness & phishing training metrics while automating the training lifecycle.
Get a Demo
Updated
September 1, 2026
Written by
Hoxhunt
Fact checked by

The short answer

Whaling phishing is an email attack that impersonates a CEO, CFO, or other executive to talk an employee into an urgent wire transfer or a data handover. It works because it borrows the target's authority: people don't second-guess their boss. These attacks, once they tip into business email compromise (BEC), cost businesses $3 billion in 2025 alone and $55.4 billion since 2013, per the FBI.

$3B
Business email compromise losses reported in 2025
$55.4B
Cumulative BEC losses reported since 2013

Below, we'll cover everything you need to know to protect your organization from this growing threat: how whaling works, how to spot attacks, and the best practices you can use to strengthen your defences.

What is whaling phishing?

Why "whaling"?

It's called whaling because attackers aren't fishing for minnows, they're harpooning the biggest fish in the building.

Whaling is a type of spear phishing. Spear phishing targets one specific person instead of a broad list, using research on that person to make the email believable. Whaling narrows that further: the target is a CEO, CFO, or other senior leader, someone whose approval alone can move money or data.

Attackers do real homework first: LinkedIn profiles, press releases, the org chart. That's what makes the email feel like it really came from someone the reader trusts, and why whaling is so much harder to catch than an everyday phishing email.

Where whaling fits in the phishing family:

Attack typeWho it targetsHow personalizedWhat it's after
PhishingA broad, often random list of recipientsGeneric, mass-sent, little to no research on the individualHarvested credentials or malware installed at scale
Spear phishingOne specific person or a small groupPersonalized using research on that person's role and habitsAccess to a specific account, system, or dataset
WhalingA senior executive or someone with sign-off authority, like a CEO, CFO, or board memberHighly personalized, built around the target's authority and how they communicateLarge wire transfers or company-wide sensitive data, approved without a second check
From: "David Chen, CEO" <d.chen@acme-corp.co>
Subject: Urgent, need this processed before EOD
Hi Sarah, I'm in back-to-back meetings and can't call. Need you to process an urgent wire transfer today, details to follow shortly. Please keep this confidential for now. Thanks, David
⚠ Look-alike domain: .co, not .com

Whaling attacks are on the rise...

Attackers keep adapting, and whaling is only getting more common.

  • AI-written phishing emails, the same trick whaling relies on, are up 34% year-over-year, per Verizon's 2025 Data Breach Investigations Report. Attackers now personalize each message with AI instead of mass-sending the same script.
  • A Harvard Kennedy School study found AI-written spear phishing emails get clicked 54% of the time, as often as ones written by human experts. Generic phishing emails, by comparison, get clicked just 12% of the time.
  • Attacking has also gotten cheaper. Phishing-as-a-service kits like RaccoonO365 let anyone rent ready-made attack infrastructure, no technical skill required. Microsoft and Cloudflare seized 338 domains tied to RaccoonO365 in September 2025, and volume kept climbing anyway.

Understanding whaling phishing: here's what you need to know

Types of whale phishing attacks

Email spoofing

Attackers fake a trusted email address, usually a senior executive's. Posing as someone the reader trusts makes the fake request harder to question.

Business email compromise (BEC)

BEC happens when attackers get into a real executive's email account and use it to message other employees, suppliers, or customers, asking them to transfer money or hand over sensitive information.

Attackers increasingly pair the email with a callback lure, a phone number that connects the target to a live scammer for "verification." Hoxhunt's Phishing Trends Report 2026 found 43% of BEC attacks now carry one.

Vendor email compromise (VEC)

VEC works the same way as BEC, but attackers impersonate a vendor or supplier instead of an executive, sending fake invoices or payment-change requests to redirect money to their own accounts.

Invoice fraud

Attackers impersonate a trusted vendor and send fake invoices to the target company. The invoices look real, but the payment details route to the attacker's own bank account.

Credential theft

Attackers use phishing emails or other social engineering tricks to get senior employees to hand over login credentials or other sensitive information.

Payroll fraud

Once attackers have an executive's or senior employee's email credentials, they ask payroll or finance to change their direct-deposit details, then redirect the paycheck to their own account.

Malware and ransomware attacks

Whaling attacks can also carry malware (software that damages or spies on a device) or ransomware (malware that locks your files until you pay to get them back). These are usually delivered through email attachments or links.

What are attackers trying to achieve?

  • Financial gain: Attackers trick executives or finance teams into approving wire transfers that send money straight to the attacker's account.
  • Data theft: Attackers use whaling to steal sensitive data, such as intellectual property, financial records, or customer information.
  • Business disruption: Some whaling attacks spread malware or ransomware across the network to disrupt operations.
  • Identity theft: Attackers impersonate a senior employee to get unauthorized access to systems or resources.
  • Reputation damage: A successful whaling attack can also damage a company's reputation, especially if leaked information or embarrassing communications go public.

Who do whaling attacks usually target?

Whaling attacks target people with authority, access to sensitive information, or control over money.

Here's who tends to be targeted, and why.

Job roleReason for targeting
CEOThe CEO has the most authority in the company. A request that looks like it's from them gets little pushback.
CFOCFOs control company finances. They can approve a wire transfer with one email.
CIOs/CTOsCIOs and CTOs control the tech stack. Compromising them opens the door to sensitive systems.
Board MembersBoard members see confidential strategy and financial plans. That makes them a source of high-value insider information.
Senior Managers and Department HeadsThey often hold real budget or sign-off authority. That's usually enough to push through a fraudulent request.
HR ManagersHR managers hold employee records and payroll access. That data fuels identity theft and payroll fraud.
Legal CounselLegal counsel holds sensitive contracts and case details. Attackers want early access to deals or disputes.

Examples of whaling attacks

Singapore multinational (2025)

A finance director at a multinational corporation, never publicly named in any report, was first contacted on WhatsApp by someone posing as the CFO. He then joined a Zoom call where the CEO and several colleagues were all AI-generated deepfakes, complete with synced facial movements and cloned voices. He transferred US$499,000 before the fraud was caught, one of the rare cases where fast law enforcement action recovered the money.

Arup (2024)

Engineering firm Arup lost $25 million after a finance employee in its Hong Kong office joined a video call where every other participant, including senior executives, was an AI-generated deepfake. The employee made 15 transfers before the scam was caught, a sign of whaling adapting to voice and video, not just email.

Twitter (2020)

Twitter suffered a high-profile whaling attack: cybercriminals posed as company executives to trick employees into handing over credentials.

That gave them access to high-profile accounts, including those of Elon Musk, Barack Obama, and Joe Biden, which attackers used to run a cryptocurrency scam. The scam cost Twitter about $120,000 in direct losses, plus real reputational damage.

FACC (2016)

Austrian aerospace supplier FACC lost close to €50 million after an employee wired the money following an email that looked like it came from CEO Walter Stephan. The company clawed back about €11 million, but the fallout didn't stop there: FACC's board fired Stephan over the failure, one of the clearest examples of how far the damage from a single whaling email can spread.

Ubiquiti Networks (2015)

Networking manufacturer Ubiquiti disclosed to the SEC that fraudsters posing as company executives moved $46.7 million out of a Hong Kong subsidiary through 14 wire transfers over 17 days, routing the money to accounts in Russia, China, Hungary, and Poland. Ubiquiti recovered $8.1 million of it.

How do whaling attacks actually work?

Here's how a whaling phishing attack will generally unfold:

  1. Research and reconnaissance. Cybercriminals research the organization and the employees they're targeting, pulling from social media, the company website, press releases, and public databases. That research is what makes the eventual email so convincing.
  2. The spoofed email. This is one message doing four jobs at once:
    1. Spoofing: it's built to look like it's from a CEO, CFO, or another senior leader.
    2. Social engineering: psychological pressure that gets someone to act instead of think.
    3. Urgency: act now, skip the questions, treat the deadline as today.
    4. The request: a wire transfer backed by a fake invoice or contract, or a direct ask for sensitive data like payroll records or customer credentials.
  3. Compromise and exploitation. If it works, the money moves fast, often straight to offshore accounts that are hard to claw back. Stolen data doesn't stop there either: it can fuel identity theft, further fraud, or extortion.


Whaling attacks are evolving

Whaling keeps changing shape. Here's what's actually new, not just "more sophisticated" in the abstract.

Advanced social engineering

Attackers now build fake email threads that look like an ongoing conversation. Some even insert a fake law firm or advisor alongside the impersonated CEO. That backstory makes the payment request feel already discussed and approved. Hoxhunt's Cyber Threat Intelligence Report 2025 flagged this as a rising 2025 tactic.

Email spoofing techniques

Spoofed sender domains keep shifting. Gmail addresses alone now account for roughly a fifth of all malicious senders. Salesforce abuse tripled in the first half of 2025, as attackers used it for business-account takeovers. Some campaigns skip logo images entirely. Instead, they fake a brand's logo with an HTML table, which slips past image-based detection.

From: IT Support <support@micros0ft-alerts.com>
Subject: Action required: verify your account
Your account will be suspended in 24 hours unless you verify your details. Click below to confirm your identity and avoid service interruption.
⚠ Spoofed domain: a zero swapped for the letter "o"

AI technology

AI-generated phishing keeps getting more fluent. It's also getting more targeted, pushing attacks away from generic bulk phishing and toward personalized spear phishing and whaling. One tell still gives it away: leftover placeholder text like ##victimdomain## or ##date2## that the AI failed to fill in.

Compromising real accounts

Some attackers skip domain spoofing entirely. Instead, they steal session tokens to hijack a real, already-logged-in account, a technique that can bypass multi-factor authentication. Once inside, they can change MFA settings or mailbox rules within minutes. A whaling email from a genuinely compromised colleague's account is far harder to catch than an obviously fake one.

How to spot a whaling attack

Whaling can be hard to catch, but a few signs hold up.

The routine trap: Hoxhunt's threat research found people fail simulations most often when the request feels like everyday work: a shared file, a calendar invite, an HR request, or one that plays on wanting recognition, like a raise or bonus. The most dangerous whaling email is often the one that doesn't feel alarming at all. It doesn't look like a ransom note. It looks like Tuesday.

An unexpected request that claims to be from an executive: Real leaders rarely email out of the blue asking for money or sensitive data, with no other context.

Urgency and pressure: Immediate wire transfers, confidential disclosures, or account access requested without the usual approval steps.

Phishing indicators, with a catch: Spelling errors and generic greetings are still red flags. But AI-written phishing is often grammatically perfect now, so absence of typos no longer means an email is safe. Ironically, a flawlessly written urgent wire-transfer request might be the real tell now: real CEOs are busy, typo-prone humans, not copy editors.

A request for confidential information: Login credentials, financial data, or other sensitive details, especially over email.

Something that doesn't fit: A topic, tone, or request that doesn't match how this person normally communicates or what they'd normally ask for.

A quick process employees can use to review suspicious emails

  1. Verify the sender. Check the email address for misspellings or slight variations in the domain or name.
  2. Assess urgency. Be skeptical of any email demanding urgent action.
  3. Review content. Look for unusual requests, unfamiliar topics, or unexpected attachments that don't fit normal communication.
  4. Verify authenticity. If in doubt, confirm the request through a different channel, like a phone call, not by replying to the email.
  5. Avoid clicking links or downloading attachments. Don't click links or open attachments in a suspicious email.
  6. Report suspicious emails. Report it to IT or security immediately.

Best practices for preventing whaling phishing

Enforce strict access controls

Limit who can reach sensitive data and systems in the first place. Grant access on a need-to-know basis, not by default.

Update your organization's software regularly

Keep devices and software updated with the latest security patches. Updates often close the exact gaps new threats rely on.

Enable multi-factor authentication

Require MFA for corporate accounts and systems, especially for anyone in a high-risk role.

Implement email encryption

Encrypt email containing sensitive data, such as financial information, intellectual property, or personally identifiable information (PII), both in transit and at rest. That closes off interception as an option.

Lock down your data protection policies

Write clear policies for who can access, share, or send sensitive data, and how.

Cover the basics: no sending files to personal email addresses, and no accessing sensitive data over public Wi-Fi without a mobile VPN.

Invest in employee security training

Humans are the single biggest risk to your organization's security...

Up to 95% of breaches start with a phishing email (Comcast, via Hoxhunt's Phishing Trends Report 2026).

That's why training employees on best practices is essential.

But how you train matters as much as whether you train. Hoxhunt CEO Mika Aalto has pointed out why fear-based training backfires: "If you generate enough fear or threat, a person will easily do something irrational, like open a shady attachment, even though they know perfectly well they shouldn't." That's the exact psychology whaling exploits with its urgency and pressure. Training that builds calm, consistent habits beats training that just scares people.

The bottom line

Whaling exploits fear and urgency. Training that runs on fear just teaches the same reflex the attacker is counting on. The fix is calm, consistent habits, not scarier warnings.

Train employees to recognize and report the latest phishing threats, whaling included.

Run regular phishing simulations that test for whaling specifically, then follow up with targeted security awareness training based on what people missed.

Realistic phishing scenarios that mimic real whaling tactics give employees a genuine feel for what to expect.

Are there any tools you can implement to defend against whaling attacks?

Email security gateways (ESGs): ESGs sit between the internet and your inbox, scanning traffic for malicious activity before it lands. They combine spam filters, antivirus scanning, and behavioral analysis to catch what a human might miss.

Quick tip

Flag every email that comes from outside your organization's network. Small domain variations are easy to miss otherwise.

Anti-phishing tools: Purpose-built to catch phishing attempts, whaling included. They use threat-intelligence feeds and reputation scoring to judge whether an email, sender, or domain can be trusted.

Email authentication protocols: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) verify that an email's sender is who it claims to be, and catch most spoofing attempts before they reach an inbox.

AI-powered detection: Modern tools analyze email behavior in real time, flag patterns that match known whaling tactics, and quarantine suspicious messages automatically.

Endpoint security: Tools like EDR (endpoint detection and response) and next-gen antivirus (NGAV) watch device activity directly, catching malware or ransomware that slips past the email gateway.

Incident response and forensic tools: If an attack succeeds anyway, these tools let your security team trace what happened: email headers, the message's true origin, and how far it spread.

An employee thinks they've fallen victim to a whaling attack: what now?

If an employee suspects they've responded to a whaling email, whether that means clicking a link, sharing information, or authorizing a transfer, speed matters more than blame. The fastest reports come from teams where flagging a mistake isn't punished.

Below is a general template. Adapt it to your organization's actual incident-response process.

  1. Do not respond. Don't reply, click links, or open attachments in the suspicious email.
  2. Report the incident. Tell IT or security immediately.
  3. Document details. Save the sender's address, subject line, and anything else relevant, before it's gone.
  4. Quarantine the email. Move it to spam or junk, or quarantine it with your email filtering tools.
  5. Change passwords. If credentials might be compromised, change them for email and any other sensitive accounts.
  6. Monitor accounts. Watch email and other accounts for unauthorized activity in the days after.

Reduce human cyber risk with Hoxhunt

Hoxhunt provides individualized phishing training, automated security awareness training, and advanced behavior change, all in one human risk management platform.

Traditional security awareness training isn't effective at changing employee behavior.

So, we built Hoxhunt to maximize outcomes using positive behavior reinforcement, personalized learning paths, and fun, engaging micro-trainings.

  • Automatically tailor training to each employee's location, role, and skill level.
  • Stay ahead of the latest threats with realistic phishing simulations (including whaling attacks).
  • Make training something people actually enjoy, with instant feedback, leaderboards, and achievements.
  • Track performance with drill-down reporting and benchmarks against other organizations.

That reporting habit is what catches a whaling email before it costs anything. Hoxhunt customer WaterAid traced a business email compromise attempt across 39 employee inboxes and remediated it within a minute of detection.

Hoxhunt phishing training dashboard

Whaling phishing FAQ

What is whaling phishing?
Whaling phishing is a targeted email attack that impersonates a senior executive, like a CEO or CFO, to trick another employee into a wire transfer or a data disclosure. It's named for going after the "big fish" in an organization, rather than casting a wide net.
How does whaling phishing differ from standard phishing attacks?
Standard phishing casts a wide net with generic emails sent to as many people as possible. Whaling is the opposite: one attacker, one target, built around real research into that person's role and authority.
What are the telltale signs of a whaling phishing attack?
An unexpected request from someone senior, pressure to act fast, and a request for money or sensitive data with no other context. AI has made spelling and grammar mistakes a far less reliable warning sign than they used to be.
What are some common tactics used in whaling phishing attacks?
Spoofed sender domains, fake email threads that mimic an ongoing conversation, and increasingly, deepfaked voice or video on a call. All of it is built on real research into the target's role, habits, and communication style.
How can organizations protect against whaling phishing attacks?
Multi-step verification for any money or data request, regular training that includes simulated whaling attempts, and email authentication protocols like SPF, DKIM, and DMARC to catch spoofed senders before they reach an inbox.

Sources

  • Whaling Phishing Risks and Strategies, Kennesaw State University, 2020.
  • Business Email Compromise: The $55 Billion Scam, FBI Internet Crime Complaint Center (IC3), 2024.
  • FBI IC3 2025 Internet Crime Report: Email Fraud Now a $3 Billion Problem, dmarcian, 2026.
  • Arup Revealed as Victim of $25 Million Deepfake Scam, CNN Business, 2024.
  • Hoxhunt Phishing Trends Report 2026, Hoxhunt, 2026.
  • Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects, Heiding, Lermen, Kao, Schneier & Vishwanath, Harvard Kennedy School (arXiv), 2024.
  • Finance Director in S'pore Transfers S$670,000 to Scammers Who Used Deepfake to Impersonate Company's Executives, Mothership.sg, 2025.
  • Austrian Firm Fires CEO After $56-million Cyber Scam, SecurityWeek, 2016.
  • Tech Firm Ubiquiti Suffers $46M Cyberheist, Krebs on Security, 2015.
  • RaccoonO365 Phishing Network Dismantled as Microsoft, Cloudflare Take Down 338 Domains, The Hacker News, 2025.
  • Want to learn more?
    Be sure to check out these articles recommended by the author:
    Get more cybersecurity insights like this