The short answer
Whaling phishing is an email attack that impersonates a CEO, CFO, or other executive to talk an employee into an urgent wire transfer or a data handover. It works because it borrows the target's authority: people don't second-guess their boss. These attacks, once they tip into business email compromise (BEC), cost businesses $3 billion in 2025 alone and $55.4 billion since 2013, per the FBI.
Below, we'll cover everything you need to know to protect your organization from this growing threat: how whaling works, how to spot attacks, and the best practices you can use to strengthen your defences.
What is whaling phishing?
It's called whaling because attackers aren't fishing for minnows, they're harpooning the biggest fish in the building.
Whaling is a type of spear phishing. Spear phishing targets one specific person instead of a broad list, using research on that person to make the email believable. Whaling narrows that further: the target is a CEO, CFO, or other senior leader, someone whose approval alone can move money or data.
Attackers do real homework first: LinkedIn profiles, press releases, the org chart. That's what makes the email feel like it really came from someone the reader trusts, and why whaling is so much harder to catch than an everyday phishing email.
Where whaling fits in the phishing family:
| Attack type | Who it targets | How personalized | What it's after |
|---|---|---|---|
| Phishing | A broad, often random list of recipients | Generic, mass-sent, little to no research on the individual | Harvested credentials or malware installed at scale |
| Spear phishing | One specific person or a small group | Personalized using research on that person's role and habits | Access to a specific account, system, or dataset |
| Whaling | A senior executive or someone with sign-off authority, like a CEO, CFO, or board member | Highly personalized, built around the target's authority and how they communicate | Large wire transfers or company-wide sensitive data, approved without a second check |
Whaling attacks are on the rise...
Attackers keep adapting, and whaling is only getting more common.
- AI-written phishing emails, the same trick whaling relies on, are up 34% year-over-year, per Verizon's 2025 Data Breach Investigations Report. Attackers now personalize each message with AI instead of mass-sending the same script.
- A Harvard Kennedy School study found AI-written spear phishing emails get clicked 54% of the time, as often as ones written by human experts. Generic phishing emails, by comparison, get clicked just 12% of the time.
- Attacking has also gotten cheaper. Phishing-as-a-service kits like RaccoonO365 let anyone rent ready-made attack infrastructure, no technical skill required. Microsoft and Cloudflare seized 338 domains tied to RaccoonO365 in September 2025, and volume kept climbing anyway.
Understanding whaling phishing: here's what you need to know
Types of whale phishing attacks
Email spoofing
Attackers fake a trusted email address, usually a senior executive's. Posing as someone the reader trusts makes the fake request harder to question.
Business email compromise (BEC)
BEC happens when attackers get into a real executive's email account and use it to message other employees, suppliers, or customers, asking them to transfer money or hand over sensitive information.
Attackers increasingly pair the email with a callback lure, a phone number that connects the target to a live scammer for "verification." Hoxhunt's Phishing Trends Report 2026 found 43% of BEC attacks now carry one.
Vendor email compromise (VEC)
VEC works the same way as BEC, but attackers impersonate a vendor or supplier instead of an executive, sending fake invoices or payment-change requests to redirect money to their own accounts.
Invoice fraud
Attackers impersonate a trusted vendor and send fake invoices to the target company. The invoices look real, but the payment details route to the attacker's own bank account.
Credential theft
Attackers use phishing emails or other social engineering tricks to get senior employees to hand over login credentials or other sensitive information.
Payroll fraud
Once attackers have an executive's or senior employee's email credentials, they ask payroll or finance to change their direct-deposit details, then redirect the paycheck to their own account.
Malware and ransomware attacks
Whaling attacks can also carry malware (software that damages or spies on a device) or ransomware (malware that locks your files until you pay to get them back). These are usually delivered through email attachments or links.
What are attackers trying to achieve?
- Financial gain: Attackers trick executives or finance teams into approving wire transfers that send money straight to the attacker's account.
- Data theft: Attackers use whaling to steal sensitive data, such as intellectual property, financial records, or customer information.
- Business disruption: Some whaling attacks spread malware or ransomware across the network to disrupt operations.
- Identity theft: Attackers impersonate a senior employee to get unauthorized access to systems or resources.
- Reputation damage: A successful whaling attack can also damage a company's reputation, especially if leaked information or embarrassing communications go public.
Who do whaling attacks usually target?
Whaling attacks target people with authority, access to sensitive information, or control over money.
Here's who tends to be targeted, and why.
| Job role | Reason for targeting |
|---|---|
| CEO | The CEO has the most authority in the company. A request that looks like it's from them gets little pushback. |
| CFO | CFOs control company finances. They can approve a wire transfer with one email. |
| CIOs/CTOs | CIOs and CTOs control the tech stack. Compromising them opens the door to sensitive systems. |
| Board Members | Board members see confidential strategy and financial plans. That makes them a source of high-value insider information. |
| Senior Managers and Department Heads | They often hold real budget or sign-off authority. That's usually enough to push through a fraudulent request. |
| HR Managers | HR managers hold employee records and payroll access. That data fuels identity theft and payroll fraud. |
| Legal Counsel | Legal counsel holds sensitive contracts and case details. Attackers want early access to deals or disputes. |
Examples of whaling attacks
Singapore multinational (2025)
A finance director at a multinational corporation, never publicly named in any report, was first contacted on WhatsApp by someone posing as the CFO. He then joined a Zoom call where the CEO and several colleagues were all AI-generated deepfakes, complete with synced facial movements and cloned voices. He transferred US$499,000 before the fraud was caught, one of the rare cases where fast law enforcement action recovered the money.
Arup (2024)
Engineering firm Arup lost $25 million after a finance employee in its Hong Kong office joined a video call where every other participant, including senior executives, was an AI-generated deepfake. The employee made 15 transfers before the scam was caught, a sign of whaling adapting to voice and video, not just email.
Twitter (2020)
Twitter suffered a high-profile whaling attack: cybercriminals posed as company executives to trick employees into handing over credentials.
That gave them access to high-profile accounts, including those of Elon Musk, Barack Obama, and Joe Biden, which attackers used to run a cryptocurrency scam. The scam cost Twitter about $120,000 in direct losses, plus real reputational damage.
FACC (2016)
Austrian aerospace supplier FACC lost close to €50 million after an employee wired the money following an email that looked like it came from CEO Walter Stephan. The company clawed back about €11 million, but the fallout didn't stop there: FACC's board fired Stephan over the failure, one of the clearest examples of how far the damage from a single whaling email can spread.
Ubiquiti Networks (2015)
Networking manufacturer Ubiquiti disclosed to the SEC that fraudsters posing as company executives moved $46.7 million out of a Hong Kong subsidiary through 14 wire transfers over 17 days, routing the money to accounts in Russia, China, Hungary, and Poland. Ubiquiti recovered $8.1 million of it.
How do whaling attacks actually work?
Here's how a whaling phishing attack will generally unfold:
- Research and reconnaissance. Cybercriminals research the organization and the employees they're targeting, pulling from social media, the company website, press releases, and public databases. That research is what makes the eventual email so convincing.
- The spoofed email. This is one message doing four jobs at once:
1. Spoofing: it's built to look like it's from a CEO, CFO, or another senior leader.
2. Social engineering: psychological pressure that gets someone to act instead of think.
3. Urgency: act now, skip the questions, treat the deadline as today.
4. The request: a wire transfer backed by a fake invoice or contract, or a direct ask for sensitive data like payroll records or customer credentials. - Compromise and exploitation. If it works, the money moves fast, often straight to offshore accounts that are hard to claw back. Stolen data doesn't stop there either: it can fuel identity theft, further fraud, or extortion.
Whaling attacks are evolving
Whaling keeps changing shape. Here's what's actually new, not just "more sophisticated" in the abstract.
Advanced social engineering
Attackers now build fake email threads that look like an ongoing conversation. Some even insert a fake law firm or advisor alongside the impersonated CEO. That backstory makes the payment request feel already discussed and approved. Hoxhunt's Cyber Threat Intelligence Report 2025 flagged this as a rising 2025 tactic.
Email spoofing techniques
Spoofed sender domains keep shifting. Gmail addresses alone now account for roughly a fifth of all malicious senders. Salesforce abuse tripled in the first half of 2025, as attackers used it for business-account takeovers. Some campaigns skip logo images entirely. Instead, they fake a brand's logo with an HTML table, which slips past image-based detection.
AI technology
AI-generated phishing keeps getting more fluent. It's also getting more targeted, pushing attacks away from generic bulk phishing and toward personalized spear phishing and whaling. One tell still gives it away: leftover placeholder text like ##victimdomain## or ##date2## that the AI failed to fill in.
Compromising real accounts
Some attackers skip domain spoofing entirely. Instead, they steal session tokens to hijack a real, already-logged-in account, a technique that can bypass multi-factor authentication. Once inside, they can change MFA settings or mailbox rules within minutes. A whaling email from a genuinely compromised colleague's account is far harder to catch than an obviously fake one.
How to spot a whaling attack
Whaling can be hard to catch, but a few signs hold up.
The routine trap: Hoxhunt's threat research found people fail simulations most often when the request feels like everyday work: a shared file, a calendar invite, an HR request, or one that plays on wanting recognition, like a raise or bonus. The most dangerous whaling email is often the one that doesn't feel alarming at all. It doesn't look like a ransom note. It looks like Tuesday.
An unexpected request that claims to be from an executive: Real leaders rarely email out of the blue asking for money or sensitive data, with no other context.
Urgency and pressure: Immediate wire transfers, confidential disclosures, or account access requested without the usual approval steps.
Phishing indicators, with a catch: Spelling errors and generic greetings are still red flags. But AI-written phishing is often grammatically perfect now, so absence of typos no longer means an email is safe. Ironically, a flawlessly written urgent wire-transfer request might be the real tell now: real CEOs are busy, typo-prone humans, not copy editors.
A request for confidential information: Login credentials, financial data, or other sensitive details, especially over email.
Something that doesn't fit: A topic, tone, or request that doesn't match how this person normally communicates or what they'd normally ask for.
A quick process employees can use to review suspicious emails
- Verify the sender. Check the email address for misspellings or slight variations in the domain or name.
- Assess urgency. Be skeptical of any email demanding urgent action.
- Review content. Look for unusual requests, unfamiliar topics, or unexpected attachments that don't fit normal communication.
- Verify authenticity. If in doubt, confirm the request through a different channel, like a phone call, not by replying to the email.
- Avoid clicking links or downloading attachments. Don't click links or open attachments in a suspicious email.
- Report suspicious emails. Report it to IT or security immediately.
Best practices for preventing whaling phishing
Enforce strict access controls
Limit who can reach sensitive data and systems in the first place. Grant access on a need-to-know basis, not by default.
Update your organization's software regularly
Keep devices and software updated with the latest security patches. Updates often close the exact gaps new threats rely on.
Enable multi-factor authentication
Require MFA for corporate accounts and systems, especially for anyone in a high-risk role.
Implement email encryption
Encrypt email containing sensitive data, such as financial information, intellectual property, or personally identifiable information (PII), both in transit and at rest. That closes off interception as an option.
Lock down your data protection policies
Write clear policies for who can access, share, or send sensitive data, and how.
Cover the basics: no sending files to personal email addresses, and no accessing sensitive data over public Wi-Fi without a mobile VPN.
Invest in employee security training
Humans are the single biggest risk to your organization's security...
Up to 95% of breaches start with a phishing email (Comcast, via Hoxhunt's Phishing Trends Report 2026).
That's why training employees on best practices is essential.
But how you train matters as much as whether you train. Hoxhunt CEO Mika Aalto has pointed out why fear-based training backfires: "If you generate enough fear or threat, a person will easily do something irrational, like open a shady attachment, even though they know perfectly well they shouldn't." That's the exact psychology whaling exploits with its urgency and pressure. Training that builds calm, consistent habits beats training that just scares people.
Whaling exploits fear and urgency. Training that runs on fear just teaches the same reflex the attacker is counting on. The fix is calm, consistent habits, not scarier warnings.
Train employees to recognize and report the latest phishing threats, whaling included.
Run regular phishing simulations that test for whaling specifically, then follow up with targeted security awareness training based on what people missed.
Realistic phishing scenarios that mimic real whaling tactics give employees a genuine feel for what to expect.
Are there any tools you can implement to defend against whaling attacks?
Email security gateways (ESGs): ESGs sit between the internet and your inbox, scanning traffic for malicious activity before it lands. They combine spam filters, antivirus scanning, and behavioral analysis to catch what a human might miss.
Flag every email that comes from outside your organization's network. Small domain variations are easy to miss otherwise.
Anti-phishing tools: Purpose-built to catch phishing attempts, whaling included. They use threat-intelligence feeds and reputation scoring to judge whether an email, sender, or domain can be trusted.
Email authentication protocols: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) verify that an email's sender is who it claims to be, and catch most spoofing attempts before they reach an inbox.
AI-powered detection: Modern tools analyze email behavior in real time, flag patterns that match known whaling tactics, and quarantine suspicious messages automatically.
Endpoint security: Tools like EDR (endpoint detection and response) and next-gen antivirus (NGAV) watch device activity directly, catching malware or ransomware that slips past the email gateway.
Incident response and forensic tools: If an attack succeeds anyway, these tools let your security team trace what happened: email headers, the message's true origin, and how far it spread.
An employee thinks they've fallen victim to a whaling attack: what now?
If an employee suspects they've responded to a whaling email, whether that means clicking a link, sharing information, or authorizing a transfer, speed matters more than blame. The fastest reports come from teams where flagging a mistake isn't punished.
Below is a general template. Adapt it to your organization's actual incident-response process.
- Do not respond. Don't reply, click links, or open attachments in the suspicious email.
- Report the incident. Tell IT or security immediately.
- Document details. Save the sender's address, subject line, and anything else relevant, before it's gone.
- Quarantine the email. Move it to spam or junk, or quarantine it with your email filtering tools.
- Change passwords. If credentials might be compromised, change them for email and any other sensitive accounts.
- Monitor accounts. Watch email and other accounts for unauthorized activity in the days after.
Reduce human cyber risk with Hoxhunt
Hoxhunt provides individualized phishing training, automated security awareness training, and advanced behavior change, all in one human risk management platform.
Traditional security awareness training isn't effective at changing employee behavior.
So, we built Hoxhunt to maximize outcomes using positive behavior reinforcement, personalized learning paths, and fun, engaging micro-trainings.
- Automatically tailor training to each employee's location, role, and skill level.
- Stay ahead of the latest threats with realistic phishing simulations (including whaling attacks).
- Make training something people actually enjoy, with instant feedback, leaderboards, and achievements.
- Track performance with drill-down reporting and benchmarks against other organizations.
That reporting habit is what catches a whaling email before it costs anything. Hoxhunt customer WaterAid traced a business email compromise attempt across 39 employee inboxes and remediated it within a minute of detection.
.webp)
Whaling phishing FAQ
What is whaling phishing?
How does whaling phishing differ from standard phishing attacks?
What are the telltale signs of a whaling phishing attack?
What are some common tactics used in whaling phishing attacks?
How can organizations protect against whaling phishing attacks?
Sources
- Subscribe to All Things Human Risk to get a monthly round up of our latest content
- Request a demo for a customized walkthrough of Hoxhunt


.avif)
.avif)