SardineCon SF/2026

Learn More

¿Qué es Whaling?

SUBSCRIBE

Whaling is spear phishing aimed at senior executives, board members, or other high-value targets whose authority or access makes a successful compromise especially damaging. It usually impersonates or targets a CEO or CFO to authorize a wire transfer or expose sensitive data, and it is a core business email compromise tactic.

What is whaling, in plain English?

Whaling is spear phishing that goes after the big fish: chief executives, finance chiefs, board members, and others whose seniority gives them power to move money or unlock sensitive information. The technique is the same targeted, researched phishing used elsewhere, but the target is chosen because a single success is worth so much.

It shows up two ways. Sometimes the executive is the target, tricked into approving a payment or clicking a malicious link. More often the executive is impersonated: an attacker poses as the CEO or CFO and pressures a subordinate, usually in finance, to make an urgent wire transfer or send confidential data. Either way, it trades on authority, because few employees push back on a direct request from the top.

Whaling is a headline tactic within business email compromise. The reason it is dangerous is arithmetic: the higher the target, the larger the payment they can authorize and the more sensitive the data they can reach, so the payoff from one successful message is disproportionate.

How a whaling attack unfolds

  1. Research — Study the executive. The attacker maps the leader's role, travel, deals, and the finance staff who act on their instructions.
  2. Impersonate — Pose as the CEO or CFO. Using a spoofed or lookalike address, they send a message that reads like the executive under time pressure.
  3. Pressure — Demand urgent, quiet action. A confidential deal or deadline is invoked to justify an unusual wire and to discourage a second check.
  4. Payout — Wire or data leaves. A subordinate sends the transfer or the sensitive files, and the funds move on before anyone verifies.

Whaling versus ordinary spear phishing

What changes

Ordinary spear phishing

Whaling

Target

Any specific employee or role

Senior executives and board members

Authority in play

Limited to the target's access

High, can authorize large payments

Payoff

Moderate

Very large single hits

Pressure lever

Routine business context

Executive authority and confidentiality

What it looks like in practice

In practice

A finance manager receives an email that appears to be from the CFO, who is known to be traveling for a deal. It says a confidential acquisition is closing and a deposit must be wired today to a law firm's account, with a plea to keep it quiet until the announcement.

The address is a lookalike domain, and the "confidential deal" is a device to stop the manager from asking colleagues. Trusting the apparent seniority and the deadline, the manager sends the wire. By the time the real CFO is reached, the money has already moved through the receiving account and out.

Why it matters to operators

Whaling produces some of the largest single-event losses in payment fraud precisely because it targets the authority to approve large transfers. The request looks legitimate to the person acting on it, and the confidentiality angle is engineered to suppress the exact verification that would stop it. On the receiving side, the funds often route through a mule or a freshly set-up business account and disperse quickly.

Defenses combine executive-specific awareness, strict payment verification with dual approval on large or first-time transfers, and email authentication to make impersonation harder. The rule that defeats most whaling is procedural: no urgency and no claim of confidentiality can waive an independent callback to the executive on a known number before the money moves.

What to watch for

  • Executive urgency. Payment requests that invoke a CEO or CFO, a deadline, and secrecy all at once.
  • Lookalike domains. Sender addresses one character off from the real executive or company domain.
  • First-time large payees. Big wires to a new beneficiary, especially a law firm or overseas account, tied to a "deal."
  • Verification blocked. Instructions to keep the request confidential or to avoid contacting the executive directly.
  • Channel switch. A request that moves from email to a personal number or app to escape normal controls.

Quick questions

How is whaling different from spear phishing?

Whaling is spear phishing aimed specifically at senior executives. The method is identical, but the target's authority makes a single success far more valuable and damaging.

Is the executive always the victim?

No. Often the executive is impersonated and a subordinate in finance is the one manipulated into acting. The attacker borrows the executive's authority rather than compromising them directly.

Why does confidentiality feature so often?

Secrecy stops the target from doing the one thing that would break the scam: checking with colleagues or the real executive. It is a control-suppression tactic, not a genuine business need.

How is it linked to business email compromise?

Whaling is one of the highest-value forms of BEC. Impersonating leadership to authorize a wire is a classic BEC play, and executive targets raise the payoff.

What is the single best control?

Mandatory independent verification of large or first-time payments through a known channel, with dual approval, and no exceptions for urgency or confidentiality.

Does email authentication help?

Yes, it makes exact-domain spoofing harder, but attackers pivot to lookalike domains and compromised accounts, so it must be paired with payment verification, not relied on alone.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

Qué saber junto con Whaling