Skip to main content

CNiC Solutions

Business professional working on cybersecurity and IT solutions in a modern Houston office.

A whaling attack does not look like the phishing you were trained to spot. There is no misspelled link, no strange attachment, no obvious scam. Instead there is a short, calm email that appears to come from your CEO, asking finance to quietly wire a payment before end of day. Because it carries the weight of authority and a deadline, it works. Whaling is the reason a single email can cost a business six or seven figures, and understanding exactly how it operates is the first step to stopping it.

  • Whaling targets the top of the org chart. It is spear phishing aimed at executives, either to compromise their account or to impersonate them and pressure their staff.
  • The payoff is enormous. The fraud whaling enables, business email compromise, cost U.S. victims about $2.77 billion in 2024 alone and was the second-costliest cybercrime reported to the FBI.
  • Spam filters do not catch it. Whaling emails are low-volume and text-only, with no malicious link or attachment, so they slip past technical defenses and land in the inbox.
  • Authority plus urgency is the whole trick. The attack works by combining a trusted name with a deadline and a request for secrecy, which short-circuits normal verification.
  • A verification habit beats it. One out-of-band callback to confirm any payment or banking change defeats nearly every whaling attempt, no matter how convincing the email looks.

What’s in This Guide

 

 

Infographic of the five stages of a whaling attack from reconnaissance and impersonation to the fraudulent payout
A whaling attack unfolds in five researched stages, from studying the target to moving the stolen funds.

 

 

What Is a Whaling Attack?

Whaling is a form of phishing that goes after the “big fish” of an organization: the executives and senior leaders whose authority, access, and signing power make them the most valuable targets in the building. The National Institute of Standards and Technology defines it plainly as a specific kind of phishing that targets high-ranking members of organizations. The name is deliberate. Ordinary phishing casts a wide net for any fish it can catch. Whaling hunts one large, high-value target on purpose.

The word “target” cuts two ways, and this is where whaling gets its power. An attack can be aimed at an executive, trying to steal the login credentials or take over the email account of a CEO or CFO. Or it can impersonate that executive, using their name and authority to deceive the people who work for them. In practice the two blend together. A criminal who compromises a CEO’s real inbox can then send flawless internal requests from it, and those requests are almost impossible for staff to question.

Whaling belongs to the broader family of social engineering, where the attacker manipulates a person rather than breaking software. It does not exploit a firewall or a bug. It exploits trust in the org chart. That is what makes it so effective and so hard to filter out with technology alone.

Source: NIST Computer Security Resource Center, glossary definition of whaling

How a Whaling Attack Works

A whaling attack is patient and researched, not a mass blast. It usually unfolds in five stages.

  1. Reconnaissance. The attacker studies the target and the company using public sources: the leadership page on your website, LinkedIn profiles, press releases, social media, and out-of-office replies. They learn who reports to whom, who approves payments, and when a leader is traveling or hard to reach.
  2. Impersonation setup. They prepare a convincing sender. That might be a look-alike domain (cnicso1utions.com with a number swapped for a letter), a display-name spoof that shows the CEO’s name while hiding a stranger’s address, or, most dangerous of all, the executive’s genuine account after a credential theft.
  3. The lure. A short, professional, text-only message arrives. There is no suspicious link or attachment to trip a scanner. It reads like a normal executive request: approve an urgent vendor payment, update banking details for payroll, or handle a confidential transaction before a deadline.
  4. The pressure. The message layers on authority, urgency, and secrecy. “I’m going into a board meeting, please handle this discreetly and confirm once it’s done.” Those cues are engineered to stop the employee from pausing to verify.
  5. The payout. The employee wires the funds or sends the requested data. The money is moved quickly through mule accounts and is often gone before anyone realizes the request was fake.

The entire scheme hinges on one thing: that a busy, trusted-looking request will be acted on without an independent check. Every effective defense, which we cover below, is really just a way of forcing that check to happen.

Whaling vs. Spear Phishing vs. Phishing

These three terms describe the same basic weapon, a deceptive message, aimed with increasing precision. The confusion is understandable, so here is the clean distinction.

Attribute Phishing Spear Phishing Whaling
Target Anyone, sent in bulk A specific named individual A specific senior executive
Personalization Generic (“Dear customer”) Tailored with real details Deeply researched, role-aware
Volume Thousands of recipients A handful Often one
Goal Credentials, malware, small payouts Access to a person or team Large wire transfers, sensitive data, account takeover
Typical payload Malicious link or attachment Link or crafted request Text-only request, no payload

The simplest way to remember it: all whaling is spear phishing, and all spear phishing is phishing, but the reverse is not true. Whaling is the sharpest tip of the spear, reserved for the targets with the most money and access.

One more term is often tangled up with whaling: business email compromise, or BEC. They are related but not identical. Whaling is the technique of targeting or impersonating an executive. BEC is the broader fraud scheme that technique usually serves, in which a spoofed or hijacked executive account is used to redirect a legitimate-looking payment. When you read that a company “lost money to CEO fraud,” you are almost always looking at whaling used to carry out BEC. That link matters, because it is through BEC reporting that we can actually measure the damage.

Why Whaling Is So Dangerous for Businesses

Because whaling is the doorway to business email compromise, the scale of BEC losses is the clearest measure of what whaling costs. The FBI’s Internet Crime Complaint Center (IC3) tracks it every year, and the numbers are staggering.

$2.77B
Reported losses to business email compromise in the U.S. in 2024, across 21,442 complaints, making BEC the second-costliest cybercrime the FBI tracked that year.Source: FBI IC3 2024 Internet Crime Report

That single-year figure sits on top of a decade of compounding damage. In a September 2024 alert, the FBI put the total exposed loss from BEC at more than $55 billion between October 2013 and December 2023, spanning all 50 states and 186 countries.

$55.5B
Total global exposed losses to business email compromise from October 2013 to December 2023, across 305,033 reported incidents.Source: FBI IC3 PSA, “Business Email Compromise: The $55 Billion Scam,” Sept. 2024

To see how BEC stacks up against every other category of cybercrime, look at where it landed among the FBI’s 2024 loss totals. Only investment fraud, a consumer scam, cost Americans more.

Top Cybercrime Categories by Reported Loss, U.S. 2024 (FBI IC3)

Investment fraud
$6.57B
Business email compromise
$2.77B
Tech support fraud
$1.46B
Personal data breach
$1.45B
Confidence and romance fraud
$0.67B

Business email compromise was the second-costliest cybercrime reported to the FBI in 2024. Source: FBI IC3 2024 Internet Crime Report.

The reason each incident hits so hard is the target. When the average is worked out, the damage per case is severe.

There is a sliver of good news. When a fraudulent wire is caught fast, it can sometimes be frozen. The FBI’s Recovery Asset Team, which works most often on BEC cases, acted on 3,020 incidents in 2024 and helped freeze funds at a 66% success rate, but only when victims reported quickly. Speed is everything, and prevention still beats recovery by a wide margin.

Myth: our spam filter or email security will catch a whaling email. It usually will not. Whaling messages are sent in tiny volumes, contain no malicious link or attachment for a scanner to flag, and are often written in plain, professional language. When the attacker uses a compromised real account or a freshly registered look-alike domain, the message passes technical checks and lands in the inbox looking completely legitimate. Whaling is defeated by process and people, not by filters alone.

Source: FBI IC3 2024 Internet Crime Report | FBI IC3, Business Email Compromise: The $55 Billion Scam

Common Whaling Tactics

Whaling is not one script. It is a set of pretexts, each chosen to fit how money and data actually move through a business. These are the patterns the FBI and security teams see most often.

 

 

Four-panel infographic of common whaling tactics: CEO wire fraud, vendor invoice change, payroll W-2 theft, and legal pressure
Whaling reuses a few reliable pretexts, from urgent CEO wire requests to vendor invoice changes and payroll data theft.

 

 

1CEO Fraud and Urgent Wire Requests

The classic. An email that appears to be from the CEO or owner asks finance to send an urgent wire for a confidential deal, an overdue supplier, or an acquisition. The request stresses discretion and a deadline so the employee acts before verifying. This is the single most common and most expensive form of whaling.

2Vendor and Invoice Manipulation

The attacker, posing as an executive or a known supplier, asks that a vendor’s bank details be “updated” before the next payment run. The invoice looks real because it often is a copy of a legitimate one. The only change is the destination account. The next routine payment goes straight to the criminal.

3Payroll and W-2 Data Theft

Not every whaling attack chases a wire. Some, timed around tax season, impersonate a leader and ask HR or payroll for employee W-2 forms or a payroll data export. The stolen tax and identity data is then used for fraudulent tax refunds or sold, turning one email into a mass identity-theft event.

4Legal, M&A, and “Confidential” Pressure

Here the lure is a supposed lawyer or the executive referencing sensitive litigation or a merger. Secrecy is baked into the story, which discourages the target from checking with anyone. The confidential framing is the manipulation: it isolates the victim from the very colleagues who could expose the fraud.

Every one of these tactics is a variation on the same theme. They borrow real authority and add a reason not to double-check. Recognizing the pattern is more durable than memorizing any single script, and it is exactly what a well-designed phishing email review habit trains your team to see.

 

CNiC Solutions — Cybersecurity

 

How to Defend Against Whaling

Because whaling attacks people and process, the strongest defenses are layered controls that assume a convincing fake will eventually reach an inbox. No single tool stops it. These five layers, working together, do.

  1. Make out-of-band verification a rule, not a favor. Any request to move money, change banking details, or send sensitive data must be confirmed through a second, known channel, a phone call to a saved number or an in-person check, never by replying to the email. This one habit defeats nearly every whaling attempt, because it forces the independent check the attack is built to avoid.
  2. Lock down executive accounts. Enforce multi-factor authentication everywhere and add conditional access policies that flag or block risky sign-ins. Since a hijacked real account is the hardest whaling variant to catch, keeping attackers out of the executive inbox in the first place is critical.
  3. Authenticate your email and expose impostors. Configure SPF, DKIM, and DMARC so spoofed messages using your domain are rejected, add external-sender warning banners, and monitor for look-alike domains so a cnicso1utions.com registration is caught before it is used.
  4. Train the people attackers target. Executives, finance, HR, and assistants need role-specific awareness training and realistic phishing simulations. The goal is a reflex: an urgent, secret money request should raise suspicion, not compliance, no matter whose name is on it.
  5. Detect and respond to compromise fast. If an account is breached, speed limits the damage. Managed detection and response watches for the signs of account takeover, such as unusual sign-ins or new inbox forwarding rules, and shuts it down before a fraudulent wire clears.

For most small and midsize businesses, standing up all five layers in-house is unrealistic. This is where a managed security partner earns its keep, deploying and monitoring these controls as a system rather than a checklist. If you are not sure where your gaps are, a cybersecurity risk assessment is the fastest way to find them.

Protect Your Executives With a Free Security Assessment
Talk to a Managed IT Team

Common Questions About Whaling

What is whaling in cybersecurity?

Whaling is a targeted phishing attack aimed at a high-ranking executive, such as a CEO or CFO. NIST calls it a specific kind of phishing that targets high-ranking members of an organization, usually to trigger fraud or steal data.

What is the difference between whaling and spear phishing?

Spear phishing targets a specific individual with a personalized message. Whaling is spear phishing aimed at the highest-value targets, senior executives, where a single successful email can authorize a large wire transfer or expose the whole company.

What is the difference between whaling and business email compromise (BEC)?

Whaling is the technique of targeting or impersonating an executive. BEC is the broader fraud scheme it often enables, where a spoofed or hijacked executive account is used to redirect a payment. Whaling is frequently the entry point for BEC.

Who is targeted in a whaling attack?

Two groups: the executive themselves (the whale), whose account or identity is the prize, and the employees who report to them, such as finance, HR, or an assistant, who can be pressured into wiring funds or sharing data.

How can businesses prevent whaling attacks?

Require out-of-band verification for any payment or banking change, enforce multi-factor authentication and conditional access, deploy email authentication (SPF, DKIM, DMARC), train executives and finance staff, and monitor for account compromise with managed detection and response.

About This Guide

The definition of whaling is taken from the NIST Computer Security Resource Center glossary (sourced to CNSSI 4009-2015). Loss figures for business email compromise, the fraud scheme whaling most often enables, are drawn from the FBI Internet Crime Complaint Center (IC3): the 2024 Internet Crime Report for annual complaint and loss totals, and the September 2024 public service announcement “Business Email Compromise: The $55 Billion Scam” for cumulative global exposure and recovery data. The average loss per incident is an original CNiC Solutions calculation from IC3 2024 figures, provided to illustrate scale, not as a guaranteed outcome for any specific business. Attack techniques and defenses reflect established guidance from these agencies and standard security practice.

Sources: NIST CSRC, whaling | FBI IC3 2024 Internet Crime Report | FBI IC3, Business Email Compromise: The $55 Billion Scam

Get an Executive IT Strategy Review

 

author avatar
David McFarlene Founder & CEO
David McFarlene is the owner and founder of CNiC Solutions, a trusted IT services and cybersecurity company serving the Houston, TX area. With over 20 years of experience in managed IT, infrastructure design, cloud solutions, and data security, David helps businesses and homeowners stay protected and productive through dependable, personalized technology support. He leads the CNiC Solutions team with a focus on reliability, transparency, and long-term relationships, ensuring clients always have a knowledgeable expert they can trust.
back to blog