Whaling is a targeted phishing attack aimed at a high-ranking executive, such as a CEO or CFO, to steal money or sensitive data. Attackers impersonate or hijack a trusted leader’s identity, then use authority and urgency to push an employee into wiring funds or handing over confidential information.
A whaling attack does not look like the phishing you were trained to spot. There is no misspelled link, no strange attachment, no obvious scam. Instead there is a short, calm email that appears to come from your CEO, asking finance to quietly wire a payment before end of day. Because it carries the weight of authority and a deadline, it works. Whaling is the reason a single email can cost a business six or seven figures, and understanding exactly how it operates is the first step to stopping it.

Whaling is a form of phishing that goes after the “big fish” of an organization: the executives and senior leaders whose authority, access, and signing power make them the most valuable targets in the building. The National Institute of Standards and Technology defines it plainly as a specific kind of phishing that targets high-ranking members of organizations. The name is deliberate. Ordinary phishing casts a wide net for any fish it can catch. Whaling hunts one large, high-value target on purpose.
The word “target” cuts two ways, and this is where whaling gets its power. An attack can be aimed at an executive, trying to steal the login credentials or take over the email account of a CEO or CFO. Or it can impersonate that executive, using their name and authority to deceive the people who work for them. In practice the two blend together. A criminal who compromises a CEO’s real inbox can then send flawless internal requests from it, and those requests are almost impossible for staff to question.
Whaling belongs to the broader family of social engineering, where the attacker manipulates a person rather than breaking software. It does not exploit a firewall or a bug. It exploits trust in the org chart. That is what makes it so effective and so hard to filter out with technology alone.
Source: NIST Computer Security Resource Center, glossary definition of whaling
A whaling attack is patient and researched, not a mass blast. It usually unfolds in five stages.
The entire scheme hinges on one thing: that a busy, trusted-looking request will be acted on without an independent check. Every effective defense, which we cover below, is really just a way of forcing that check to happen.
These three terms describe the same basic weapon, a deceptive message, aimed with increasing precision. The confusion is understandable, so here is the clean distinction.
| Attribute | Phishing | Spear Phishing | Whaling |
|---|---|---|---|
| Target | Anyone, sent in bulk | A specific named individual | A specific senior executive |
| Personalization | Generic (“Dear customer”) | Tailored with real details | Deeply researched, role-aware |
| Volume | Thousands of recipients | A handful | Often one |
| Goal | Credentials, malware, small payouts | Access to a person or team | Large wire transfers, sensitive data, account takeover |
| Typical payload | Malicious link or attachment | Link or crafted request | Text-only request, no payload |
The simplest way to remember it: all whaling is spear phishing, and all spear phishing is phishing, but the reverse is not true. Whaling is the sharpest tip of the spear, reserved for the targets with the most money and access.
One more term is often tangled up with whaling: business email compromise, or BEC. They are related but not identical. Whaling is the technique of targeting or impersonating an executive. BEC is the broader fraud scheme that technique usually serves, in which a spoofed or hijacked executive account is used to redirect a legitimate-looking payment. When you read that a company “lost money to CEO fraud,” you are almost always looking at whaling used to carry out BEC. That link matters, because it is through BEC reporting that we can actually measure the damage.
Because whaling is the doorway to business email compromise, the scale of BEC losses is the clearest measure of what whaling costs. The FBI’s Internet Crime Complaint Center (IC3) tracks it every year, and the numbers are staggering.
That single-year figure sits on top of a decade of compounding damage. In a September 2024 alert, the FBI put the total exposed loss from BEC at more than $55 billion between October 2013 and December 2023, spanning all 50 states and 186 countries.
To see how BEC stacks up against every other category of cybercrime, look at where it landed among the FBI’s 2024 loss totals. Only investment fraud, a consumer scam, cost Americans more.
Top Cybercrime Categories by Reported Loss, U.S. 2024 (FBI IC3)
Business email compromise was the second-costliest cybercrime reported to the FBI in 2024. Source: FBI IC3 2024 Internet Crime Report.
The reason each incident hits so hard is the target. When the average is worked out, the damage per case is severe.
CNiC Solutions analysis: Dividing the FBI’s 2024 BEC losses ($2,770,151,146) by the number of complaints (21,442) yields an average reported loss of roughly $129,000 per incident. Calculation and interpretation original to CNiC Solutions, based on FBI IC3 2024 data.
There is a sliver of good news. When a fraudulent wire is caught fast, it can sometimes be frozen. The FBI’s Recovery Asset Team, which works most often on BEC cases, acted on 3,020 incidents in 2024 and helped freeze funds at a 66% success rate, but only when victims reported quickly. Speed is everything, and prevention still beats recovery by a wide margin.
Myth: our spam filter or email security will catch a whaling email. It usually will not. Whaling messages are sent in tiny volumes, contain no malicious link or attachment for a scanner to flag, and are often written in plain, professional language. When the attacker uses a compromised real account or a freshly registered look-alike domain, the message passes technical checks and lands in the inbox looking completely legitimate. Whaling is defeated by process and people, not by filters alone.
Source: FBI IC3 2024 Internet Crime Report | FBI IC3, Business Email Compromise: The $55 Billion Scam
Whaling is not one script. It is a set of pretexts, each chosen to fit how money and data actually move through a business. These are the patterns the FBI and security teams see most often.

The classic. An email that appears to be from the CEO or owner asks finance to send an urgent wire for a confidential deal, an overdue supplier, or an acquisition. The request stresses discretion and a deadline so the employee acts before verifying. This is the single most common and most expensive form of whaling.
The attacker, posing as an executive or a known supplier, asks that a vendor’s bank details be “updated” before the next payment run. The invoice looks real because it often is a copy of a legitimate one. The only change is the destination account. The next routine payment goes straight to the criminal.
Not every whaling attack chases a wire. Some, timed around tax season, impersonate a leader and ask HR or payroll for employee W-2 forms or a payroll data export. The stolen tax and identity data is then used for fraudulent tax refunds or sold, turning one email into a mass identity-theft event.
Here the lure is a supposed lawyer or the executive referencing sensitive litigation or a merger. Secrecy is baked into the story, which discourages the target from checking with anyone. The confidential framing is the manipulation: it isolates the victim from the very colleagues who could expose the fraud.
Every one of these tactics is a variation on the same theme. They borrow real authority and add a reason not to double-check. Recognizing the pattern is more durable than memorizing any single script, and it is exactly what a well-designed phishing email review habit trains your team to see.
Because whaling attacks people and process, the strongest defenses are layered controls that assume a convincing fake will eventually reach an inbox. No single tool stops it. These five layers, working together, do.
For most small and midsize businesses, standing up all five layers in-house is unrealistic. This is where a managed security partner earns its keep, deploying and monitoring these controls as a system rather than a checklist. If you are not sure where your gaps are, a cybersecurity risk assessment is the fastest way to find them.
Protect Your Executives With a Free Security Assessment
Talk to a Managed IT Team
The definition of whaling is taken from the NIST Computer Security Resource Center glossary (sourced to CNSSI 4009-2015). Loss figures for business email compromise, the fraud scheme whaling most often enables, are drawn from the FBI Internet Crime Complaint Center (IC3): the 2024 Internet Crime Report for annual complaint and loss totals, and the September 2024 public service announcement “Business Email Compromise: The $55 Billion Scam” for cumulative global exposure and recovery data. The average loss per incident is an original CNiC Solutions calculation from IC3 2024 figures, provided to illustrate scale, not as a guaranteed outcome for any specific business. Attack techniques and defenses reflect established guidance from these agencies and standard security practice.
Sources: NIST CSRC, whaling | FBI IC3 2024 Internet Crime Report | FBI IC3, Business Email Compromise: The $55 Billion Scam
Get an Executive IT Strategy Review
Yes: almost every business that offers Wi-Fi to customers, clients, or visitors needs a separate guest…
Vishing, short for voice phishing, is a scam in which criminals use phone calls or voicemail…
Social engineering is the use of psychological manipulation to trick people into revealing confidential information, granting…
Virtual desktop infrastructure (VDI) is technology that hosts full desktop operating systems on centralized servers in…