Whaling: phishing that targets the executives
Whaling is spear phishing that goes after the biggest targets: the executives. The logic is simple — the higher up the org chart, the more a single compromised or impersonated account can do. A convincing "message from the CEO" carries authority that few employees will challenge.
Why executives are prime targets
- Authority — their requests are followed quickly and questioned rarely.
- Access — to finance, strategy, legal and sensitive data.
- Exposure — names, roles and events are often public, making impersonation easy to research.
- Leverage — one approved wire or shared document can be enormously costly.
What a whaling attack looks like
It may be an email "from the CEO" to finance requesting an urgent, confidential transfer; a lookalike-domain message to a board member; or a fake executive profile on social media used to build rapport before an ask. The common thread is borrowed authority plus urgency.
Whaling weaponises hierarchy: the same request that would be questioned from a peer sails through when it appears to come from the top. Process has to override deference.
How to protect leadership
- Make high-value requests verify-by-default — out-of-band confirmation for payments and data, no matter who seems to ask.
- Authenticate email (SPF, DKIM, DMARC) so the executive's real domain can't be spoofed.
- Reduce public exposure of travel, schedules and org details where possible.
- Monitor for lookalike domains and fake profiles impersonating executives.
Phish Plug watches for lookalike domains and impersonation used in executive-targeted scams, and helps take down the fake pages and profiles behind them.
The takeaway
Whaling targets the people whose word moves money and whose authority stops questions. The defence is to make verification automatic for high-value actions, shrink executives' public footprint, and watch for the impersonation that makes a whaling lure believable.
Keep reading
Related articles
Clone phishing: when a real email comes back poisoned
Clone phishing copies a legitimate message and swaps the link or attachment. Why the familiarity makes it dangerous and how to recognise and stop it.
Read article Threats · 6 minQR code phishing (quishing): the scan-and-steal scam
A QR code hides its destination until you scan it. How quishing abuses that trust, where fake codes appear, and how to defend your brand and customers.
Read article Threats · 7 minPharming: when the right address sends you to a fake site
Pharming poisons the path between a correct address and the real server. How DNS-based redirection works, why it is hard to spot, and how to reduce the risk.
Read articleProtect your brand from impersonation
Run a free clone check on one domain — Phish Plug proves the cloaking and builds the takedown case for you.