← All terms

Whaling

Whaling is a spear phishing attack specifically targeting senior executives or high-value individuals within an organization.

Whaling is spear phishing directed at the biggest targets in an organization — C-suite executives, board members, and senior leaders who have authority to approve large transactions or access sensitive data.

How it works

Whaling attacks exploit the authority and access that executives hold:

  • Legal or regulatory pretexts. A fake subpoena, regulatory inquiry, or board-related document arrives as an attachment or link. Executives are conditioned to treat legal matters as urgent and confidential.
  • CEO-to-CFO impersonation. The attacker spoofs the CEO's email and requests an urgent wire transfer, leveraging the power dynamic — subordinates are reluctant to question a direct order from the top.
  • Board communication. Fake meeting invites or shared documents from a board portal exploit the expectation that board materials are time-sensitive and restricted.

Because executives often operate outside standard security controls — personal devices, executive assistants managing email, exemptions from MFA — they can be both the most targeted and the least protected employees.

How to defend against it

  • Include executives in simulation programs. Many organizations exempt leadership from phishing tests, creating the widest gap where the risk is highest. NOUSEC simulations test all levels of the organization.
  • Enforce verification procedures for financial transactions — dual approval, callback to a known number, and mandatory delay on large transfers.
  • Remove executive exemptions from MFA, email filtering, and endpoint policies. Privileged access should mean more security controls, not fewer.
  • Monitor executive impersonation. Track lookalike domains and display-name spoofing targeting senior leaders.

Related terms

Spear PhishingSpear phishing is a targeted phishing attack that uses personalized information about the victim to increase its effectiveness.Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo