What Is a Whaling Attack? The 2026 Guide to Executive-Targeted Phishing

Key takeaways
- A whaling attack is a highly targeted form of spear phishing that targets senior executives, board members, and others with unusually valuable authority, access, or information.
- Whaling is defined by who the attacker targets. Executive impersonation and CEO fraud may target an employee instead, even when the attacker disguises themselves as a senior leader.
- Prevention requires layered controls: independent verification, phishing-resistant authentication, enforced approval processes, careful management of public exposure, and role-specific simulations.
Most phishing attacks are built to reach as many people as possible. Whaling takes the opposite approach.
A whaling attack targets senior executives and other high-value individuals whose access, authority, or information makes them especially valuable to an attacker. Instead of sending thousands of generic messages and hoping someone responds, attackers research a single target and build a social engineering campaign specifically for that person.
The potential payoff explains the extra effort. An executive may be able to approve large financial transactions, access confidential company information, or authorize actions that other employees can’t.
Generative AI has given attackers new ways to make these attempts more convincing, but whaling itself isn’t new. Executive-targeted phishing has been costing organizations money for more than a decade.
Whaling Attack: Definition & Meaning
A whaling attack is a highly targeted form of phishing aimed at senior executives, board members, and other high-profile people within an organization.
Whaling falls under the broader category of spear phishing. Both use research and personalization to target specific individuals, but whaling focuses on people whose positions give them unusually valuable access or authority.
That changes the type of lure an attacker can use. A generic password-reset email may be enough for a broad phishing campaign, while an executive could receive a request involving an acquisition, legal matter, board decision, regulatory issue, or another topic that fits the person's responsibilities.
Executives are also valuable for the information they can access. Their accounts may contain financial records, strategic plans, legal communications, customer data, or details about transactions not yet publicly announced.
In short, whaling is defined primarily by the target: The attacker pursues a ‘big fish’ whose position could unlock an unusually valuable outcome.
Who is Targeted in a Whaling Attack?
Senior executive or another high-value person whose organizational position creates leverage for the attacker are always the targets in these types of attacks.
Common targets include: CEOs, CFOs, CIOs, board members, business-unit leaders, and senior finance executives. The target doesn’t have to hold a C-suite title, though. Control over sensitive systems, financial approvals, confidential information, or strategic decisions can make someone valuable enough to pursue.
People surrounding executives may be attacked too, but the terminology changes. If an attacker impersonates the CEO to pressure an accounts payable employee into wiring money, that’s typically described as CEO fraud or business email compromise. If the attacker directly deceives the CEO, CFO, or another senior leader, the attack fits the stricter definition of whaling.
4 Types of Whaling Attacks
Whaling attacks can pursue several goals, and a single campaign may combine more than one.
- Credential theft: The attacker attempts to steal credentials that provide access to email, cloud services, financial systems, or other corporate resources.
- Sensitive data theft: The target is persuaded to provide financial records, board materials, legal documents, employee data, customer information, or details about an upcoming transaction.
- Financial fraud: The attacker tries to persuade the executive to authorize a wire transfer, change payment information, or approve another financial transaction.
- Voice and video impersonation: The attacker uses phone calls, AI-generated audio, or deepfake video to make an executive-targeted deception more convincing.
Keep in mind that these categories overlap. Stolen executive credentials can expose sensitive information and provide a trusted account for additional attacks inside the organization.
Whaling also intersects with BEC, although the terms aren’t interchangeable. The FBI's 2025 IC3 Annual Report recorded 24,768 BEC complaints and approximately $3.05 billion in reported losses. Those figures cover the broader BEC category, not whaling alone, but they show the financial stakes surrounding targeted business impersonation.
How Does a Whaling Attack Work?
Whaling usually begins before the first message reaches the target.
Senior executives tend to have significant public footprints. Attackers can use open-source intelligence - including company websites, earnings calls, interviews, LinkedIn, conference appearances, and press releases - to understand an executive's role, relationships, priorities, travel, and communication style.
They don’t need a complete picture. A few accurate details can make a false request feel routine.
An announced acquisition could provide cover for a confidential financial request. A new partnership might give the attacker the name of a company the executive expects to hear from. The objective is to build a pretext that fits the target's workday rather than one that immediately feels out of place.
A typical whaling attack follows five stages:
- Research: The attacker identifies a high-value target and gathers public or stolen information about the person and organization.
- Pretext creation: The attacker builds a believable story involving a real responsibility, relationship, project, or deadline.
- Delivery: The first contact arrives through email, SMS, phone, a collaboration platform, or video.
- Pressure: The attacker uses urgency, authority, secrecy, or fear to shorten the time available for verification.
- Action: The attacker pushes the target to disclose information, open a fake login page, approve a payment, or bypass a normal process.
Some campaigns move between channels to create apparent confirmation. A text might follow an email, or a voice call might reinforce instructions delivered through a collaboration platform. The channel can change, but the goal is always to make the target act before independent verification catches up.
3 Real-World Whaling & Executive Fraud Examples
Real incidents show both how long executive-targeted social engineering has worked and how the techniques are changing, illustrating an important distinction: An executive can be the target of an attack or the identity being impersonated. Only the former automatically makes an attack a whaling attack.
Mattel’s $3 Million Whaling Attack
One of the clearest examples dates to 2015, long before generative AI and deepfake impersonation became part of the social engineering landscape.
Mattel had recently appointed Christopher Sinclair as CEO when a finance executive received what appeared to be an email from Sinclair requesting a payment to a vendor in China. The request fit Mattel's internal financial procedures closely enough to work, and the executive wired more than $3 million.
The fraud was discovered when the executive later mentioned the payment to Sinclair, who knew nothing about it. Mattel was unusually fortunate: A bank holiday in China gave authorities time to freeze and recover the funds, according to the Associated Press.
The case remains instructive. The attacker didn’t need AI-generated audio or video. A convincing identity, the right target, and a plausible request were enough.
WPP’s 2024 Deepfake Executive Attack
The tools available to attackers have since become considerably more sophisticated.
In 2024, WPP CEO Mark Read warned employees about an attempted fraud involving a fake WhatsApp account, a Microsoft Teams meeting, an AI-generated voice clone, and publicly available video footage.
The attackers used Read's image to create the WhatsApp account and impersonated Read and another senior WPP executive during the virtual meeting. They targeted another agency leader, whom they tried to persuade to start a new business and provide money and personal information.
The attempt failed when the target became suspicious. The Guardian's report on the WPP incident shows how several channels and forms of impersonation can support the same false story.
Unlike the Mattel case, the WPP attempt used AI to strengthen an established social engineering technique rather than create an entirely new attack category.
$25 Million Arup Fraud
A 2024 fraud in Hong Kong helps show where the terminology changes.
An employee at engineering firm Arup joined a video conference in which apparent senior company officials requested financial transfers. The voices and images were fake. The employee ultimately sent HK$200 million, or about $25 million at the time, through 15 transactions, according to reporting on Arup's confirmation of the attack.
Despite the executive impersonation, this isn’t a whaling attack under a strict definition. The attackers impersonated the executives, not the employee. The employee who authorized the transfers was the direct target.
That distinction explains why whaling, CEO fraud, BEC, and executive impersonation often appear in the same discussion but don't mean exactly the same thing.
Whaling vs Spear Phishing: What is the Difference?
Whaling is a specialized form of spear phishing distinguished primarily by its target.
Spear phishing uses a personalized attack against a specific person or group. The target could be an accountant, engineer, HR employee, salesperson, or anyone else whose access or information an attacker can use.
Whaling narrows that focus to senior executives and other high-profile individuals. The techniques can be similar: malicious links, fake login pages, impersonation, voice calls, SMS, or video. What changes is the target's value and authority and, often, how much preparation the attacker is willing to invest.
A spear phishing attack might target a payroll employee to obtain employee records. A whaling attack could target the CFO to access financial information or authorize a high-value transaction.
How to Prevent a Whaling Attack: 5 Tips
Executives are attractive targets precisely because organizations need them to have access and authority. Prevention should protect that authority without preventing leaders from doing their jobs.
1. Account for Executive Exposure
Eliminating an executive's public presence isn’t realistic, but organizations should understand what attackers can learn from it.
Public information can reveal responsibilities, business relationships, travel, upcoming events, speech patterns, and other context useful for a targeted attack. Security teams can use the same information to assess risk and create realistic executive training.
The objective isn’t to make leadership invisible. It’s to recognize which details could make an impersonation or phishing attempt more credible.
2. Independently Verify Sensitive Requests
A convincing identity shouldn’t be enough to approve a consequential action.
Requests involving large payments, changes to banking information, credentials, sensitive documents, or exceptions to established procedures should trigger a separate verification process.
That verification must use information or a channel already known to be legitimate. CISA advises people not to use links or phone numbers from a suspicious message and instead to verify through a known contact method.
3. Protect Executive Accounts with Strong Authentication
Stealing an executive's credentials can give an attacker access to the real account rather than forcing the attacker to imitate it.
Multi-factor authentication can make stolen passwords less useful, particularly when the organization adopts phishing-resistant methods. CISA recommends moving toward FIDO/WebAuthn authentication because it’s designed to resist credential phishing.
Organizations should also monitor executive accounts for unusual logins, new forwarding rules, unexpected account changes, suspicious session behavior, and changes to recovery or MFA settings.
4. Don’t Let Authority Override Approval Processes
Whaling exploits the tendency to give unusual requests more latitude when they appear to come from senior leadership.
Financial and data-handling procedures should still apply when the requester appears to be the CEO, CFO, or another executive. High-value transactions can require multiple approvals, while unusual payment changes can trigger mandatory independent verification.
Leadership needs to support those controls. Employees should know that verifying an executive request is part of the process, not an obstacle.
5. Train Executives with Attacks Designed for Executives
Generic phishing simulations don’t necessarily show how someone will respond to an attack built around their actual role and authority.
Executive training should reflect the requests leadership could plausibly receive and the channels attackers now use. Personalized simulations can test whether an executive verifies a believable request, not merely whether the person recognizes an obvious phishing email.
Adaptive Security uses public signals and organizational context to create personalized phishing simulations across email, voice, and deepfake scenarios. That gives executives and those around them practice responding to attacks that resemble the ones they're most likely to encounter.
Prepare Executives for Whaling Attacks in 2026
Whaling works by tailoring an attack to someone whose access or authority makes the effort worthwhile.
The Mattel case shows that the approach was effective long before generative AI. The WPP attempt shows how modern impersonation tools can make the same underlying deception more convincing. The Arup fraud shows why verification can’t rely on a familiar face or voice alone.
Defending against whaling requires similarly targeted preparation. Strong account security and approval procedures reduce opportunities for attackers, while realistic training gives executives practice questioning requests designed specifically to earn their trust.
Adaptive Security combines next-generation, role-based security awareness training with phishing simulations built for today's social engineering, including email, voice, and deepfake impersonation.
For a deeper look at protecting senior leadership, check out Whaling & CEO Fraud: Defending the C-Suite Against AI Impersonation. The guide covers whaling, CEO fraud, deepfake impersonation, and the technical and procedural defenses organizations can use to protect the C-suite.
Frequently Asked Questions
What is a whaling attack in cybersecurity?
A whaling attack is a highly targeted form of spear phishing aimed at a senior executive, board member, or other high-value person. The attack uses personalization and social engineering to steal information, credentials, money, or access.
What type of phishing attack is whaling?
Whaling is a subtype of spear phishing. All whaling attacks are targeted, but they’re distinguished by their focus on senior or high-authority individuals.
Who is the focus of a whaling attack?
The focus is usually a CEO, CFO, board member, general counsel, senior finance leader, or another person with unusually valuable access or decision-making power.
Is whaling a social engineering attack?
Yes. Whaling relies on psychological manipulation, such as authority, urgency, secrecy, trust, or fear, to make a high-value target take an unsafe action.
What is the difference between whaling and spear phishing?
Spear phishing can target any specific person or group. Whaling is the executive-focused subset of spear phishing, aimed at people whose position makes a successful attack especially valuable.
What is the difference between whaling and CEO fraud?
Whaling directly targets an executive or another high-value person. CEO fraud usually impersonates an executive to manipulate an employee, vendor, or business partner. A campaign can involve both techniques.
What are examples of whaling attacks?
Examples include a fake legal request sent to general counsel, a fraudulent acquisition payment sent to a CFO, a credential-harvesting page tailored to a CEO, or a voice-cloned call designed to get an executive to approve a transaction.
How can organizations prevent whaling attacks?
Use phishing-resistant MFA, require independent verification for sensitive requests, enforce multi-person approvals, monitor executive accounts, review public exposure, and run realistic, role-specific simulations across email, voice, and video.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Related articles

Phishing Awareness Training for Remote Employees: Build Skills That Stop Social Engineering Across Every Channel

10 Benefits of Cybersecurity Awareness Training for Remote Employees That Reduce Human Risk Across Distributed Teams

