Whaling
Whaling is spear phishing aimed at senior executives. The defining feature is who the target is, not who the message appears to come from — and that distinction separates it from CEO fraud, where an executive is impersonated rather than attacked. The two are routinely conflated, including by vendors, and keeping them apart is the point of this page.
| What it is | Spear phishing where the recipient is a senior executive or board member |
| Also called | Whale phishing, executive phishing |
| Who is the victim | The executive — they receive the message |
| Distinct from CEO fraud | There, the executive is impersonated and someone else is the victim |
| Why executives are chosen | Authority, system access, and the ability to approve exceptions |
| Typical pretexts | Legal action, a regulatory matter, a board issue, a confidential transaction |
| Structural weakness | Executives are often exempted from the controls applied to everyone else |
| Escalation | Synthetic audio and video used to impersonate executives on calls |
Whaling and CEO fraud are opposite directions
This is the distinction worth taking away, and most definitions blur it.
| Whaling | CEO fraud | |
|---|---|---|
| The executive is | The target | The disguise |
| Who receives the message | The executive | A finance or accounts payable employee |
| What the attacker wants | The executive’s credentials, access or authorization | A payment made on the executive’s apparent instruction |
| Exploits | Authority combined with exemption from controls | Authority combined with reluctance to question it |
| Sits under | Spear phishing | Business email compromise |
Usage does vary — some sources use whaling loosely for anything involving an executive, in either direction. Where the term appears in a vendor document or a control description, it is worth establishing which is meant, because the defenses are different. Defending executives is an access and process problem; defending against CEO fraud is a payment authorization problem.
Why executives are unusually exposed
The reasons are organizational rather than personal, which is why the problem persists across companies.
They are publicly identifiable. Names, roles, biographies, travel and commitments are in filings, press releases and conference programs. The reconnaissance described under spear phishing is easier for a CEO than for anyone else in the organization.
They are frequently exempted. Executives are the people most likely to have been granted an exception to a security control — a device policy, an email restriction, a step-up requirement — on the grounds that it impeded their work. The exemption is granted by people who report to them.
Their assistants are a parallel target. Executive assistants have delegated access to calendars, mail and sometimes approvals, and rather less security attention.
Refusal is costly. An IT team enforcing a control against an executive is contradicting someone senior, and that asymmetry decides more security outcomes than any technical factor.
Why this matters for identity verification
Two connections, and the second is the live one.
Access recovery. An executive account is the highest-value recovery target in an organization, and recovery for a senior person is often handled as a courtesy — a call to a help desk that recognizes the name and wants to be helpful. That is an identity question being answered by familiarity. Re-establishing identity with an authenticated document and a live biometric is the control that does not bend to seniority.
Synthetic media. Executives are the most recorded people in any organization — earnings calls, conference talks, interviews, podcasts. That recorded material is training data, and it makes them the easiest people to impersonate convincingly with synthetic audio or video. The same exposure that makes them easy to research makes them easy to clone, which is why deepfake detection has become an executive-protection question as much as a fraud-team one. GenAI detection and deepfake analysis addresses the media; identity document verification addresses the recovery path.
What controls can’t do
They cannot reduce an executive’s public profile. Disclosure is mandatory and visibility is part of the role.
They cannot survive exemption. A control that senior people are excused from does not protect the people most targeted.
Training is weakest where it is needed most. Executives have the least time for it and the most persuasive attacks aimed at them.
Recognizing a voice or face is no longer verification. Any process resting on knowing what someone sounds like needs rebuilding around evidence rather than recognition.
Frequently asked questions
What is whaling in cybersecurity?
Spear phishing aimed at senior executives or board members. The target is chosen for their authority, system access and ability to approve exceptions, and the pretexts used tend to be legal, regulatory or board matters that justify urgency and confidentiality.
What is the difference between whaling and CEO fraud?
Direction. In whaling the executive is the target and receives the message. In CEO fraud the executive is impersonated and someone else — usually in finance — receives it. Usage varies and some sources blur the two, so it is worth confirming which is meant in any given document, because the defenses differ.
Why are executives harder to protect?
Because the exposure is structural. They are publicly identifiable through filings and press coverage, they are the people most likely to have been granted exceptions to security controls, their assistants hold delegated access with less scrutiny, and enforcing a control against them means contradicting someone senior.
Why does deepfake risk concentrate on executives?
Because they are the most recorded people in an organization. Earnings calls, conference talks and interviews provide ample material for synthetic voice and video, so the same public visibility that makes them easy to research makes them the easiest to impersonate convincingly.
Related reading
- Spear phishing — the parent technique, and how the research is assembled
- CEO fraud — the other direction — the executive as disguise rather than target
- Deepfake — why the most recorded people are the easiest to clone
- Business email compromise — the wider category these payment-directed attacks sit in