RESOURCES · SECURITY & EMAIL

What is
whaling?

Whaling is phishing aimed at the "big fish" — your CEO, your directors, or the people who can move money. Instead of a scattergun scam, it's a targeted, well-researched con built to look like a genuine request from (or to) a senior leader. Here's how it works, and how to protect your business.

Applies to: Leaders & finance teams Read: ~4 min Level: Non-technical
Quick answer

Whaling targets senior people — or impersonates them — to trick staff into paying an invoice, moving funds or handing over sensitive data. It runs on authority and urgency: "I need this done now, I'm in a meeting, don't call." The single best defence is a simple rule: verify any money or data request through a second, trusted channel — every time.

HOW IT WORKS

A researched, targeted con.

Whaling isn't a lucky guess — it's homework, then pressure:

Before a single message is sent, attackers research your business. They study your website, comb through LinkedIn, and scroll your social media to learn who's in charge, who handles the money, who's away travelling, and how your people talk to each other. Armed with that, they take one of two routes: they either target an executive directly — trying to hook the leader themselves — or they impersonate one to pressure a subordinate, most often someone in finance who's used to acting on the boss's word.

The usual ask is designed to move value fast: an urgent payment, a change of bank details on a legitimate supplier, a quick run of gift cards, or a slice of confidential information they can use in the next attack. Because it looks like it came from a person you trust, it sails past the usual caution.

THE RED FLAGS

What to watch for.

Whaling has a recognisable shape. If a request has these features, slow down:

WHY LEADERS ARE THE TARGET

Big fish, bigger payoff.

Senior people are worth the extra effort for three reasons. They have more authority and access — they can approve payments and reach sensitive information. They're publicly known, so their name, title and role are easy to find and easy to imitate. And crucially, staff are reluctant to question or slow down a request from the boss — nobody wants to be the person who held up something the CEO said was urgent. Attackers know that hesitation, and they lean on it hard.

HOW TO PROTECT YOUR PEOPLE

Make the scam fail by default.

The goal is a business where this con simply doesn't work, no matter how convincing it looks:

  1. Verify out-of-bandBefore acting on any money or data request, call the person on a number you already have — never a number from the email. A 30-second phone call defeats almost every whaling attempt.
  2. Build a second-check into paymentsHave a payment and bank-change process that always requires an independent second person to confirm — especially for new accounts or changed details. Make it the rule, not the exception.
  3. Brief your leaders and finance teamWalk your executives and finance staff through exactly this scam, using real examples. When people have seen the trick before, they spot it in the moment.
  4. Add technical protectionsLayer on email filtering, impersonation protection, and "external sender" banners so lookalike and spoofed messages are flagged before anyone acts on them.
No email is proof. A request to move money or change bank details should never be actioned on email alone — no matter how senior the sender appears, and no matter how urgent it feels. If it involves funds or sensitive data, confirm it through a second, trusted channel first. Every time.
PROTECT YOUR LEADERSHIP

Would your team pause before paying the "CEO"?

Whaling only works when a convincing email meets a process that trusts it. Our free IT Health Check reviews your email impersonation protection and your payment-verification habits — so a fraudulent "urgent" request from the top gets caught and questioned, not quietly paid.

KEEP READING

Related resources