Whaling: Phishing Aimed at Executives
Whaling targets senior leaders with legal, board and deal-related lures, or impersonates them to staff. How whaling works and the routines that protect executives and organizations.

Whaling is phishing aimed at the biggest fish: chief executives, finance directors, board members and other senior leaders. The lures are tailored to their world, such as legal notices, regulatory matters, board papers and confidential deals, and the rewards for attackers are large.
Common whaling lures
- Legal subpoenas or complaints requiring urgent review.
- Regulator or auditor requests.
- Board documents or confidential merger materials on a "secure portal".
- Invitations to speak at prestigious events.
- Personal lures: family, charities, investments.
The other side: impersonating executives
Attackers also pretend to be executives to trick staff into urgent payments, gift card purchases or data transfers. See the gift card request from your boss and business email compromise.
Why executives are exposed
- Public profiles, interviews and travel schedules.
- Assistants and deputies who act on their behalf.
- Busy schedules and pressure to act fast.
- Sometimes, exemptions from security controls "for convenience".
Protective routines
- No exemptions: executives use the same or stronger controls as everyone else.
- Phishing-resistant sign-in: passkeys or security keys. See security keys.
- Agreed verification between executives, assistants and finance for any payment or sensitive request.
- Limited public detail about travel and schedules.
- Separate personal and work accounts, both secured.
Leaders set the tone. When executives welcome being verified, staff feel safe checking unusual requests.
Unsure about a high-stakes email? Paste it into CyberWatch AI Scan for a free check.
For all the types of phishing, read our complete guide.
Frequently asked questions
What is the difference between whaling and CEO fraud?
Whaling targets executives themselves. CEO fraud impersonates executives to trick staff. Both involve senior leaders and often large sums.
Why target executives?
They have authority, access to sensitive information and power to approve payments, and they are often busy and public.
What helps most?
Assistants and executives agreeing verification routines, phishing-resistant sign-in, and limiting public information about schedules.
Sources
- Small business guide: cyber security, UK National Cyber Security Centre
- Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
- Cybersecurity for Small Business, US Federal Trade Commission


