Whaling (CEO fraud)
Whaling, also known as CEO fraud, is a targeted scam aimed at senior executives, or at the people who take instructions from them, designed to get a payment made or confidential information released.
CEO fraud, also called whaling, is a form of targeted scam in which criminals go specifically after senior people in a company, the chief executive, the finance director, the people who authorise payments, with the aim of getting funds transferred or confidential information handed over.
It works through impersonation and pressure: convincing the victim they are dealing with a trusted colleague or a legitimate business partner.
When it succeeds it causes serious financial loss, and reputational damage that lasts longer than the loss does.
The methods
The techniques are consistent across cases. Spoofed email that appears to come from a legitimate internal address, or a lookalike domain that is one character different. Social engineering built on information gathered beforehand, so the message references a real deal, a real supplier or a real trip. And language engineered to create urgency, so that the recipient acts quickly and does not check.
The pressure is the mechanism. The message is nearly always urgent, confidential, and comes from somebody the recipient does not want to keep waiting.
What actually reduces it
Prevention needs both technical controls and a process people are allowed to follow.
On the technical side: multi-factor authentication on mailboxes, and email authentication through DMARC so that spoofed sender domains are rejected rather than delivered with a warning nobody reads.
On the process side, the control that works is an out of band verification rule for payment changes and unusual transfers, using a phone number already on file rather than one in the email. It has to apply to everybody, including the chief executive, because a rule that senior people are exempt from is exactly the rule this attack is built to exploit.
Awareness training matters, and it works best when it makes clear that questioning an urgent instruction from the top is expected rather than career limiting.
A worked example
An attacker sends an email to a company’s finance director, appearing to come from the chief executive.
The message says there is an urgent financial matter and that a transfer has to be made to a particular bank account immediately to avoid serious consequences for the company.
The finance director, believing they are following a direct instruction, makes the transfer without checking whether the email is genuine.
The company finds out later, and the money is generally gone within hours.
Whaling, BEC and spear phishing
The three overlap and are not interchangeable.
Spear phishing is the technique: a message written for one specific recipient using information gathered about them.
Whaling is spear phishing aimed at the top of the organisation, or at people acting on instructions from the top. The name describes the target, not the method.
Business email compromise is the broader category of email fraud against organisations, and its more damaging variants do not involve spoofing at all: the attacker has real access to a real mailbox, reads the thread, and joins a conversation that is already running. There is nothing to spot in the headers, because the headers are genuine.
In one sentence: spear phishing is how, whaling is who, and BEC is the family they both belong to.