A whaling attack, also known as whale phishing, is a highly targeted phishing attempt aimed at senior executives, such as a CEO, CFO, or General Counsel, that impersonates a trusted figure to extract money, credentials, or sensitive data. The term comes from the idea of going after the "big fish" in an organization rather than casting a wide net. Because whaling attacks are built around a specific person's role, authority, and communication style, they tend to be more convincing and more costly than ordinary phishing. This guide covers how whaling attacks work, how they differ from spear phishing, real examples, and what actually stops them.
Key Takeaways
- Because whaling targets the people whose approval alone can move money or unlock sensitive systems, a single successful attempt can cost an organization millions, and has been enough to sink a company entirely.
- Whaling differs from spear phishing by narrowing the target specifically to people whose approval alone can move money or unlock sensitive systems.
- Compromised-account whaling, where the attacker works from inside a real executive mailbox, is harder to detect than a spoofed sender and increasingly common.
- Real incidents like the 2020 Levitas Capital attack ($8.7 million) and the 2024 Arup deepfake video call ($25 million) show how costly a single successful whaling attempt can be.
- Out-of-band verification for financial requests is the single most effective defense against whaling.
What Is a Whaling Attack?
A whaling attack is a form of spear phishing that targets high-ranking executives specifically because of the access, authority, and financial control they hold. Attackers research a target's role, reporting structure, and communication habits, then impersonate a trusted figure, often another executive, a board member, or outside counsel, to pressure the victim into an urgent wire transfer, a credential handover, or the release of confidential data. The payoff for a successful whaling attack is usually much larger than a typical phishing attempt, which is why attackers invest more time researching the target before sending a single message.
Whaling vs. Spear Phishing vs. Phishing
Phishing, spear phishing, and whaling describe the same underlying tactic, impersonation to extract money, credentials, or data, applied at different levels of precision.
Whaling is best understood as spear phishing narrowed to the people whose approval alone can move money or unlock sensitive systems. That narrower focus is also why whaling attacks are harder to catch with generic filtering. A message built around a real executive's name, cadence, and current priorities does not look like bulk spam.
How Whaling Attacks Work
Most whaling attacks follow a predictable arc, even when the specific pretext changes.
Executive impersonation. The attacker either spoofs an executive's email address, registers a lookalike domain, or, in the more damaging cases, works from inside a real compromised executive mailbox. Compromised-account whaling is harder to catch than a spoofed sender, because the message comes from a legitimate, previously trusted address with a real send history.
Urgency and confidentiality framing. The request is time-sensitive and often marked confidential, which discourages the recipient from checking with anyone else before acting. A message asking someone to "keep this between us until the announcement" removes the normal instinct to verify.
Financial or data requests. The ask is usually a wire transfer, a gift card purchase, a change to vendor payment details, or a request for sensitive files like tax documents or M&A materials.
Fake legal or M&A pressure. Some of the most convincing whaling attempts invoke pending litigation, an acquisition, or a regulatory deadline, since employees are less likely to question a request tied to legal exposure. See how phishing emails outsmart users and bypass detection for more on how attackers exploit urgency and authority across phishing types generally.
Real-World Examples of Whaling Attacks
Levitas Capital. In 2020, the Australian hedge fund Levitas Capital was targeted through a whaling attack that began with a fake Zoom meeting invite sent to a co-founder, purportedly from a business contact. The link installed malware that gave attackers access to the firm's email systems, which they then used to authorize roughly $8.7 million in fraudulent payments. The fund recovered most of the money but lost its largest client and shut down within months, illustrating how a single successful whaling attempt can end a company, not just cost it money.
Arup, Hong Kong. In 2024, an employee at the UK engineering firm Arup's Hong Kong office was invited to a video call that appeared to include the company's CFO and other colleagues. Every other participant on the call was an AI-generated deepfake. Believing the request was legitimate, the employee authorized transfers totaling roughly $25 million. The case is one of the clearest examples of how whaling has evolved: attackers are no longer limited to email impersonation, and a live video call is no longer automatic proof of identity.
Both cases share the same underlying pattern: a request that looked routine enough, and came from someone senior enough, that the person receiving it did not stop to verify it through a second channel.
Warning Signs of a Whaling Attack
- Unusual urgency paired with a request to bypass the normal approval process
- Instructions to keep the request confidential or avoid discussing it with colleagues
- A tone or phrasing that does not match how the executive normally writes
- A request involving a new payment destination, vendor, or account
- Contact through an unfamiliar channel, such as a personal email address or a new messaging app, for a request that would normally go through official channels
How to Prevent Whaling Attacks
Require out-of-band verification for financial requests. Any request involving a wire transfer, a change in payment details, or the release of sensitive data should be confirmed through a second channel, such as a phone call to a known number, before it moves forward. This single habit stops the majority of whaling attempts, since it breaks the urgency the attacker is counting on.
Harden executive accounts specifically. Executives are higher-value targets, so their accounts warrant stronger authentication, closer monitoring for unusual login or forwarding activity, and faster response if something looks off. See preventing VIP impersonation attacks.
Train on whaling specifically, not just generic phishing awareness. Standard security awareness training that only covers spelling errors and suspicious links will not prepare employees to catch a compromised-account whaling attempt or a deepfake video call. The goal is to help staff treat urgency and unquestioned authority as red flags in their own right.
Detect compromised-account whaling, not just spoofed senders. Rule-based filters that look for spoofed domains or known-bad senders miss the harder case: an attacker working from inside a real, previously trusted executive mailbox. Effective detection needs to look at behavior, not just sender identity. See email security and stopping business email compromise and vendor email compromise.
How Material Helps Stop Whaling Attacks
Material detects whaling attempts by analyzing behavior across the mailbox rather than relying on a static list of known-bad senders. That includes flagging VIP impersonation attempts, catching credential-harvesting attacks that carry no obvious malicious link or attachment, and identifying account activity consistent with a compromise already in progress. If a whaling attempt reaches an inbox before it is flagged, Material can move and reclassify the message after delivery, and one confirmed pattern protects the rest of the organization automatically. See stopping sophisticated email attacks.
Stop Whaling Attacks Before They Reach Your Executives
Whaling attacks succeed because they are built around a real person's authority, not a generic pretext, which is exactly what makes them hard to catch with filtering alone. Material connects directly to Google Workspace and Microsoft 365 by API, giving it the context to catch VIP impersonation and compromised-account whaling that static rules miss, and to contain the damage automatically if an attempt gets through. To see where your organization's exposure stands, run the free Workspace Security Scorecard, or get a demo to see Material in action.
Whaling Attack FAQs
What is a whaling attack?
A whaling attack, also called whale phishing, is a highly targeted phishing attempt aimed at senior executives, such as a CEO or CFO, that impersonates a trusted figure to extract money, credentials, or sensitive data. It is a form of spear phishing narrowed specifically to people whose approval alone can move money or unlock sensitive systems. The name comes from targeting the "big fish" in an organization rather than a broad list of recipients.
What is the difference between whaling and spear phishing?
Spear phishing targets a specific individual or small group with valuable access, while whaling narrows that focus to senior executives specifically, because of the financial authority and access they hold. Whaling attacks are also typically more personalized, built around the executive's real communication style, schedule, and current priorities rather than generic role-based details.
What is an example of a whaling attack?
One documented example is the 2020 attack on Australian hedge fund Levitas Capital, where a fake Zoom invite led to malware installation and roughly $8.7 million in fraudulent transfers, ultimately forcing the fund to close. A more recent example is the 2024 Arup deepfake video call in Hong Kong, where an employee authorized about $25 million in transfers after being deceived by AI-generated video impersonations of company executives on a live call.
How can organizations protect executives from whaling attacks?
The most effective step is requiring out-of-band verification for any financial request or sensitive data release, such as a phone call to a known number before a transfer is approved. Organizations should also harden executive accounts with stronger authentication, run training specific to whaling rather than generic phishing awareness, and use detection that can identify compromised-account activity rather than relying only on spoofed-sender rules.
Does Material protect against whaling and VIP impersonation attacks?
Yes. Material detects VIP impersonation and whaling attempts by analyzing behavior across the mailbox, including credential-harvesting attacks that carry no malicious link or attachment, rather than relying on a static list of known-bad senders. See preventing VIP impersonation attacks.
Does Material use AI to detect whaling attacks?
Yes. Material uses behavioral detection to identify whaling and VIP impersonation attempts, including cases where an attacker is working from inside a real, previously trusted executive mailbox rather than a spoofed sender. The detection looks at patterns in account activity and communication behavior, not keyword matching, and AI is included at every tier of the platform.

