Whaling Attacks - Phishing That Targets Executives
About 2 min read
Whaling is a phishing attack that targets individuals with high authority within an organization, such as corporate executives and board members. The name comes from the idea of "going after the big fish (whale)." Compared with ordinary phishing, it is prepared far more carefully: after researching the target's job responsibilities and relationships, attackers send extremely convincing fraudulent emails.
Real-World Use Cases
For example, a whaling attack could involve an email impersonating a business partner's or your own CEO that instructs an accounting staff member to make an urgent transfer of tens of millions of yen. In such a case, if you have a rule that transfers are confirmed with the person through a channel other than email (by phone or in person) right before sending, you are far more likely to prevent the damage.
How Whaling Works
Typical tactics include a transfer request impersonating a business partner's CEO, a demand for confidential documents impersonating a lawyer, and a request to provide information impersonating tax authorities. Because executives are busy, they may respond without sufficiently verifying whether an email is genuine. According to the annual report of the FBI's Internet Crime Complaint Center (IC3), the total damage from BEC (business email compromise) reached about 2.77 billion U.S. dollars in 2024, and in some cases the loss per incident ranges from tens of millions to hundreds of millions of yen. Tactics that imitate an executive's voice using voice synthesis to pressure staff into wiring money by phone are also known.
The Difference From Spear Phishing
Whereas spear phishing is a general term for targeted attacks aimed at specific individuals or organizations, whaling is an attack that narrows in particularly on executives and people with high decision-making authority. In spear phishing, the main objectives are attaching malware or stealing login credentials, but in whaling there are many cases that demand direct transfer instructions or the disclosure of confidential information, making the loss per incident vastly larger. It is the area that should be given top priority among social engineering countermeasures.
Countermeasures
Set especially strong random passwords for executive accounts and always enable multi-factor authentication. It is important to establish a rule that transfers and the disclosure of confidential information are confirmed through channels other than email (phone, in person). Security training for executives is also effective: regularly conducting drills modeled on real attack emails helps build the ability to spot suspicious messages. Be sure to also review the basics of phishing protection.
Was this article helpful?