Social Engineering & FraudMANIPULATIVE

Whaling

What it is

Spear-phishing aimed at senior executives, board members, or the staff who act on their behalf, exploiting the fact that a request made in the chief executive's name is rarely questioned.

How it works

Whaling combines two levers: the authority that attaches to an executive name and the routine deference of the people around it. An assistant, a payroll clerk, or a controller who receives a terse note from "the CEO" asking for employee tax forms or an urgent wire faces an asymmetric choice: complying is normal, while pushing back feels like insubordination or a career risk. Attackers exploit that asymmetry, usually with a lookalike domain or a display name that mimics the executive, timed for a moment when the real executive is unreachable, such as a flight or a conference. Milgram's obedience experiments are the usual citation for why an instruction from a perceived authority overrides private doubts, though Gina Perry's archival work shows the original findings were messier and more contested than the textbook version. The more reliable modern evidence is the FBI's business-email-compromise data, in which executive impersonation is a recurring pattern behind billions of dollars in reported losses.

Real-world examples

  • In 2016 a Snapchat payroll employee sent the W-2 tax forms of current and former staff to an outsider impersonating CEO Evan Spiegel; Seagate suffered the same lure the same year.
  • The Austrian aerospace supplier FACC lost about 50 million euros in 2016 to a "fake president" email requesting a transfer for a fictitious acquisition; the board subsequently dismissed its chief executive.
  • Mattel wired about 3 million dollars to a Chinese bank in 2015 after an email that appeared to come from its newly appointed CEO; the money was recovered largely because the transfer landed on a bank holiday.
  • Attackers also target executives directly, sending a CEO a fake subpoena or board document, because the executive's own mailbox is the richest source of pretexts for the next round of attacks.

Ethical guidelines

  • Impersonating an executive to move money or data is wire fraud; there is no ethical deployment.
  • Authorized simulations should be approved by the executives whose names are used and should never expose individual employees to ridicule.
  • Leadership bears responsibility: a culture in which questioning an urgent request from the top is punished is the precondition this attack relies on.

How to defend against it

  • Adopt a written rule that no payment, banking change, or release of personnel data proceeds on email alone; confirmation must come by phone to a known number or in person, even when the request appears to come from the CEO.
  • Executives should say this out loud to their teams: "If I ever ask you to skip verification, assume it is not me." Removing the fear of pushing back removes the lever.
  • Check the sending address, not the display name, and look for lookalike domains (a missing letter, an added hyphen, .co instead of .com); register the common lookalikes of your own domain before someone else does.
  • Segregate duties so that no single person can both approve and execute a transfer; the attacker then has to fool two people through two channels.
  • Treat "I am in a meeting and cannot talk" as the standard tell: a real executive can take a thirty-second call to confirm a six-figure wire.

From the Defense Playbook

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Federal Bureau of Investigation, Internet Crime Complaint Center (2023). Business Email Compromise: The $50 Billion Scam (Public Service Announcement I-060923-PSA). FBI IC3 · link
    Cumulative exposed BEC losses above 50 billion dollars for 2013-2022 and the recurring role of executive impersonation.
  2. Milgram, S. (1963). Behavioral Study of Obedience. Journal of Abnormal and Social Psychology, 67(4), 371-378 · link
    Original demonstration that instructions from a perceived authority override private objections.
  3. Perry, G. (2013). Behind the Shock Machine: The Untold Story of the Notorious Milgram Psychology Experiments. The New Press
    Archival critique showing that Milgram's obedience findings were more variable and more contested than the popular account.
  4. Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social engineering attacks. Journal of Information Security and Applications, 22, 113-122 · link
    Classification of targeted social-engineering attacks, including executive-targeted phishing, by channel and operator.
Last reviewed
Suggest a correction

Detect Whaling in any text

Paste any message, email, or article into our free Manipulation Detector to see if Whaling or other techniques are being used on you.

Related Articles