Whaling
What it is
Spear-phishing aimed at senior executives, board members, or the staff who act on their behalf, exploiting the fact that a request made in the chief executive's name is rarely questioned.
How it works
Real-world examples
- •In 2016 a Snapchat payroll employee sent the W-2 tax forms of current and former staff to an outsider impersonating CEO Evan Spiegel; Seagate suffered the same lure the same year.
- •The Austrian aerospace supplier FACC lost about 50 million euros in 2016 to a "fake president" email requesting a transfer for a fictitious acquisition; the board subsequently dismissed its chief executive.
- •Mattel wired about 3 million dollars to a Chinese bank in 2015 after an email that appeared to come from its newly appointed CEO; the money was recovered largely because the transfer landed on a bank holiday.
- •Attackers also target executives directly, sending a CEO a fake subpoena or board document, because the executive's own mailbox is the richest source of pretexts for the next round of attacks.
Ethical guidelines
- ●Impersonating an executive to move money or data is wire fraud; there is no ethical deployment.
- ●Authorized simulations should be approved by the executives whose names are used and should never expose individual employees to ridicule.
- ●Leadership bears responsibility: a culture in which questioning an urgent request from the top is punished is the precondition this attack relies on.
How to defend against it
- ►Adopt a written rule that no payment, banking change, or release of personnel data proceeds on email alone; confirmation must come by phone to a known number or in person, even when the request appears to come from the CEO.
- ►Executives should say this out loud to their teams: "If I ever ask you to skip verification, assume it is not me." Removing the fear of pushing back removes the lever.
- ►Check the sending address, not the display name, and look for lookalike domains (a missing letter, an added hyphen, .co instead of .com); register the common lookalikes of your own domain before someone else does.
- ►Segregate duties so that no single person can both approve and execute a transfer; the attacker then has to fool two people through two channels.
- ►Treat "I am in a meeting and cannot talk" as the standard tell: a real executive can take a thirty-second call to confirm a six-figure wire.
From the Defense Playbook
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.
Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Federal Bureau of Investigation, Internet Crime Complaint Center (2023). Business Email Compromise: The $50 Billion Scam (Public Service Announcement I-060923-PSA). FBI IC3 · linkCumulative exposed BEC losses above 50 billion dollars for 2013-2022 and the recurring role of executive impersonation.
- Milgram, S. (1963). Behavioral Study of Obedience. Journal of Abnormal and Social Psychology, 67(4), 371-378 · linkOriginal demonstration that instructions from a perceived authority override private objections.
- Perry, G. (2013). Behind the Shock Machine: The Untold Story of the Notorious Milgram Psychology Experiments. The New PressArchival critique showing that Milgram's obedience findings were more variable and more contested than the popular account.
- Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social engineering attacks. Journal of Information Security and Applications, 22, 113-122 · linkClassification of targeted social-engineering attacks, including executive-targeted phishing, by channel and operator.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.