Smart. Focused. Email.
Fast, cross-platform email designed to filter out the noise - so you can focus on what's important.
💡Whaling: a phishing attack aimed squarely at the people with the most authority to approve a wire transfer or hand over sensitive data: your CEO, your CFO, anyone whose name alone can make an employee stop asking questions. The bigger the fish, the more research goes into hooking them.
Whaling is phishing, narrowed down to one very specific, very valuable target: your organization's leadership. It's more researched, more convincing, and more expensive when it works. The name is a deliberate play on "phishing": attackers aren't casting a net anymore, they're hunting the biggest catch in the water, and they're willing to spend weeks preparing a single email to land it.
Picture the inbox of a CFO on a random Tuesday: dozens of legitimate, time-sensitive requests, each one needing a quick decision. That's exactly the environment whaling is built for.
Regular phishing plays a numbers game: thousands of generic emails, hoping a small percentage bite. Whaling flips that completely. One target, extensively researched, often using details pulled straight from LinkedIn, a company bio page, or an old press release. The email might reference a real deal, a real conference the exec actually attended, a real name from the board. But it's phishing that's done its homework, and that's what makes it dangerous.
And the payoff, when it works, is enormous. FACC, an Austrian aerospace parts supplier for Airbus and Boeing, lost close to $56 million in 2016 after an employee wired funds following an email that looked exactly like it came from the CEO. The fallout didn't stop at the money. Both the CEO and CFO were fired within weeks, Infosecurity Magazine reported at the time. One email. Two careers over.
FACC isn't an outlier. Networking hardware maker Ubiquiti disclosed in 2015 that it had wired roughly $46.7 million to overseas accounts after finance employees were fooled by messages impersonating company executives and outside attorneys. The company eventually clawed back a portion of the funds, but only after months of legal effort. That's a reminder that recovery is never guaranteed, and it's never fast.
Why aim this high instead of casting a wide net? Because executives can authorize large transfers without a second signature, and because employees are trained (correctly, mostly) to move fast when leadership asks for something. Whaling weaponizes exactly that instinct. It also exploits a quieter reality: junior staff rarely feel comfortable questioning a request that appears to come from the top, even when something about it feels off.
These three terms get tangled together constantly, and honestly, the overlap is real.
Regular phishing email casts wide: one generic message, sent to thousands, hoping a handful fall for it.
Spear phishing narrows the target to a specific person or small group, but not necessarily anyone senior. Could be a new hire. Could be someone in accounts payable. The research is personal, but the target doesn't need to hold real authority.
Whaling narrows it further still, specifically to executives and other high-value targets, using research most attackers wouldn't bother compiling for a lower-value mark. Think of it as spear phishing with a much bigger budget and a much narrower objective.
Business email compromise is the broader category describing what happens next: the scam itself, the wire transfer, the fake invoice. Whaling is often the method. BEC is the result. Whaling picks the target. BEC describes the con. An attacker can also skip whaling entirely and still run a BEC scam (by compromising a vendor's email account, for instance), which is why the two terms aren't interchangeable even though they're frequently used that way.
Verify by a second channel, every time. A quick call to a known number (not one listed in the suspicious email itself) beats trusting a signature at the bottom of a message. This single habit stops the overwhelming majority of whaling attempts cold, because it breaks the attacker's one advantage: speed.
Limit what executives share publicly. Travel schedules, deal details, org charts, all of it becomes research material for the next attempt. A LinkedIn post announcing an overseas trip is, in effect, a green light for attackers to impersonate that executive while they're unreachable.
Require dual approval on wire transfers past a set threshold. It's slower on purpose, and that's the entire point. No single email, however convincing, should be able to move six figures on its own.
Train leadership specifically, not just general staff. Executives are the target here, and most security training is written for everyone but them. The people with signing authority need to understand exactly how these emails are built and why they'll feel so personal.
Watch for urgency and secrecy stacked together. "Handle this quietly and quickly" is one of the biggest tells in the book: legitimate financial requests rarely ask employees to skip normal process and stay silent about it at the same time.
Whaling succeeds because it looks like ordinary business, arriving at exactly the moment someone is too busy, too deferential, or too rushed to double-check. The defense isn't a smarter filter: it's a culture where pausing to verify, even when the message says "CEO," is never treated as a delay worth apologizing for.