What is whaling?
Whaling is phishing aimed at the "whales": top management and the employees who can move money or hand over data. The most widespread variant is known as CEO fraud: The fraudster poses as the CEO and asks an employee to carry out a transfer. These attacks are among the most lucrative forms of cybercrime, precisely because they skip the technology and go straight for the human being.
Whaling vs. phishing vs. spear phishing
The three terms are the same basic idea with increasing precision:
- Phishing: mass-sent fake emails, the same message to thousands, hoping a few take the bait.
- Spear phishing: targeted at a specific person or company, with research behind it.
- Whaling: spear phishing against the top (the executive team, the CFO, the board) or in the CEO's name against employees.
The family has several branches: vishing and quishing (phone and QR codes), spoofing of sender addresses and, most recently, deepfakes, where even voice and video are forged.
How CEO fraud plays out in practice
A typical sequence looks like this:
- Research: The attacker finds the management's names on the website and LinkedIn, sees who sits in finance, and when the CEO is travelling or at a conference.
- Contact: An email from "the CEO" lands with a finance employee, either from a forged sender address or a lookalike domain (for example
misupportlt.dkwith an l instead of an i). - Pressure: The message is urgent and confidential: "I'm in a meeting, can't take calls. Transfer DKK 240,000 to this account today. It concerns an acquisition, keep it to yourself."
- The transfer: If the payment goes through, the money has typically been moved on through mule accounts within hours.
Note what is not involved: malware, hacking, technical vulnerabilities. The entire attack is psychology.
Invoice fraud: the typical warning signs
A related variant is invoice fraud, where "a supplier" announces that their account number has changed, after which the next genuine invoice is paid into the fraudster's account. The typical red flags across both variants:
- Urgency and confidentiality: "must happen today", "don't involve anyone else".
- Breaks with normal process: payment outside the normal flow, a new account, a foreign bank.
- The sender is "almost" right: one letter wrong in the domain, or the reply address differs from the sender.
- Language and tone: slightly too formal, slightly too generic, or noticeably different from how the person usually writes.
Protect your management: concrete measures
- Verification procedure: All account changes and unusual payments are confirmed via a different channel: Call back on a known number. No exceptions, not even for the CEO; a genuine CEO will understand.
- Four eyes on payments above a set threshold.
- DMARC, SPF and DKIM on your domain, so your own sender address cannot be forged freely.
- Awareness training for management and the finance function: They are the target group, not just "ordinary" employees.
- Report attacks to the police (in Denmark, the National Special Crime Unit, NSK) and your bank immediately. A fast response may still stop the transfer.
How MI Support IT can help
MI Support IT trains executive teams and finance functions to recognise CEO fraud through security awareness training with simulated attacks, and sets up the technical safeguards as part of a comprehensive approach to IT security. Contact us before the fraudster does.