A whaling attack is a type of phishing attack that targets senior executives. The act of whaling is usually perpetrated via email and involves deceiving victims into initiating actions that put the organization and its assets at risk.
Let's explore how a whaling attack works, why executives are targeted, examples of successful whaling attacks, and steps you can take to prevent them.
How a whaling attack works
Whaling attacks use information from a variety of sources—including the public domain (social media and corporate websites) and the dark web—to deliver highly personalized phishing emails to executives.
If attacks are successful, cybercriminals can plant malware and move laterally across the organization. They can also hijack an executive’s email, masquerade as them, and instruct unsuspecting employees to grant access to the company’s sensitive data or transfer funds.
Whaling attacks are relatively simple in their design. Like spear phishing, whaling emails incorporate hyperlinks or a malware attachment. However, whaling is more targeted than spear phishing, often involves impersonation, and the returns can be much greater (hence the term “whaling”).
Whaling emails can also form part of an integrated campaign. For instance, to sway an executive into believing the communication is genuine, a threat actor might follow up an initial email with a phone call to force action, such as clicking on a link.
Why attackers target executives
According to the 2023 Verizon DBIR, Social Engineering incidents, like phishing and whaling, have increased from the previous year largely due to the use of pretexting, which is commonly used in Business Email Compromise (BEC)—almost doubling since last year. Compounding the frequency of these attacks, the median amount stolen from these attacks has also increased over the last couple of years to $50,000.
Why go after executives? Consider the following:
- Digital access: Your organization’s C-suite and board of directors hold the keys to the kingdom. They have almost unfettered digital privileges that give them permission to view, edit, delete, and move a wealth of data, including sensitive information that attackers can exploit.
- Authority: Executives also have the digital authority to authorize actions, such as adding new vendors and wiring money.
- Mixing business and personal: Executives often, if unwittingly, bypass corporate security controls to save time, such as using insecure personal email to access files, systems, and applications.
- Persistent connectivity: To conduct business, executives frequently use vulnerable home networks and public Wi-Fi, putting them at risk of man-in-the-middle phishing attacks.
With so much going on and so much at stake, it’s not surprising that security teams lack confidence in their executives’ abilities to defend against cyberattacks on their devices, systems, and home network—despite cyber threats ranking as a top concern for boards.
Examples of whaling attacks
Whaling attacks often go unreported due to the fear of damage to a business’ reputation—no one wants to disclose that an executive fell for a scam. But government regulations require certain companies and government agencies to report cybersecurity incidents, including whaling.
A notable example of a publicly-disclosed whaling attack was storage device manufacturer, Seagate. In 2016, a spokesperson confirmed that a Seagate employee received what appeared to be a legitimate email from the company’s CEO requesting W-2 data for all current and former employees. Believing the request to be genuine, the staffer released the personal data of thousands of employees to cybercriminals.
In a separate campaign, employees from Inc. and Fast Company publisher Mansueto Ventures and social messaging platform Snapchat were victimized by the same whaling attack. During the scam, attackers exposed employee wage information and social security numbers that were used to file fraudulent tax returns.