An email arrives in the controller’s inbox at 4:47 PM on a Thursday. It is from the CEO. The wording is short and a little brusque, the way the CEO actually writes. There is a single-line ask: pay an outstanding vendor invoice today before close of business, and reply when it is done. The amount is large but not unreasonable. The vendor name is familiar. The controller does what a good controller does: they get it done.

By Friday afternoon, the real CEO finds out. The email was not from them. The vendor was a near-lookalike spelling. The bank account was new. The money is gone, and the small business that wired it is now talking to its insurance carrier, its bank, and its lawyer at the same time.

This is the shape of a whaling attack. It is the most expensive form of phishing for a small business because the request reads as routine, it arrives at the busiest possible moment, and there is no shared verification habit that catches it before the money moves.

What Makes A Whaling Attack Different From Regular Phishing?

Regular phishing is a wide net. An attacker buys a list, sends a generic “your account is locked” email to ten thousand inboxes, and waits for whoever clicks. Whaling is the opposite. The attacker picks one company, studies it, and writes one email that looks like it came from someone specific – usually the CEO, sometimes the CFO, sometimes a board member or a major investor. The target is rarely the executive themselves. The target is the person on the other end of an unusual request the executive could plausibly make. That is most often the controller, an accounts payable clerk, an executive assistant, an HR manager, or whoever owns vendor onboarding.

The reconnaissance behind a whaling attack is the part most owners underestimate. Before the email goes out, the attacker has scraped LinkedIn for the org chart, pulled the executive’s writing style from press releases and blog posts, and looked up the company’s vendors from news mentions, case studies, and federal filings. They know who reports to whom, who handles wires, when the CEO is traveling, and which vendors actually exist. The email lands inside that operational picture, not on top of it. Unlike SMS-based phishing campaigns targeting frontline staff, a whaling message rarely contains an obvious typo or a stranger’s name.

How Does It Compare To Spear Phishing And Business Email Compromise?

Spear phishing is targeted at one person, but that person could be anyone – a sales rep, an engineer, a customer service lead. Whaling is the executive-impersonation flavor of spear phishing where the email pretends to come from a senior leader. Business email compromise is the broader category that covers both whaling and the related pattern where the attacker actually breaks into a real mailbox and sends from inside. The lines blur in practice. What matters operationally is that all three rely on the same human shortcut: people do not pause to verify a request that looks like it came from someone they would want to please.

Why Are Small Business Leaders Such Easy Targets?

Small businesses have all of the same money flowing through them as midmarket companies – payroll, vendor payments, tax payments, intercompany transfers, refunds – with a fraction of the controls. The CEO is often a real signature authority on the bank account. The CFO role is sometimes a fractional one. The accounts payable function might be one person who has been doing it for nine years and trusts their judgment. None of that is wrong. It is the operating model that makes small businesses fast. But it also means the same person who picks up a wire instruction also makes the final call on whether the wire goes out, and that is exactly the chokepoint a whaling email is designed to exploit.

The public profile of a small business leader makes the rest of the work easy. Most small business owners have a LinkedIn account, a podcast appearance or two, a press release in a local paper from last spring, and several speaking engagements where the slide deck is publicly available. None of those things are mistakes; they are normal marketing. But they also feed the attacker the writing patterns, the vendor names, the travel schedule, and the names of direct reports. When the email lands at 4:47 PM on a Thursday and references the CEO’s actual trip to a real industry conference the previous week, it does not feel like fiction. It feels like a CEO who is rushing because they are coming back from travel and trying to clear their inbox. A practical layer of ongoing security awareness practice with realistic scenarios is the only thing that consistently catches that emotional pull in real time.

Where Does The Pressure Tactic Usually Show Up?

Three pressure patterns appear in almost every whaling email. The first is time pressure: the request must happen today, before close, before the executive boards a flight, before a board call. The second is secrecy pressure: do not loop in the rest of finance, this is sensitive, the acquisition is not announced yet, payroll cannot know. The third is authority pressure: this is from the CEO directly, and the CEO is annoyed that the last person they asked did not move fast enough. None of those framings hold up to a thirty-second phone call to the CEO’s actual cell. Every one of them works when the recipient is alone, busy, and trying not to disappoint a senior person.

What Should Your Team Actually Do When A CEO Email Feels Off?

The honest first step is to slow the clock down. Whaling attacks rely on the recipient finishing the action within minutes. Every minute the request sits in a draft response instead of the wire system is a minute the attack loses. The rule that holds up across small businesses is a documented out-of-band verification step on any movement of money, sharing of payroll or W-2 data, change to vendor banking, or grant of new system access. Out-of-band means not the same email thread. It means a phone call to a known number, a quick walk to the office next door, or a message in the company’s chat platform to the actual person’s direct handle – not a reply to the email.

The second step is to look for the four signals that show up on almost every whaling email. The reply-to address differs subtly from the display name – a hyphen instead of an underscore, a misspelled last name, a personal-looking gmail address where the executive normally uses the company domain. The phrasing is just slightly off – more formal, more brusque, fewer of the executive’s usual quirks. The request involves money, sensitive data, or new access, and it is framed as a one-time exception. And there is an explicit ask to keep the request quiet, often dressed up as an acquisition, a tax matter, or a confidential deal. Any single one of those is a yellow flag; two together is a stop. For the most common ask, a documented verbal callback step on every wire request above a set threshold is the single highest-impact control a small business can adopt.

What If The Money Has Already Moved?

The window for recovery is small but real. Same-day notice to the sending bank can sometimes recall a domestic wire if the receiving bank has not yet released funds. The FBI’s Internet Crime Complaint Center maintains a kill-chain process specifically for business email compromise that can freeze funds in a recipient account when reported within seventy-two hours. The faster step is the most important one: notify the sending bank, file an IC3 complaint at ic3.gov, notify the cyber insurance carrier, and reset the credentials on any account that may have been involved. Recovery odds drop sharply after day three.

How Do You Build A Verification Habit Before The Real One Hits?

Process beats vigilance over a long enough timeline. Vigilance is a person paying attention; process is a checklist that does not depend on the person being well-rested. The most resilient small businesses we walk through a security review use the same three building blocks for whaling resilience.

The first building block is a verification policy that lives somewhere written down. The policy names the trigger events – wires, payroll-data requests, vendor banking changes, new system access, gift card purchases – and names the verification step for each. The verification step is usually a phone call to a number stored in the HR or finance system, not a number provided in the request itself. Putting the policy in writing turns “I felt funny about this so I called” into “the rule says I call, so I called,” and that distinction is what protects a junior employee who does not yet feel comfortable second-guessing a senior person.

The second building block is technical controls on the email path itself. Domain authentication records – SPF, DKIM, DMARC – make it harder for an attacker to spoof the actual company domain in the From line, which forces them onto a lookalike domain that is easier for a recipient to catch. Mailbox protection on executive accounts adds banner warnings when an external sender uses the display name of an internal employee. Enforced strong multi-factor on every executive mailbox blocks the related pattern where the attacker has actually stolen the executive’s password and is sending from inside.

The third building block is rehearsal. A verification habit that has only been described in a policy document is not a habit. A short tabletop exercise once a quarter, where the finance team and the executive assistant talk through three or four simulated whaling scenarios and practice the callback step, builds the muscle memory that makes the real one obvious. The exercise also produces a useful side effect: it surfaces the missing pieces in the policy before an attacker finds them.

Who Owns The Verification Policy Day To Day?

The right owner is the person who runs finance, with IT or the managed IT provider responsible for the technical controls on email. Splitting the policy across two owners almost always fails because each side assumes the other handled it. The owner publishes the policy, owns the quarterly review, runs the tabletop, and is the named escalation when a real suspicious request lands. Naming a single owner is the smallest possible step that turns whaling resilience from a slide deck into a real defense.

Frequently Asked Questions

How is whaling different from a normal phishing email?

A normal phishing email is generic and sent to thousands of people. A whaling email targets one company and impersonates a specific senior leader inside it. The attacker has usually done research on the company’s org chart, vendor list, and executive writing style, so the request lands as plausible to the person who receives it.

Who inside a small business is the actual target?

Rarely the executive themselves. The target is whoever the executive would plausibly ask to move money or share sensitive data: the controller, an accounts payable clerk, the executive assistant, the HR manager, or a payroll administrator. The attacker is counting on the recipient wanting to act quickly on a senior request.

What is the single most effective control against whaling?

A written verification policy that requires an out-of-band phone call to a known number before any money moves, any payroll or W-2 data is sent, any vendor banking is changed, or any new system access is granted. The phone number must come from the company directory, not from the email itself.

Can multi-factor authentication stop whaling?

It stops the variant where the attacker is sending from inside the real executive mailbox after stealing their password. It does not stop the lookalike-domain variant where the attacker never needed to log in to anything. That is why the verification policy matters as much as the technical controls – the two cover different attack paths.

How fast does a whaling wire need to be reported to have a chance of recovery?

Same day is best. The FBI’s Internet Crime Complaint Center has a financial fraud kill-chain process that can freeze funds in the receiving account when reported within seventy-two hours, and the sending bank may be able to recall a domestic wire that the receiving bank has not yet released. After day three, recovery odds drop sharply.

Should we tell employees the CEO will never email about wires?

Telling people what the CEO will and will not do is less reliable than giving them a verification step they apply to every request. Rules of thumb fail under time pressure. A policy that says “always call the named number before sending money, no exceptions” works whether the request came from the CEO, the CFO, a board member, or anyone else.

Does cyber insurance cover money lost in a whaling attack?

Sometimes, under a specific endorsement called social engineering fraud coverage. It is not always included in the base policy and the limits are often lower than the policy’s main cyber limit. Confirm with the insurance broker before assuming the loss is covered, and tighten the verification policy regardless – insurers increasingly ask whether one is in place at renewal time.

Where Does A Vendor-Led Audit Fit In Closing These Gaps?

A one-day external review usually catches the gaps a busy finance team has stopped seeing. The reviewer inventories every spoofable identity in the company, confirms the email authentication records are in place, walks through the verification policy with the people who would actually execute it, and runs a single tabletop scenario before leaving. The deliverable is a written policy the finance lead can sign, a punch list of the three or four technical controls to tighten on the email side, and a quarterly cadence the team can run on its own. For a Treasure Coast small business that wants a quiet outside look at closing the targeted-impersonation gaps across leadership accounts, that is the kind of work O&O Systems is set up to do.