It most commonly targets executives, board members, or senior officials. The target’s role defines whaling; it is not a separate technical delivery channel and does not require a request for money.
Attackers may tailor a message using public filings, organizational news, travel plans, suppliers, or professional relationships. Related campaigns may approach assistants, finance personnel, legal teams, or account administrators who can act for or reach a senior target, but those approaches are not automatically whaling.
Key points
Typical objectivesObtaining sensitive documents, credentials, payments, tax or personnel data, account access, strategic information, or approval for a process change.
Protective designApply strong authentication, least privilege, delegated-access review, protected email domains, and independent approval to high-impact actions without creating informal executive exceptions.
InvestigationExamine the sender identity, destinations, attachments, sign-in activity, mailbox rules, and related approaches to assistants or colleagues; preserve evidence and escalate potential exposure promptly.
Important limitationPhishing received by a senior account is not automatically whaling; the target must have been selected around the role. Focusing only on executives also overlooks the people and systems around them.