# What is Whaling?

> Whaling is spear phishing selected around a target’s seniority, public profile, authority, or access to high-value information and transactions.

- Canonical URL: https://yellowcube.eu/glossary/whaling/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It most commonly targets executives, board members, or senior officials. The target’s role defines whaling; it is not a separate technical delivery channel and does not require a request for money.

Attackers may tailor a message using public filings, organizational news, travel plans, suppliers, or professional relationships. Related campaigns may approach assistants, finance personnel, legal teams, or account administrators who can act for or reach a senior target, but those approaches are not automatically whaling.

### Key points

- **Typical objectives:** Obtaining sensitive documents, credentials, payments, tax or personnel data, account access, strategic information, or approval for a process change.
- **Protective design:** Apply strong authentication, least privilege, delegated-access review, protected email domains, and independent approval to high-impact actions without creating informal executive exceptions.
- **Investigation:** Examine the sender identity, destinations, attachments, sign-in activity, mailbox rules, and related approaches to assistants or colleagues; preserve evidence and escalate potential exposure promptly.
- **Important limitation:** Phishing received by a senior account is not automatically whaling; the target must have been selected around the role. Focusing only on executives also overlooks the people and systems around them.

### Related terms

[Spear phishing](<https://yellowcube.eu/glossary/spear-phishing/>) · [Phishing](<https://yellowcube.eu/glossary/phishing/>) · [Business email compromise (BEC)](<https://yellowcube.eu/glossary/business-email-compromise/>) · [Pretexting](<https://yellowcube.eu/glossary/pretexting/>) · [Email spoofing](<https://yellowcube.eu/glossary/email-spoofing/>)

### Sources

[Canadian Centre for Cyber Security: Social engineering](https://www.cyber.gc.ca/en/guidance/social-engineering-itsap00166) · [UK National Cyber Security Centre: Phishing attacks](https://www.ncsc.gov.uk/guidance/phishing)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

