Why AI Is Making Whaling Attacks Harder to Spot,and What Executives Can Actually Do About It
Whaling attacks are highly targeted phishing campaigns that pursue senior executives and board members by exploiting their authority and access rather than software vulnerabilities. Unlike mass phishing emails, a whaling attack relies on weeks of open-source intelligence (OSINT) research to produce personalized messages that pass authentication checks and read like legitimate internal communication. The stakes are enormous: according to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, business email compromise costs victims an average of roughly $123,000 per reported case, with whaling sitting at the costly center of that category because it targets the people who can authorize the largest transfers.
The most infamous example remains the 2015 incident at networking firm Ubiquiti Networks, where cybercriminals impersonated the CEO and directed a sequence of wire transfers through a Hong Kong subsidiary, stealing $46.7 million in a single campaign. That case captures why whaling has become the highest-value category of executive-targeted fraud, and why standard email filters rarely catch it.
How Has AI Changed the Whaling Attack Landscape?
The convergence of two forces has made whaling attacks far more dangerous: the depth of publicly available executive data and the rise of AI-generated content. A cyberattacker today can feed a CEO's conference keynote into a voice cloning tool and produce a vishing call (voice phishing call) indistinguishable from the actual executive. This represents a fundamental shift in how these attacks work. AI has erased the grammar and voice call signs that once exposed a whaling attack, making rehearsed human verification the deciding control across email, voice, and collaboration platforms.
The problem is compounded by the fact that cyberattackers can now leverage weeks of OSINT reconnaissance combined with AI-generated impersonation. A 2024 incident at engineering firm Arup demonstrated this starkly: a Hong Kong finance employee approved a transfer after joining a video call populated entirely by deepfake participants, blending whaling-style targeting with AI-generated impersonation. This hybrid approach makes detection exponentially harder because the attack combines personalized targeting with synthetic media that bypasses traditional voice and video verification.
Which Roles Are Cybercriminals Targeting Beyond the CEO?
While the CEO and CFO remain high-value targets, cybercriminals have expanded their targeting profile to include roles that hold delegated access or payment authority. The roles that cyberattackers prioritize extend beyond the CEO and CFO to include legal counsel, HR directors, controllers, and executive assistants who hold delegated access or payment authority. This diversification of targets makes it harder for organizations to concentrate their defenses in a single area.
The psychological levers that a whaling attack exploits are carefully engineered. Manufactured urgency, anomalous sender addresses, unusual requests, and pressure to bypass normal processes are the clearest warning signs of a whaling attack. However, with AI-generated content, even these warning signs become less reliable. A message that arrives with perfect grammar, a plausible sender address, and a tone that matches the impersonated executive's communication style can slip past even experienced executives under time pressure.
How to Defend Against Whaling Attacks in Your Organization
- Email Authentication and Phishing-Resistant MFA: Implement multi-factor authentication (MFA) that doesn't rely on SMS or email codes, which can be intercepted or spoofed. Phishing-resistant MFA uses hardware security keys or biometric verification to prevent attackers from gaining access even if they compromise credentials.
- Mandatory Out-of-Band Verification Policies: Establish procedures that require executives to verify unusual requests through a separate communication channel. If a wire transfer request arrives via email, the executive should call the requester directly using a known phone number, not one provided in the email itself.
- Behavior-Changing Cybersecurity Awareness Training: Move beyond one-time training completion metrics to measure behavioral change over time. Cybersecurity awareness training that rehearses exact pressure moments and whaling scenarios is what separates organizations that catch a fraudulent wire request from those that fund one. Training should focus on the specific trust relationships and communication patterns within your organization.
Preventing a whaling attack requires three layers working together: email authentication and phishing-resistant MFA, mandatory out-of-band verification policies, and behavior-changing cybersecurity awareness training. The key insight is that a whaling attack succeeds when a convincing message reaches a busy executive faster than any verification habit kicks in. Organizations that invest in training executives to verify before they act, even under pressure, significantly reduce their risk.
The human element remains central to both the attack and the defense. According to Verizon's 2026 Data Breach Investigations Report, the human element was present in 62% of confirmed incidents, and a whaling attack represents the apex of that exploitation, weaponizing the specific trust relationships of a particular organization. This means that technical controls alone cannot stop whaling attacks; they must be paired with human-centered defenses that account for the psychological and social engineering tactics that make these attacks so effective.
As AI tools become more sophisticated, the burden of defense shifts increasingly toward the humans who hold the keys to sensitive systems and financial accounts. Organizations that recognize this shift and invest in executive-level security training, combined with robust technical controls and verification procedures, are best positioned to withstand the whaling attacks that will continue to target their most valuable decision-makers.