More than 90% of breaches start with a phishing attack.
Hackers are adaptive and opportunistic, so it’s no surprise that some have adapted their phishing attempts so they can land the biggest fish—CEOs and executives—using a technique known as ‘whaling’.
What is whaling?
Whaling is a type of phishing attack aimed at C-level or top-level executives with access to finances or sensitive data. A hacker uses social engineering and computer intrusion techniques to get as much information as they can on their targets. Just by scouring social media channels such as LinkedIn, they can collect personal data and information that can then be exploited to put their schemes into action. The attacker also collects information about how an organisation’s emails are structured in order to make them look as authentic and believable as possible.
What happens when whaling is successful?
Often the attacker will pretend to be a CEO, or senior executive, and send requests for money or data via email to another high-level executive. In the most serious cases, successful whaling attacks have resulted in millions of pounds of company funds being sent to accounts controlled by criminals.
A well-publicised example is that of European manufacturer Leoni AG, whose CFO was deceived into transferring £34 million into a bank account of the hacker’s choosing in 2016. In this case, the CFO received an email spoofed to look like it came from one of the company’s top German executives.
Why is whaling so successful?
Why waste your time targeting lower level workers—or a business as a whole—when you can make significant criminal gains by targeting the big fish at the top. The scammer relies on workers’ desires to impress senior managers and uses this behaviour to their advantage.
How to tackle phishing
As with many cyber threats, educating the final line of defence (us) is key to limiting the risks. Training employees and executives on what to look out for and how to avoid becoming a victim can reduce the threat dramatically:
- PGI’s Cyber Security Fundamentals course is a great place to start in educating your workforce.
- Phishing vulnerability assessments will also help your employees identify a phishing email.
Prepare your organisation for phishing attacks, contact us.
Insights
Trust & Safety: A look ahead to 2025
Working within the Trust and Safety industry, 2024 has been PGI’s busiest year to date, both in our work with clients and our participation in key conversations, particularly around the future of regulation, the human-AI interface, and child safety.
Lies, damned lies, and AI - Digital Threat Digest
At their core, artificial systems are a series of relationships between intelligence, truth, and decision making.
A pointless digital jigsaw - Digital Threat Digest
Feeding the name of a new criminal to the online OSINT community is like waving a red rag to a bull. There’s an immediate scramble to be the first to find every piece of information out there on the target, and present it back in a nice network graph (bonus points if you’re using your own network graph product and the whole thing is a thinly veiled advert for why your Ghunt code wrap with its purple-backlit-round-edged-dynamic-element CSS is better than everyone else’s).