A finance employee in Hong Kong suspected phishing. Then he joined a video call where the CFO and three colleagues were all deepfakes. He authorized $25.6 million in transfers before anyone realized.
The employee had good instincts. When an email arrived in January 2024 from someone claiming to be the UK-based chief financial officer of Arup, the global engineering firm behind the Sydney Opera House and Beijing’s Bird’s Nest, requesting a confidential transaction, the Hong Kong finance worker suspected a phishing attempt. The message asked for secrecy, referenced an acquisition the employee knew nothing about, and carried the kind of urgency that security training teaches people to question.
Then came the video call. The CFO appeared on screen. So did three other colleagues the employee recognized from meetings and company communications. They discussed the transaction, answered questions, and provided the context that the email had lacked. Reassured by what he saw and heard, the employee authorized 15 wire transfers totaling $25.6 million to five bank accounts in a single day. No Arup system was breached. No credential was stolen. No malware was deployed. Every person on the call had been generated by AI, built from publicly available footage of Arup executives scraped from LinkedIn, YouTube, and recorded conference appearances. Arup’s CIO, Rob Greig, later told the World Economic Forum that after the incident he tried to deepfake himself using free, open-source tools. It took him 45 minutes.
The Arup case is the most documented example of a whaling attack, but the pattern it represents is not new. Whaling is spear phishing engineered for the people whose authority moves the most money, exposes the most data, and carries the most institutional weight. What has changed is the fidelity of the impersonation and the number of channels it can operate across simultaneously.
Why executives are worth more to attackers
The economics of whaling have always been straightforward: targeting a CEO, CFO, or general counsel requires more reconnaissance than mass phishing but produces orders-of-magnitude larger payoffs per success. The FBI’s 2025 Internet Crime Report recorded $3.046 billion in business email compromise losses, the broader category that includes whaling, with individual incidents routinely reaching seven and eight figures. Targeted spear phishing campaigns, which include whaling, have a roughly 60 percent success rate despite accounting for less than 0.5 percent of all phishing attempts.
But the value of an executive identity in 2026 extends well beyond the authority to approve a wire transfer. Palo Alto Networks’ 2026 Identity Security Landscape report found that 96 percent of organizations report human identities operating with access far beyond what their roles require, and that a single human login now sits at the center of downstream access to AI agents, workflows, approvals, integrations, and cloud environments. The average organization manages 109 machine identities for every human, with 79 of those being AI agent identities. When an attacker compromises an executive’s identity, the blast radius is no longer limited to what that executive can authorize manually. It extends to everything their identity can trigger, invoke, and approve across the organization’s entire digital infrastructure.
This is the shift that distinguishes modern whaling from the email-only campaigns of a decade ago. Compromising a CEO’s identity in 2016 gave the attacker access to the CEO’s email and the authority that email carried. Compromising a CEO’s identity in 2026 gives the attacker access to the CEO’s email, their connected SaaS applications, their AI agent permissions, their OAuth consents, their session tokens, and the downstream systems that trust actions originating from that identity without re-verification.
From spoofed emails to synthetic executives
The trajectory of whaling over the past decade traces the same pattern visible across the broader threat landscape: each generation of defense forces a corresponding evolution in attack sophistication.
The FACC case remains the canonical example of first-generation whaling. In January 2016, attackers impersonated Walter Stephan, the CEO of Austrian aerospace manufacturer FACC, in a spoofed email to the finance department requesting a €50 million transfer for a purported acquisition. The email matched Stephan’s writing style closely enough that the finance employee complied. FACC recovered €10.9 million. The remaining €42 million disappeared to accounts in Slovakia and Asia. The company took a €41.9 million charge that wiped out its annual profit, its share price dropped 17 percent, and the supervisory board fired both the CEO and CFO. The attack required nothing more than a convincing email and an understanding of how deference to executive authority functions inside a large organization.
The second generation added voice. By 2023, voice cloning tools had matured to the point where a few seconds of publicly available audio could generate a convincing replica of an executive’s speech patterns. In 2024, attackers cloned the voice of Ferrari’s CEO and called a senior executive on WhatsApp, complete with the CEO’s southern Italian accent, pressing about a confidential acquisition that required immediate action. The executive grew suspicious and asked a personal question that the real CEO would know. The voice on the other end could not answer. The attack failed, but it demonstrated that voice-only verification, the traditional fallback when an email seems suspicious, had become unreliable.
The third generation arrived with Arup. Deepfake video made the verification call itself an attack vector. The finance employee in Hong Kong did exactly what training prescribes: he was skeptical of the email, and he sought verification through a video call. The video call was the attack. By the time Vectra AI published its analysis in 2026, deepfake-enabled vishing had surged more than 1,600 percent in Q1 2025 compared to the end of 2024, and deepfake fraud losses exceeded $200 million in North America in a single quarter. AI-driven fraud tactics increased 118 percent year-over-year. The Arup case was the watershed, but the capability is now commodity infrastructure.
What the impersonation looks like from the outside
Whaling campaigns depend on external infrastructure that exists before the first email is sent or the first call is placed.
The reconnaissance phase mines publicly available information to build the impersonation: earnings calls, press releases, LinkedIn profiles, conference appearances, investor presentations, and organizational charts. For voice and video deepfakes, attackers harvest audio and video from the same sources. Arup’s CIO confirmed that the source material for the deepfakes came entirely from public footage. The more visible an executive’s public presence, the more material attackers have to work with.
The delivery infrastructure typically includes spoofed or lookalike domains that lend credibility to the initial email contact, credential harvesting pages that capture login credentials if the whaling campaign’s goal is account takeover rather than wire fraud, and in some cases compromised email accounts within vendor or partner organizations that provide the legitimacy of an existing business relationship. Whaling campaigns timed to corporate events, such as earnings announcements, M&A activity, or leadership transitions, exploit the urgency and distraction that accompany these periods.
For organizations protecting their brand against whaling, the external signals are often visible before the attack lands. Lookalike domains registered to impersonate executive email addresses, social media profiles fabricated to establish a synthetic executive identity, and phishing pages designed to capture credentials for executive accounts all represent detectable infrastructure. The challenge is that these assets are not created as part of a single, visible campaign. They appear incrementally, across different registrars and hosting providers, and may sit dormant for weeks before activation.
The Bottom Line
Whaling works because it borrows the one thing no technical control can easily revoke: the trust an organization places in its own leadership. The attack has evolved from a forged email to a multi-channel operation that can replicate an executive’s appearance, voice, and communication style with commodity tools. The Arup case proved that even an employee who correctly identifies a suspicious email can be defeated by the verification step that follows. For organizations whose executives are public-facing, the defense requires monitoring the external impersonation infrastructure that attackers assemble before the whaling campaign begins, not just training employees to be skeptical of what arrives in their inbox.
Key Takeaways
A whaling attack is a form of spear phishing that targets or impersonates senior executives such as CEOs, CFOs, and general counsel. The attack exploits the authority these individuals carry within their organizations, either by targeting them directly with sophisticated lures or by impersonating them to instruct employees to transfer funds, share credentials, or approve fraudulent transactions.
Business email compromise, the broader fraud category that includes whaling, caused $3.046 billion in reported losses in 2025 according to the FBI. Individual whaling incidents regularly reach seven and eight figures, with the Arup deepfake case resulting in $25.6 million in losses and the FACC “Fake President Incident” causing a €42 million charge.
AI has transformed whaling from an email-only technique into a multi-channel operation. Voice cloning can replicate an executive’s speech from seconds of publicly available audio. Deepfake video can populate an entire video conference with synthetic participants. Generative AI can produce emails that match an executive’s writing style. Deepfake-enabled vishing surged more than 1,600 percent in Q1 2025.
Business email compromise is the broader fraud category that encompasses attacks using email to manipulate victims into transferring funds or revealing information. Whaling is a subset of BEC that specifically targets or impersonates senior executives. CEO fraud, another related term, specifically describes attacks where a criminal impersonates the CEO to instruct employees below them.
Effective defense combines email authentication (DMARC enforcement to prevent direct domain spoofing), dual-authorization protocols for financial transactions, executive-specific security training, and monitoring for the external impersonation infrastructure that precedes whaling campaigns, including lookalike domain registrations, fabricated executive profiles, and credential harvesting pages targeting executive accounts.



