Whaling: Targeted Attacks on Administrators and Executives

Phishing emails aimed at everyone are easy to spot, with their clumsy wording and generic greetings. Whaling is different. It targets a specific senior person, such as an administrator, owner, CFO or executive director, using details gathered about their role, relationships and routines. The message might reference a real vendor, a real board member or a real project, which makes it far more believable.

Leaders are attractive targets because they have authority, access and often exemptions from the rules everyone else follows. This post explains how attackers research leaders and what extra protections to put in place.

How Attackers Research Their Targets

Much of the research is simple and uses public information:

Your website and social media. Staff directories, leadership bios, press releases and photos reveal names, titles, reporting lines and who handles finances.

Professional profiles. Career histories, associations and conference attendance suggest topics a target will respond to.

News and community events. Ribbon cuttings, facility expansions, awards or leadership changes provide timely hooks.

Public records and filings. Ownership, licensure and regulatory information can make a message look official.

Leaked credentials and past breaches. Old passwords from other breaches may still work if reused.

Out-of-office messages. Automatic replies sometimes reveal travel dates and who is covering.

None of this requires sophistication. It requires patience.

What Whaling Messages Look Like

Common themes include:

A fake request from the owner or board chair to approve an urgent payment.

A spoofed message from legal counsel or a regulator demanding a quick response.

A document-sharing link that leads to a fake sign-in page.

A vendor "invoice update" with new bank details.

A message that appears to come from a trusted colleague, sent from a lookalike address.

The tone is usually urgent and confidential, discouraging the target from checking with others.

Extra Protections for Leaders

Strong authentication

Require multi-factor authentication on every executive account, and use phishing-resistant methods such as hardware security keys or passkeys where supported. Ordinary text message codes are better than nothing but are more vulnerable.

Tighter email protections

Make sure your email security flags external senders, spoofed display names and lookalike domains. Configure sender authentication records, such as SPF, DKIM and DMARC, for your own domain so attackers cannot easily impersonate you. Consider additional filtering for high-risk mailboxes.

Separate approval for payments

No one person, including the administrator, should be able to approve and release a payment alone. Require a call-back to a known number for any new payee or change in bank details, regardless of who requests it.

Reduce the public footprint

Review what your website and social profiles reveal. You do not need to hide your leadership team, but consider removing direct mobile numbers, detailed org charts and personal information. Encourage leaders to tighten privacy settings and be thoughtful about what they post about travel.

Protect personal accounts and devices

Executives often use personal email and phones for business. Attackers know it. Cover personal accounts with unique passwords, a password manager and MFA, and keep devices updated. Consider whether personal accounts should be used for work at all.

Limit standing privileges

Administrators and executives do not need local admin rights on their computers. Fewer privileges limit damage if an account is compromised.

Train Leaders Specifically

Generic annual training is not enough. Give executives short, scenario-based sessions covering whaling examples that mimic their real world: board communications, vendor invoices, regulator letters. Include their assistants, who often manage inboxes and calendars and are targets themselves.

Build a Culture Where Questions Are Welcome

Staff should feel comfortable questioning an unusual request from the top. Tell them directly, and have leaders thank people who verify. A single skeptical employee can prevent a costly mistake.

Prepare for the Day It Happens

Know whom to call, how to reset accounts quickly, and how to check for forwarding rules and unusual sign-ins. Report suspicious activity early, because delays make recovery harder.

How UnityCare IT Can Help

UnityCare IT helps healthcare and senior-living leaders harden their accounts, tune email security and train executive teams. If you would like an honest look at how exposed your leadership team is, we can help.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172