Phishing emails aimed at everyone are easy to spot, with their clumsy wording and generic greetings. Whaling is different. It targets a specific senior person, such as an administrator, owner, CFO or executive director, using details gathered about their role, relationships and routines. The message might reference a real vendor, a real board member or a real project, which makes it far more believable.
Leaders are attractive targets because they have authority, access and often exemptions from the rules everyone else follows. This post explains how attackers research leaders and what extra protections to put in place.
Much of the research is simple and uses public information:
Your website and social media. Staff directories, leadership bios, press releases and photos reveal names, titles, reporting lines and who handles finances.
Professional profiles. Career histories, associations and conference attendance suggest topics a target will respond to.
News and community events. Ribbon cuttings, facility expansions, awards or leadership changes provide timely hooks.
Public records and filings. Ownership, licensure and regulatory information can make a message look official.
Leaked credentials and past breaches. Old passwords from other breaches may still work if reused.
Out-of-office messages. Automatic replies sometimes reveal travel dates and who is covering.
None of this requires sophistication. It requires patience.
Common themes include:
A fake request from the owner or board chair to approve an urgent payment.
A spoofed message from legal counsel or a regulator demanding a quick response.
A document-sharing link that leads to a fake sign-in page.
A vendor "invoice update" with new bank details.
A message that appears to come from a trusted colleague, sent from a lookalike address.
The tone is usually urgent and confidential, discouraging the target from checking with others.
Require multi-factor authentication on every executive account, and use phishing-resistant methods such as hardware security keys or passkeys where supported. Ordinary text message codes are better than nothing but are more vulnerable.
Make sure your email security flags external senders, spoofed display names and lookalike domains. Configure sender authentication records, such as SPF, DKIM and DMARC, for your own domain so attackers cannot easily impersonate you. Consider additional filtering for high-risk mailboxes.
No one person, including the administrator, should be able to approve and release a payment alone. Require a call-back to a known number for any new payee or change in bank details, regardless of who requests it.
Review what your website and social profiles reveal. You do not need to hide your leadership team, but consider removing direct mobile numbers, detailed org charts and personal information. Encourage leaders to tighten privacy settings and be thoughtful about what they post about travel.
Executives often use personal email and phones for business. Attackers know it. Cover personal accounts with unique passwords, a password manager and MFA, and keep devices updated. Consider whether personal accounts should be used for work at all.
Administrators and executives do not need local admin rights on their computers. Fewer privileges limit damage if an account is compromised.
Generic annual training is not enough. Give executives short, scenario-based sessions covering whaling examples that mimic their real world: board communications, vendor invoices, regulator letters. Include their assistants, who often manage inboxes and calendars and are targets themselves.
Staff should feel comfortable questioning an unusual request from the top. Tell them directly, and have leaders thank people who verify. A single skeptical employee can prevent a costly mistake.
Know whom to call, how to reset accounts quickly, and how to check for forwarding rules and unusual sign-ins. Report suspicious activity early, because delays make recovery harder.
UnityCare IT helps healthcare and senior-living leaders harden their accounts, tune email security and train executive teams. If you would like an honest look at how exposed your leadership team is, we can help.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172