Category: Uncategorized

  • What Is Whaling? How Executive Email Fraud Works

    What Is Whaling? How Executive Email Fraud Works

    Whaling phishing is a highly targeted email scam aimed at senior executives to trick them into making fraudulent payments or revealing sensitive company information. It's expensive enough that enterprise-focused sources estimate whaling attacks cost organisations about $1.8 billion per year, and one well-known CEO-impersonation scam led to a reported €50 million loss.

    If you run a small business, this matters even if you don't have a big security team. A whaling attack doesn't need to break your systems first. It only needs one believable message, sent to the right person at the right moment.

    Many owners assume attackers only go after large public companies. In practice, smaller teams can be easier targets because the CEO, finance lead, office manager, and executive assistant often share the same email tools and informal approval habits. That makes speed and trust part of the risk.

    Last updated: 25 May 2026

    What is Whaling Phishing?

    A whaling attack is a specific kind of spear phishing. Instead of sending the same fake message to thousands of people, the attacker studies one organization and aims at someone with authority, access, or influence. That usually means a CEO, CFO, founder, director, or assistant who can move money or approve sensitive requests.

    Understanding the Whaling Attack

    The email often looks ordinary at first glance. It may ask for a wire transfer, payroll file, invoice payment, login approval, or urgent review of a document. The trick is social engineering. Attackers rely on authority, secrecy, and time pressure so the target reacts before slowing down to verify.

    Why executives get singled out

    Senior staff have something attackers want. They can approve payments, override process, access legal or finance records, and ask others to act quickly. A message that seems to come from the CEO carries weight, even in careful teams.

    Security-training firm Hoxhunt estimates annual losses to whaling at around $1.8 billion. The most-cited cautionary tale is FACC, an Austrian aerospace parts supplier to Boeing and Airbus. In January 2016, an attacker impersonating CEO Walter Stephan emailed the finance team to wire funds for a fictitious acquisition — about €42 million (roughly US$47 million at the time) was transferred before the fraud was caught, and only €10.9 million was ever recovered. FACC's supervisory board fired the CFO in February 2016 and the CEO in May 2016, citing the "fake president incident."

    Practical rule: If an email asks a senior person to bypass normal process, the process is usually what's protecting you.

    Why these emails work

    Whaling messages are often carefully researched. Attackers read company websites, LinkedIn profiles, press releases, and public contact pages. Then they write an email that fits your real business rhythms, such as quarter-end payments, travel schedules, hiring, or a confidential acquisition.

    For small teams, this can feel especially real because normal communication is often informal. The owner may already send short messages like “Please handle today” or “Need this done before noon.” That means the fake email doesn't need to be perfect. It only needs to feel familiar enough.

    If you want a broader look at the payment-fraud side of this problem, our guide to business email compromise prevention covers the wider playbook attackers use around spoofed executive requests.

    Whaling vs Phishing and Spear Phishing

    Not every phishing email is whaling. People often use the terms loosely, which causes confusion when they try to choose the right defense.

    Standard phishing casts a wide net. Spear phishing narrows the target. Whaling goes after a specific high-value person or someone close to that person, such as a finance manager or executive assistant.

    Whaling vs Phishing and Spear Phishing

    The simplest way to think about it

    A regular phishing email might claim your mailbox is full and ask you to sign in. It's generic, sent at scale, and built for volume.

    A spear phishing email is more specific. It might mention your job title, your supplier, or a project your team is working on.

    A whaling attack goes further. It focuses on a leader, finance approver, or privileged user, and it usually tries to trigger a high-impact action. Torq's breakdown of whaling phishing notes that these attacks rely on impersonation, lookalike domains, and urgency, which is why generic spam filtering alone isn't enough.

    Phishing compared side by side

    Attribute Standard Phishing Spear Phishing Whaling
    Target Broad group of users Specific person or small group Executive or high-privilege user
    Personalisation Low Medium to high High
    Typical tone Generic warning or fake account alert Context-aware and role-aware Authoritative, urgent, often confidential
    Common goal Steal credentials or deliver malware Steal access or data Trigger payments, approvals, or privileged access
    Best first defence Spam filtering and user awareness Verification and targeted controls Executive-mailbox protections and approval workflows

    A whaling email doesn't look more “technical” than other scams. It looks more plausible.

    Why the defence changes

    Many businesses often falter at this stage. They buy decent spam filtering, run a basic awareness session, and assume they're covered. That helps with bulk phishing, but whaling often slips past superficial checks because it's crafted for one person and one moment.

    For executive phishing, we'd focus on a shorter list of controls that matter more:

    • Account protection: Turn on multi-factor authentication for executive and finance accounts.

    • Message context: Add external-sender banners so staff can spot email from outside your domain.

    • Behaviour review: Watch for unusual finance or legal communication patterns, especially requests that break the normal flow.

    • Approval friction: Require a second step before money moves or sensitive data leaves.

    If you want the broader foundation first, our article on what email phishing is and how to secure your inbox explains the baseline controls that support this higher-risk category.

    Common Examples of Executive Email Fraud

    Whaling usually shows up in ways that feel routine. That's why people miss it. The attacker doesn't need drama. They need something that fits your day.

    The fake CEO payment request

    A finance lead receives an email that appears to come from the owner just before lunch. The message says the company is handling a confidential acquisition and asks for an immediate transfer. It also says not to call because the sender is in meetings.

    Nothing in the wording looks obviously broken. The grammar is clean. The signature looks right. The request sounds serious, and the secrecy feels plausible because business owners do sometimes handle sensitive deals discreetly.

    The red flag is the mix of pressure and isolation. The email pushes urgency while cutting off verification. That's the hallmark of a CEO fraud email. The attacker wants the target to act alone, quickly, and outside normal controls.

    The assistant credential capture

    An executive assistant gets a message that appears to come from the CEO or a trusted software service. It asks them to review a secure document before a board meeting or sign in again because a mailbox setting changed.

    The link opens a page that looks familiar. The assistant enters credentials, gets an error, and tries again. At that point, the attacker may already have the login details.

    This version of executive phishing doesn't steal money first. It steals access. Once inside an email account, the attacker can watch conversations, learn approval habits, and time a later fraud attempt much more precisely.

    The vendor payment change

    A controller receives a message that seems to come from an executive who is “helping” a supplier update banking details. The note is short and confident. It may say the change is already approved and only needs processing before end of day.

    This kind of message works because it sounds operational, not suspicious. It borrows the authority of leadership and the routine nature of accounts payable. If your team handles payments by email and doesn't verify banking changes out of band, a message like this can slide through.

    When a request mixes authority, urgency, and secrecy, slow down. Legitimate work can survive a callback.

    These examples differ in detail, but the shape stays the same. Someone trusted appears to ask for something important. The request pushes for speed. Normal verification gets framed as unnecessary or inconvenient.

    How Do You Spot a Whaling Email?

    The hard part about whaling isn't that the email looks sloppy. It's that it often looks polished enough to pass a quick glance. Attackers use public information from company sites and social media, then mimic real business processes with lookalike domains, forged display names, and urgent payment language, as explained in Mimecast's whaling phishing guidance.

    Identifying the Warning Signs of a Whaling Email

    Check the parts people skip

    Individuals often read the display name and the first line of the message. That's not enough. You need to inspect the actual address, the reply path, and the request itself.

    Look for these signs:

    • Unusual sender address: The name says “CEO” but the address originates from a different domain or a near-match domain.

    • Reply-to mismatch: The visible sender looks normal, but replies go somewhere else.

    • Urgency with secrecy: The message insists on immediate action and discourages calling or checking.

    • Sensitive request: It asks for money, credentials, payroll files, tax records, or legal documents.

    • Process bypass: It tells you to ignore normal approvals because the matter is confidential or time-sensitive.

    One detail many teams miss is domain age. A brand-new lookalike domain can be a strong spoofing clue, even if the email body is well written.

    Here's a short explainer if you want to show the concept to staff:

    A simple five-step inbox check

    We teach a short review process because people won't follow a complicated checklist in a busy workday.

    1. Read the actual address, not just the name. Attackers count on staff seeing “Sarah, CEO” and stopping there.

    2. Pause on unusual urgency. Real executives may be brief, but they shouldn't need you to ignore controls.

    3. Check where the reply goes. A mismatch often exposes the scam.

    4. Ask whether the request fits the role. A CEO asking an assistant for credentials or gift-card codes should feel wrong.

    5. Verify outside email. Call, message, or speak to the sender through a known channel.

    What to say to your team

    Staff often worry about seeming slow or difficult. That's part of why whaling works. Attackers exploit politeness and hierarchy as much as technical weakness.

    Verification is not distrust. It's standard handling for high-risk requests.

    Your team doesn't need to become forensic analysts. They need permission to pause, inspect, and confirm. That one habit catches many executive fraud attempts before they turn into an incident.

    Protecting Your Team from Whaling Attacks

    The best defence is layered. No single tool stops every whaling attack, because the scam mixes technical spoofing with human pressure. You need stronger account security, clearer business process, and an email setup that supports both without making daily work painful.

    For organisations in Canada, this isn't abstract. IBM's overview of whale phishing cites the Canadian Centre for Cyber Security's 2023 National Cyber Threat Assessment, which says phishing is one of the most common and effective delivery methods used by cyber threat actors. The same assessment reports that 65% of Canadian organisations said they were impacted by a cybersecurity incident in the prior 12 months, with smaller firms especially exposed.

    Protecting Your Team from Whaling Attacks

    Start with process before tools

    A lot of damage happens because the process is loose, not because the attacker is brilliant. If your team can change payment details or send payroll data based on email alone, you've given the scam an easy path.

    We'd put these controls in place first:

    • Mandatory callback for money movement: Any wire transfer, banking change, or unusual invoice approval gets confirmed through a known phone number or another trusted channel.

    • Two-person approval for sensitive actions: One person prepares the action, another approves it.

    • No credential sharing by email: Ever. Not for admins, not for assistants, not for executives.

    • Written escalation path: Staff should know exactly who to contact when a request feels off.

    These steps matter because they remove the attacker's favourite advantage, which is speed.

    Lock down executive and finance mailboxes

    Executives and finance staff need stronger inbox protection than the average account. Their accounts sit close to money, legal authority, and sensitive records.

    Focus on practical controls:

    • Multi-factor authentication: This adds a second check beyond the password.

    • External-sender banners: These help staff see when a message came from outside your organisation.

    • Anti-spoofing standards: DMARC, SPF, and DKIM help receiving systems evaluate whether mail claiming to come from your domain is legitimate.

    • Behaviour-based alerts: Flag unusual finance, legal, or approval patterns instead of relying only on spam scores.

    If those terms are unfamiliar, here's the plain-English version. SPF, DKIM, and DMARC are email authentication standards. They help other mail systems decide whether a message using your domain should be trusted. They won't solve whaling by themselves, but they reduce obvious domain abuse and support better filtering.

    Train for the exact scenario

    Generic phishing training often says “don't click suspicious links.” That's useful, but whaling needs more role-based training.

    A finance lead should practise spotting fake transfer requests. An assistant should practise verifying document-share emails and login prompts. An owner should know that their public travel plans and public team structure can help an attacker write a more convincing message.

    Short scenario drills work better than long policy documents. We'd rather see a team rehearse three believable executive fraud situations than skim a generic slide deck once a year. If you're reviewing tools to support that effort, our guide to anti-phishing programs for business teams can help you compare your options.

    Small teams don't need complex security theatre. They need a few rules that people will actually follow under pressure.

    Don't ignore data residency and provider trust

    For high-stakes executive communication, email provider choices matter. If your company handles financial approvals, legal discussions, HR records, or client data by email, you should know where that data lives and which laws apply to it.

    For Canadian organisations, PIPEDA requirements from the Office of the Privacy Commissioner of Canada are part of that picture. Data residency doesn't stop a whaling attack on its own, but it does shape your privacy posture, your compliance story, and how much control you have over sensitive communications.

    This is our view at Typewire, and we'll state it clearly as opinion. Small teams are usually better served by an email provider that keeps security simple, supports modern authentication, blocks common tracking tricks like spy pixels, and keeps business email under infrastructure you understand. Complexity is often its own risk.

    Build a response habit before you need it

    Even strong teams sometimes click, reply, or approve something they shouldn't. What matters next is how quickly people report it.

    Set a basic incident routine:

    1. Stop the action if the payment or data transfer hasn't completed.

    2. Report the message internally so IT or your admin contact can review related mail.

    3. Reset credentials and sessions if someone entered login details.

    4. Warn affected staff if the attacker may now impersonate someone inside the company.

    5. Document what happened so you can tighten the process that failed.

    The aim isn't perfection. It's resilience. A team that verifies unusual requests, protects key inboxes, and reports quickly is much harder to exploit.


    If you want an email setup built for privacy-conscious teams, Typewire is a Canadian private email provider that hosts data in Canada on infrastructure we operate ourselves. We focus on practical outcomes: encrypted email, phishing detection, spy pixel blocking, custom domains, and straightforward business email without ads, tracking, or third-party cloud dependence.

  • What Is a Phishing Email Example: Spot Dangerous Scams 2026

    What Is a Phishing Email Example: Spot Dangerous Scams 2026

    A phishing email is a fraudulent message designed to trick you into revealing sensitive information, like passwords or credit card numbers, by pretending to be from a trustworthy source. In 2025, phishing emails that used urgent prompts such as “Update your credentials” reached an 18% click-through rate, which helps explain why these messages keep showing up in everyday inboxes.

    You've probably seen one already. It looks like a password reset, a delivery update, an invoice, or a bank warning. It doesn't look wild or ridiculous. It looks normal enough that you almost click before you stop and think.

    That's what makes modern phishing tricky. A lot of phishing email examples no longer look sloppy. Many now use polished wording, familiar branding, and simple requests that feel routine.

    At Typewire, we think the best defence starts with recognition. If you can see the pattern, you're much harder to fool.

    Last updated: 25 May 2026

    What Is a Phishing Email

    A phishing email is a fake message built to impersonate someone you trust. That might be your bank, Microsoft 365, a delivery company, your manager, or even your own email provider. The goal is usually simple. Get you to click, sign in, download something, or hand over information.

    Security guidance describes phishing as a social-engineering attack. That means the attacker is trying to manipulate your decision-making, not just break software. The message pushes for a fast response before you slow down and verify what's happening, as explained in SecurityMetrics' phishing email guidance.

    Why phishing works

    Imagine someone showing up at your door wearing a convincing uniform and asking for your house keys. They don't need to pick the lock if they can persuade you to open the door yourself.

    Phishing works the same way. The email borrows trust from a known brand or a familiar type of message, then asks for one small action. Click this link. Open this file. Confirm your password. Review this invoice.

    Practical rule: If an email tries to create urgency before it creates clarity, treat it as suspicious.

    What a phishing email usually tries to do

    Most phishing email examples fall into a few common goals:

    • Steal credentials by sending you to a fake login page
    • Collect financial details through fake billing or payment messages
    • Install malware through risky attachments such as .zip or .exe
    • Start a larger compromise by getting one small action first

    A lot of readers get confused on one point. They think phishing always means obvious scams with bad spelling. That's outdated. Many current attacks look clean, branded, and believable. A key clue is often not the writing quality. It's the mismatch between what the email claims and what it wants you to do.

    7 Real Phishing Email Examples

    Some of the most effective phishing email examples look like messages you'd expect to receive on a normal Tuesday. Shipping alerts, invoices, account notices, and cloud storage warnings are common because they fit into everyday life. Security reporting has also noted that newer phishing often uses shipping or parcel lures, invoice fraud, and more polished wording shaped by AI, as described in Huntress' 2025 phishing techniques review.

    7 Real Phishing Email Examples

    Fake password reset

    Subject: Your mailbox password expires today
    From: Security Team mailprotectverify@outlook.com

    Your email access will be suspended unless you confirm your credentials now.

    Reset Password

    This one works because most of us have seen legitimate password notices before. The red flags are the pressure, the vague sender name, and the public email address pretending to be an internal security team.

    If you hover over the button, it often leads somewhere unrelated to your real provider. That's one of the clearest signs of a phishing email.

    Bogus order confirmation

    Subject: Order received for your new smartphone

    Thank you for your purchase. If you did not place this order, click below to cancel immediately.

    This lure creates panic. You didn't order anything, so your instinct is to hit “cancel” before something gets charged.

    That reaction is exactly what the attacker wants. A real merchant usually gives you a way to review the order inside your account, not a rush button in a random email. If you're concerned, go to the company site directly in your browser instead of using the message link.

    Bank account alert

    Subject: Unusual sign-in detected

    We noticed suspicious activity on your account. Verify your identity within 30 minutes to avoid a temporary hold.

    Bank phishing often looks clean and professional. The wording may be polished. The logo may look right. The danger sits in the link destination and the pressure to act without checking first.

    A real bank may alert you to activity, but it won't expect you to trust a random link blindly. Open your banking app or type the bank's address yourself.

    When a message says “protect your account now,” stop and verify before doing anything else.

    Fraudulent invoice scam

    Subject: Invoice attached for April services

    Please process payment today to avoid late fees. See attached file.

    This example is common in small businesses because invoices already move through email every day. The attacker counts on someone in accounting, operations, or a busy owner paying quickly.

    Watch for context gaps. Do you recognise the vendor? Were services provided? Is the attachment unexpected? A fake invoice may arrive as a document, archive file, or file that asks you to enable something after opening.

    Storage limit exceeded

    Subject: Your cloud storage is full

    Your incoming mail will be blocked unless you upgrade your storage quota. Sign in to continue.

    This one plays on a real fear. If email stops working, it can disrupt your whole day.

    The catch is that the message often sends you to a login page that only looks like your provider. The page is there to harvest your username and password. Many people search “what is a phishing email example” because they've seen this exact message and aren't sure if it's legitimate.

    Prize or lottery message

    Subject: Congratulations, your claim is ready

    You have been selected to receive a payout. Reply with your full name, address, and banking details.

    This is an older pattern, but it still appears because it targets hope instead of fear. It may not ask you to click a link at first. Sometimes it starts by collecting personal details through a reply.

    That matters because phishing doesn't always mean fake websites. Sometimes the attacker wants enough information to keep building trust.

    Social media security alert

    Subject: New login to your social account

    We detected a login from a new device. Review activity now.

    This one often looks especially believable because social platforms send real security notices. A fake version may copy the layout, colours, and wording almost perfectly.

    The clue is usually small. Maybe the sender address is slightly off. Maybe the button goes to a strange domain. Maybe the email asks you to sign in through a path you've never seen before. Those tiny inconsistencies are classic phishing red flags.

    Common Signs of a Phishing Email

    A good phishing email rarely looks ridiculous anymore. It often looks like a normal invoice, a shipping update, or a sign-in notice written in clean, professional language. Many are polished with AI, which means grammar mistakes are no longer a reliable warning sign.

    Common Signs of a Phishing Email

    Sender details that don't line up

    The sender name is the label on the package. The actual email address is the return address. Attackers know people often read the label and skip the return address.

    So check both.

    A message can say “Microsoft Support” or “Accounts Payable” and still come from a random public mailbox that has nothing to do with the company. Some phishing emails also use domains that look close enough to feel familiar at a glance, especially on a phone screen. If you want a clear explanation of how fake sender identity works, see our guide to what email spoofing is and how to protect your privacy and security.

    Links, attachments, and low-friction traps

    Phishing usually asks for one small action that feels routine. Review the invoice. Track the parcel. Open the shared document. Confirm your login.

    That small action is the trap.

    Use this quick check before you interact with any message:

    • Hover before clicking. Look at the destination, not the button text.
    • Treat unexpected attachments with caution. An invoice or delivery note can be fake even if it looks ordinary.
    • Watch for risky file types. Compressed files and executable files deserve extra scrutiny.
    • Open the site yourself. If the email claims to be from a courier, bank, or software provider, type the official website into your browser instead.

    Urgency, emotion, and vague language

    Phishing works by shrinking the time you give yourself to think. A real company may send an urgent notice. A phishing email often adds pressure, confusion, or emotion on top of that urgency.

    Here are some common patterns:

    Pattern Why attackers use it
    Urgent deadline To push you into acting before you verify
    Fear of account loss To trigger a quick login or password reset
    Surprise charge, invoice, or refund To provoke a fast emotional reaction
    Generic greeting To make one message work for thousands of targets

    Modern phishing often sounds calm and professional. That is part of what makes it dangerous. If an email wants money, credentials, or a file download, slow the moment down and inspect the details. Private email services can help here too by filtering suspicious messages, blocking known bad domains, and giving you a cleaner buffer between you and these look-alike scams.

    What to Do If You Receive One

    If you receive a suspicious message, don’t interact with it. Don’t click the link, don’t open the attachment, and don’t reply to “check if it’s real.” The safest first move is always to stop the conversation.

    What to Do If You Receive One

    A simple response plan works well:

    • Leave the message unopened if possible. If it’s already open, close it without clicking anything.
    • Report it in your mail app. Most email services have a phishing or junk reporting option.
    • Verify through a separate channel. If the email claims to be from your bank, vendor, or IT team, contact them through their official site or known phone number.
    • Delete it after reporting. You don’t need it sitting in your inbox.

    If you want a broader checklist, our post on how to avoid phishing emails with essential security tips covers good daily habits that reduce risk.

    If you already clicked, act quickly. Change the password for the affected account from the official website, not the emailed link. If you reused that password elsewhere, change those too. If banking or payment details were involved, contact your financial institution right away.

    This short video gives a helpful visual walkthrough of the response process.

    How Typewire Helps Block Phishing

    A lot of phishing emails no longer look sloppy. They look like a normal invoice, a shipping update, or a message from a vendor you already know. The wording is cleaner now, often polished enough to pass a quick glance. That means your email service has to do more than catch obvious junk. It needs to screen for subtle fraud before the message gets a chance to pressure you into clicking.

    Typewire adds several layers that help with that job. It includes anti-spam filtering, phishing detection, virus scanning, and spy pixel blocking.

    Because we operate our own infrastructure in Vancouver, we control these checks end-to-end, which means we can tune filtering aggressively without relying on third-party systems that may prioritize other concerns.

    Spy pixels work like read receipts that you never agreed to. They can tell a sender that your inbox is active and that you opened the message, which gives scammers useful feedback.

    Why the email setup matters

    Email security starts before a message reaches your inbox. Your provider handles the systems that receive mail, examine it, and decide whether it looks trustworthy enough to deliver. If a service controls its own filtering and mail setup, it has more room to tune those checks and reject suspicious traffic earlier.

    Authentication standards also help receiving servers decide whether a message likely came from the domain it claims to represent. That does not stop every phishing email, especially lookalike domains designed to mimic a real company, but it cuts down one common form of impersonation. If you want the technical side explained in plain language, our guide on how to authenticate email with a real-world setup that works walks through the basics.

    Privacy is part of security

    Privacy tools help here too.

    A private email service cannot replace careful reading, but it can reduce how much attackers learn from your inbox. Attachment scanning can catch risky files. Phishing filters can flag suspicious messages before they blend in with normal work email. Blocking hidden trackers removes one of the easiest ways scammers test whether a real person is reading and engaging.

    For Canadian users, local hosting and privacy rules may also factor into which provider they trust. Typewire says it hosts email in Canada and operates under PIPEDA, which is Canada’s federal private-sector privacy law. You can read the official law on the Government of Canada’s PIPEDA page. That will not block a fake invoice on its own, but it does affect how a provider handles storage, access, and personal data.

    Frequently Asked Questions About Phishing

    Is phishing the same as spam

    Not exactly. Spam is unwanted email. Phishing is deceptive email with a goal, usually stealing credentials, money, or access. Some phishing arrives as spam, but not all spam is phishing.

    Can you get a virus just by opening an email

    Usually, the bigger risk comes from what you do next. Clicking a link, downloading a file, opening a risky attachment type, or entering credentials causes most of the actual harm. The message itself is often just the bait.

    Does phishing only happen by email

    No. The same trick shows up in text messages and phone calls too. Text-based phishing is often called smishing. Voice-based impersonation is often called vishing.

    Phishing stays common because it scales well. A 2025 threat summary said 3.4 billion phishing emails per day were being sent, estimated that 38% of global phishing email volume came from North America, and found that urgency-based prompts such as “Update your credentials” reached an 18% click-through rate, according to SQ Magazine’s phishing statistics summary. The lesson is simple. Slow down when an email tries to speed you up.


    If you want an email service built around privacy, filtering, and fewer hidden tracking tricks, take a look at Typewire. We focus on secure, ad-free email with Canadian data residency, so you have another layer of defence while you build better phishing habits.