“Whaling” is another evolution of phishing attacks that uses sophisticated social engineering techniques to steal confidential information, personal data, access credentials to restricted services/resources, and specifically information with relevant value from an economic and commercial perspective.

What distinguishes whaling from phishing and spear phishing is the choice of targets: relevant executives of private business and government agencies. The word whaling indicates that the target is a big fish to capture.

Whaling adopts the same methods of spear phishing attacks, but the scam email is designed to masquerade as a critical business email sent from a legitimate authority, typically from relevant executives of important organizations. Typically, the content of the message sent is designed for upper management and reports some kind of fake company-wide concern or high confidential information.

