Whaling Attacks: Why Executives Need Different Phishing Training

In this blog

Whaling Attacks Why Executives Need Different Phishing Training

In January 2024, a finance employee at the engineering firm Arup joined a video call with who appeared to be the company’s CFO and several senior colleagues. Every face looked right. Every voice sounded right. The employee authorized 15 wire transfers totaling 25.6 million dollars. Every person on that call was a deepfake.

Six months later, an executive at Ferrari received a WhatsApp voice call from someone who sounded exactly like CEO Benedetto Vigna, asking for urgent help with a confidential transaction. The executive asked a single personal question only the real Vigna would know the answer to. The caller hesitated and hung up. Nothing was lost.

Same attack pattern. Same level of technical sophistication. Two completely different outcomes. The difference was not luck. It was whether the person on the receiving end had been trained to expect this specific kind of pressure, in a way generic phishing awareness training rarely prepares anyone for.

In Short

Whaling attacks succeed or fail based on whether the targeted executive has built the instinct to pause and verify under real social pressure, not based on whether they can recite phishing red flags from a slide deck.

Two Executives, Two Outcomes

Arup

The Arup incident remains the most consequential publicly documented deepfake whaling attack to date, and it was followed roughly a year later by a similar attempt against a Singapore-based multinational that resulted in a 499,000 dollar loss through the same deepfake video call technique.

Ferrari

Ferrari’s outcome was shaped by a specific, trained behavior: asking a verification question through a channel and method the attacker could not have anticipated or scripted for, and acting on suspicion despite pressure from seemingly familiar voices.

The Arup and Ferrari cases are useful precisely because they show the same attack technique landing on two different people with two different results. According to a detailed timeline compiled by Vectra AI’s research on whaling attacks , the Arup incident remains the most consequential publicly documented deepfake whaling attack to date, and it was followed roughly a year later by a similar attempt against a Singapore-based multinational that resulted in a 499,000 dollar loss through the same deepfake video call technique.

What separated Ferrari’s outcome from Arup’s was not better technology or a smarter employee. It was a specific, trained behavior: asking a verification question through a channel and method the attacker could not have anticipated or scripted for, and being willing to act on suspicion even while multiple “familiar” voices on the call insisted everything was legitimate. That instinct, treating urgency and social pressure as a reason to slow down rather than speed up, is exactly what whaling-specific training needs to build, and it does not develop from watching the same generic phishing video every employee sees once a year.

Why Standard Training Doesn’t Reach Executives

Executives are frequently the hardest group in any organization to train effectively, for reasons that have little to do with intelligence or awareness and everything to do with role, ego, and time.

Exempt From Testing

They are often exempted from company-wide phishing tests. Many organizations quietly excuse leadership from routine simulated phishing campaigns, either out of deference or because scheduling around executive calendars is difficult, which means the group facing the highest-stakes attacks often gets the least practical testing.

Confidence Works Against Them

Senior leaders have typically built careers on decisive judgment, which can translate into overconfidence about their ability to spot a scam, right up until the scam is built specifically to exploit their actual relationships and calendar.

Constant Time Pressure

Executives operate under real, near-constant urgency as a normal part of the job, which is exactly the emotional state whaling attacks are engineered to exploit. A request that would look obviously suspicious to someone with time to think looks routine to someone already juggling twelve urgent things.

Generic Training Feels Irrelevant

A slide about spotting a suspicious link from an unknown sender does not prepare anyone for a deepfake video call from colleagues they recognize, discussing a real, confidential business matter.

Broader research on training effectiveness supports this. The National Cybersecurity Alliance’s ongoing research into cybersecurity attitudes has found a rising sense of security fatalism among the public , the belief that protective effort is pointless, alongside growing confusion about how to act on security information. If that is true of the general working population, it is even more relevant for a group whose training is often generic, infrequent, and disconnected from the specific way they are actually targeted.

Why Standard Training Doesn't Reach Executives

What Whaling-Specific Training Actually Needs

Training that reaches executives looks different from a standard awareness program in a few specific ways:

1

Built Around Their Real Calendar

It has to be built around their real calendar, not a generic template. A whaling simulation referencing a plausible acquisition, board matter, or urgent personal request lands very differently than a generic “your account will be suspended” email.

2

Multi-Channel Pressure

It has to include multi-channel pressure, not just email. The Arup and Ferrari cases both moved beyond email into voice and video. Training that only tests inbox behavior misses the exact escalation pattern attackers now use.

3

Verification Habit

It needs a built-in verification habit, not just a warning. The lesson from Ferrari was not “be more suspicious.” It was having a specific, practiced action, asking something only the real person would know, ready to use under pressure.

4

Include the People Around the Executive

It should include the people around the executive, not just the executive. Executive assistants, chiefs of staff, and finance staff who act on an executive’s authority are frequently the actual target, since they are often easier to reach and less likely to be personally recognized by the attacker’s impersonation.

PhishCare’s Whaling Simulation

PhishCare’s whaling simulation is built for exactly this group, running realistic, role-specific scenarios for executives and the people authorized to act on their behalf, separate from standard company-wide phishing campaigns. For the broader framework on how this fits alongside general employee testing, see our guide on spear phishing training, and for the voice-channel piece of this pattern specifically, our guide on vishing simulation platforms covers how attackers use phone calls to reinforce exactly this kind of pressure.

Measuring Executive Risk Separately

📊

Keep Executive Risk Visible

Standard company-wide risk metrics often hide executive-specific risk rather than revealing it, since a small executive group’s results get averaged into a much larger employee population. Tracking whaling simulation results as a distinct line inside an employee phishing risk score keeps this risk visible to leadership and security teams, rather than letting it disappear into a company-wide average that looks reassuring on paper while leaving the highest-value targets untested in practice.

Final Thoughts

Key Takeaway

The gap between Arup’s 25.6 million dollar loss and Ferrari’s successful defense was not a gap in intelligence, seniority, or resources. It was a gap in whether one specific, practiced instinct had been built before the moment it was needed. That is what whaling-specific training is actually for: not making executives recite red flags, but giving them one reliable, practiced move to make when everything about a request feels urgent and everyone on the call sounds exactly right.

Frequently Asked Questions

Why do executives need different phishing training than regular employees?

Executives are targeted with far more research-intensive, personalized attacks, often extending beyond email into voice calls and deepfake video, and they are frequently exempted from standard company-wide phishing tests, leaving the highest-value targets in an organization the least practically tested.

What is an example of a real whaling attack?

In January 2024, attackers used deepfake video to impersonate a company’s CFO and several colleagues on a video call, convincing a finance employee at the engineering firm Arup to authorize 15 wire transfers totaling 25.6 million dollars.

Can whaling attacks be stopped through training alone?

Training significantly reduces risk but works best combined with organizational safeguards, such as requiring a second verification channel for any urgent financial request, regardless of how convincing the initial request appears.

Why do executives often resist security training?

Common reasons include confidence built from career success, near-constant time pressure that discourages careful verification, and generic training content that does not reflect the specific, sophisticated way executives are actually targeted.

Does PhishCare offer whaling simulation for executives?

Yes. PhishCare supports whaling simulation as a distinct campaign type alongside standard phishing and spear phishing testing, allowing organizations to test executives and the people authorized to act on their behalf separately from company-wide campaigns.

Free Demo

See How Your Executives Would Respond

A generic phishing test will not tell you how your executives would respond to a deepfake video call. See how PhishCare’s whaling simulation works with a free demo account, no credit card required.

Content Reviewed By

Mohammed Nawaz Sajjad, Sr. Security Analyst at PhishCare
Mohammed Nawaz Sajjad
Sr. Security Analyst at CyberSapiens | Phishing Simulation | Ethical Hacker | Bug Hunter | Red Team

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking.

View LinkedIn Profile