What Is Executive Phishing? How Cybercriminals Target Business Leaders

Written by Fabian RaemyReviewed by Jake JohnsonPublished August 12, 202618 min read
What Is Executive Phishing? How Cybercriminals Target Business Leaders
The Takeaway

Executive phishing doesn't look like the phishing emails your team trains on. It looks like your CFO, your attorney, or your own voice.

Quick Answer: Executive phishing is a targeted phishing attack, such as whaling, spear phishing, or CEO fraud, that impersonates or targets a specific business leader to steal money, credentials, or data. It succeeds by exploiting an executive's public visibility and authority rather than by hacking a system, and in 2025 it drove more than $3 billion in U.S. business email compromise losses alone.

If you are a CEO, founder, CFO, or general counsel, your name is probably already searchable next to your title, your company, and a rough sense of what you are worth to defraud. Attackers do not need to break into anything to get started. A funding announcement, an earnings call, or a LinkedIn post about a new hire is often enough raw material to build a convincing pretext.

Most phishing training was built for a generic employee inbox, not for someone whose calendar, travel, and signing authority are semi-public. This is exactly where executive phishing cybersecurity has to work differently from standard employee training.

A well-timed email that references a real deal, a real board member, or a real family event does not look like the phishing example from last year's compliance video. It looks like an ordinary Tuesday. This is why executive phishing attacks succeed against people who would never fall for a lottery scam or a fake delivery text. The lure is built specifically for them, often using information they made public themselves, which is what separates whaling and CEO fraud from the phishing everyone else gets trained to spot.

Key Takeaways

  • Business email compromise cost victims more than $3.05 billion in the United States in 2025 across 24,768 complaints, and $30.26 million of that total involved AI-generated content, according to the FBI's Internet Crime Complaint Center.
  • A University of Texas at San Antonio study found that AI-written phishing emails impersonating a supervisor performed as well as those written by communications professionals, and significantly outperformed them in a time-sensitive scenario.
  • Human listeners correctly identify AI-cloned voices from commercial tools only 61 to 66 percent of the time, while an automated detector in the same 2026 study caught synthetic audio more than 94 percent of the time.
  • The FBI has documented attackers mailing physical extortion letters directly to corporate executives, showing that executive phishing now spans channels well beyond email.
  • Batten Black's six-domain assessment treats executive email security as one piece of a wider exposure picture, since the same public information that fuels a whaling email also drives residential and family targeting. Select a date and time to see exactly what's exposed.

What Is Executive Phishing?

Executive phishing covers several related attack types that all share one trait: they target a specific, named business leader rather than a broad list of employees. Spear phishing executives means researching one person's role, relationships, and recent activity to write a message that gets past their skepticism.

Common Types of Executive Phishing

The main forms include:

  • Whaling: A form of spear phishing aimed specifically at the most senior "whale" in an organization, such as a CEO, CFO, or board member. It typically uses more research and a more convincing pretext than a standard phishing email.
  • Business email compromise (BEC): An attacker impersonates an executive, attorney, or vendor to redirect a wire transfer or change payment instructions.
  • CEO fraud or CEO phishing: Common terms for BEC attacks where the impersonated sender is a chief executive.

Why Executive Phishing Is So Costly

The FBI logged 24,768 BEC complaints in 2025 with reported losses of $3,046,598,558, making it the second most costly cybercrime category the bureau tracks, behind only investment fraud.

Why Spam Filters Are Not Enough

Executive phishing succeeds by exploiting trust and urgency rather than by breaking through a firewall, which is exactly why a strong spam filter alone does not stop it.

Whaling, Spear Phishing, BEC, and CEO Fraud at a Glance

These terms get used interchangeably in most coverage of the topic, but they describe different points in the same attack chain. The table below separates them by who they target and what the attacker is actually after.

Attack Type Who It Targets How It Typically Arrives Primary Goal
Spear Phishing One specific employee or executive A researched, personalized email Steal credentials or sensitive data
Whaling A senior executive specifically (CEO, CFO, board member) An email built around real, public details Steal credentials, data, or authorize a payment
Business Email Compromise (BEC) Finance, HR, or an assistant with payment authority A spoofed or compromised executive or vendor email Redirect a wire transfer or payment
CEO Fraud / CEO Phishing An employee who reports to or trusts the CEO An urgent message appearing to come from the CEO Authorize an unusual or rushed payment
Deepfake Executive Impersonation Anyone on a call or video with the executive A cloned voice or fabricated video Bypass verbal verification for a payment or data request

How Executive Phishing Attacks Exploit Social Engineering and Public Data

Executive phishing attacks follow a predictable pipeline: research, pretext, urgency, and payload. An attacker starts with whatever is already public, a press mention, a conference bio, an assistant's name on a company directory, and uses it to make the next message feel familiar rather than suspicious.

How the Attack Unfolds

1 Research

Gathers public details, a recent deal, a travel post, an org chart, that make a future message feel informed rather than generic.

2 Pretext

Those details get built into a plausible reason for contact, often mimicking a real vendor, attorney, or internal process the target already recognizes.

3 Urgency

Adds time pressure, a closing deadline, an angry client, a compliance deadline, designed to short-circuit the target's normal verification habits.

4 Payload

The actual ask arrives, usually a wire transfer, a credential entry, or a request to open an attachment, timed to when resistance is lowest.

Social engineering attacks work because they borrow trust that already exists instead of trying to manufacture new trust from nothing. A 2025 University of Texas at San Antonio study published through IEEE Access tested this directly, sending AI-generated and human-written phishing emails impersonating a supervisor to thousands of employees.

The supervisor-impersonation emails, the closest real-world equivalent to a whaling phishing attack, produced click rates around 21 percent and got roughly 11 percent of recipients to enter data, regardless of whether a human or an AI wrote the message. When researchers asked people why they engaged, the strongest factor by far was simply that the email came from what looked like an internal, familiar address.

That single finding explains most of what makes executive phishing dangerous: the message does not need to be clever if the sender identity is convincing enough.

Signs of a Targeted Executive Impersonation Scam

  • Unusual Urgency From a Known Sender: A request from a supervisor, attorney, or partner that demands action within minutes, especially outside normal business hours.
  • A Request to Bypass Normal Verification: A message asking you to skip a callback confirmation or a second approver "just this once, given the timing."
  • Personal Details That Feel Too Specific: References to a real deal, a real trip, or a real family event that were only ever mentioned publicly, never confirmed privately.
  • A Slightly Off Channel: A message arriving through a personal email address, a new phone number, or a different app than the sender normally uses to reach you.

Here's what those four signs actually look like stacked into a single message. Tap each highlighted phrase below.

From:"James Whitfield" <j.whitfield.exec@gmail-secure-mail.com>
Subject:URGENT: Wire needed before close of business today

Hi Sarah,

I'm still finishing up details from this morning's board call about the acquisition, so instead of my usual laptop.

I need you to process a wire transfer to our new escrow partner .

I know this , go ahead and send it directly. I'll confirm everything when I'm back online this evening.

Also, . Thanks, James

Tap a highlighted phrase to see why it's a red flag.

CEO Fraud and CEO Phishing: How Wire Transfer Fraud Happens

CEO fraud and CEO phishing both describe the moment a whaling attempt turns into an actual financial loss, once an attacker's message convinces someone to move money. The FBI's own case files show how ordinary these requests can look right up until the money is gone.

Real Wire Fraud Cases the FBI Has Documented

CEO fraud rarely announces itself. In one case detailed by the FBI, a senior citizen closing on a property received an email that appeared to come from the title company, containing wire instructions for over $1.3 million to an account criminals controlled.

In another, a city government office wired more than $6 million after receiving fraudulent instructions from an impersonated vendor. In a third, a homebuyer wired over $449,000 after receiving an email impersonating their own attorneys.

FBI Documented Case $0

A senior citizen closing on a property received wire instructions from an email impersonating the title company.

FBI Documented Case $0

A city government office wired funds after receiving fraudulent instructions from an impersonated vendor.

FBI Documented Case $0

A homebuyer wired funds after receiving an email impersonating their own attorneys.

Wire transfer fraud like this works because the request looks routine. It arrives at a moment when a wire transfer was already expected, from a sender whose name the recipient already recognized, asking for something that only feels unusual in hindsight.

The FBI's Recovery Asset Team was able to freeze funds in the cases above only because the incidents were reported within hours, underscoring how narrow the recovery window really is.

Where BEC and Wire Fraud Losses Concentrate

BEC attacks rarely travel alone. The categories below all show up in the same IC3 dataset, and each one supplies either the money lost or the research an attacker used to get there.

Fraud Type 2025 IC3 Complaints 2025 IC3 Reported Losses Relevance to Executive Phishing
Business Email Compromise 24,768 $3,046,598,558 Directly impersonates an executive or assistant to redirect a wire transfer
Real Estate Fraud 12,368 $275,110,419 Frequently targets executives and principals during property closings
Government Impersonation 32,424 $797,943,193 Used in mail-based extortion letters sent directly to corporate executives
Personal Data Breach 67,456 $1,314,923,988 Supplies the research attackers use to build a credible executive pretext
Identity Theft 31,675 $185,832,657 Exploits an executive's exposed personal records to bypass verification
Employment Fraud 24,688 $362,934,762 Used to harvest internal org-chart and assistant contact details

Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report

A companion piece breaks down how these same fraud categories fit into the broader picture facing wealthy households, in The Real Security Risks Facing High-Net-Worth Individuals.

AI Phishing Attacks and Deepfake Executive Impersonation

AI phishing attacks have moved from a theoretical risk to a line item in federal crime statistics. The FBI attributed $893 million in 2025 losses to AI-related fraud, including $30.26 million specifically tied to AI-enabled business email compromise.

Voice cloning is the sharpest edge of this trend: deepfake executive impersonation has already been used to convince a finance employee at a global engineering firm to wire $25 million after a video call with what turned out to be fabricated colleagues.

How Well Can People Detect a Cloned Voice?

Detecting these fakes is genuinely difficult, not just for untrained employees. A 2026 study from Fraunhofer AISEC, the largest audio deepfake perception study conducted to date, found that people correctly identify cloned voices from commercial synthesis tools only 61 to 66 percent of the time. An automated detector maintained accuracy above 94 percent across the same test set.

Detecting a Cloned Voice

Human Listeners 61-66%

Automated Detector 94%+

Fraunhofer AISEC, 2026: the largest audio deepfake perception study conducted to date.

A separate University College London study published in PLOS ONE found nearly identical results years earlier, at 73 percent human accuracy, and documented a real 2019 case in which fraudsters used a cloned executive voice to redirect a €220,000 wire transfer.

Deepfake executive impersonation does not need to be perfect. It only needs to be good enough to survive a few seconds of doubt during a busy afternoon. If any of this sounds like exposure you already recognize, a confidential assessment shows exactly what's public about you right now, before someone else uses it.

Why Deepfake Impersonation Fools Even Careful Executives

A few factors make deepfake impersonation especially convincing, even for executives who know what to watch for:

  • Voice Cloning Needs Very Little Source Audio: A few seconds of a public speech, earnings call, or interview is enough to train a convincing clone.
  • Commercial Tools Produce the Hardest Fakes to Catch: Fakes generated by accessible, commercial voice APIs were the single hardest category for human listeners to correctly identify.
  • Growing Skepticism Cuts Both Ways: The same 2026 research found people are now more likely to wrongly doubt a real recording, a dynamic attackers can exploit by claiming a genuine call was staged.
  • Video Adds a Second Layer of Trust: A face on a call reduces suspicion even when something about the voice alone might otherwise raise a flag.

Executive Email Security vs. Standard Corporate Protection

Executive email security is not the same problem as company-wide spam filtering, even though most organizations budget for it as if it were. Standard corporate tools are tuned to catch high-volume, generic phishing. They were never designed to flag a single, well-researched message written for one specific person, using details a generic filter has no way to recognize as risky.


Coordinated Executive Advisory
Standard Corporate Email Security
Email Filtering and Spam Detection
Included, with review of executive-specific rules
Catches high-volume phishing
Executive's Personal Devices and Accounts
Assessed as part of a full exposure review
Rarely covered
Family Member Exposure
Assessed and addressed directly
Not covered
Wire Transfer Verification Protocol
Built and tested with the client
Sometimes, IT-defined
Data Broker and Public Record Monitoring
Coordinated removal and ongoing monitoring
Not covered
Incident Response After a Targeted Attempt
One advisor coordinates the full response
IT help desk queue

Coordinated Executive Advisory
Consumer Security Tools
Email Filtering and Spam Detection
Included, with review of executive-specific rules
Limited or none
Executive's Personal Devices and Accounts
Assessed as part of a full exposure review
Partial, user-managed
Family Member Exposure
Assessed and addressed directly
Not covered
Wire Transfer Verification Protocol
Built and tested with the client
Not applicable
Data Broker and Public Record Monitoring
Coordinated removal and ongoing monitoring
Point-solution subscription only
Incident Response After a Targeted Attempt
One advisor coordinates the full response
Self-directed

Where This Coordination Gap Actually Costs Executives

Executive cybersecurity has to close the gap this comparison shows: the layer that catches spam and the layer that catches a targeted whaling attempt are not the same layer, no matter how good the first one is. This is the same gap addressed in more detail on the page covering executive and founder security advisory, which maps out how exposure changes once a leader's profile becomes public.

Batten Black exists for exactly this gap. Standard corporate email security was built to catch spam at scale, not a single, carefully researched message aimed at one executive.

Batten Black's six-domain assessment reviews executive email security alongside the personal exposure, family details, and public records that make a whaling attempt or a deepfake call convincing in the first place. One named advisor coordinates the response so a targeted attempt gets caught before it becomes a wire transfer.

Book a Confidential Assessment See exactly what an attacker could already piece together about you, before they use it.

Executive Cybersecurity: How to Prevent Executive Phishing Before It Costs You

Preventing executive phishing starts by assuming any single email, call, or video request could be fabricated, no matter how convincing the sender sounds. No single control catches everything, which is why the strongest defenses stack several layers rather than relying on one.

Close the Credential and Wire Transfer Gaps

Phishing-resistant multi-factor authentication, the kind built on hardware keys rather than text message codes, closes off the credential-harvesting path that most spear phishing depends on. It will not stop a wire transfer request on its own, though, which is why a separate verification protocol for payments matters just as much.

A callback verification protocol means any request to move money or change payment details gets confirmed through a phone number already on file, never one supplied inside the message itself.

The FTC recorded more than $3.5 billion in imposter scam losses in 2025, nearly three times what was reported in 2020, with business impersonation among the fastest-growing categories in that total. A verified callback catches most of this fraud before a wire ever leaves the building.

What a Callback Verification Protocol Should Include

A strong callback verification protocol should create multiple checkpoints before any unusual or high-risk request is approved:

  • An Independently Sourced Phone Number: Call a number already on file or saved in a verified directory, never one included in the request itself.
  • A Second Approver for Unusual Requests: Any payment change or first-time wire above a set threshold requires sign-off from a person who was not part of the original request.
  • A Short, Documented Pause: Build in a brief delay before releasing funds, long enough for a second person to sanity-check the request against normal patterns.
  • A Clear Escalation Path: Make sure every employee who touches payments knows exactly who to call if something feels slightly off, without fear of slowing down a legitimate deal.

Reduce What's Public Before an Attacker Finds It

The other half of prevention happens before an email ever arrives. Reducing what a data broker or a casual search reveals about an executive's home address, travel patterns, and family removes the raw material attackers use to build a credible pretext in the first place, the same OSINT reduction work covered under doxxing protection.

A coordinated review across all six protection domains, outlined in this process breakdown, is what closes the remaining gap between a strong email filter and an executive whose calendar, home address, and family are still fully public.

A Layered Defense, at a Glance

Control What It Stops Where It Lives
Phishing-resistant MFA (hardware keys) Credential harvesting from a spoofed login page Executive's personal and work accounts
Callback verification protocol A fraudulent wire or payment change request Finance and executive assistant workflows
OSINT and data broker reduction The research attackers use to build a pretext Public records, data brokers, social media
Six-domain coordinated review Gaps between digital, financial, and residential exposure One advisor across all six domains

Conclusion: Why Batten Black Is Built to Stop Executive Phishing

Executive phishing works because it is built around one person's real life, not a generic template a spam filter can flag. A whaling email, a CEO fraud wire request, and a cloned voice on a call all rely on the same raw material: an executive's public visibility, routines, and relationships.

Standard IT security stops the phishing everyone else receives. It was never built to catch the one message written specifically for you.

Batten Black closes that gap by treating executive email security as one piece of a coordinated, six-domain assessment rather than an isolated IT problem. One advisor reviews wire transfer protocols, reduces the public data that makes impersonation convincing, and coordinates the response if a targeted attempt gets through. If your role, visibility, or signing authority has grown recently, a confidential assessment shows exactly where you stand today.

Book a Confidential Assessment Discreet. No obligation. Initial findings typically delivered within two weeks.

Sources 

  • FBI Internet Crime Complaint Center: "2025 Internet Crime Report" - ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  • FBI Internet Crime Complaint Center: "Mail Scam Targeting Corporate Executives Claims Ties to Ransomware" - ic3.gov/psa/2025/psa250306-2
  • Federal Trade Commission: "FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025" - ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025
  • University of Texas at San Antonio (IEEE Access): "Lateral Phishing with Large Language Models: A Large Organization Comparative Study" - arxiv.org/pdf/2401.09727
  • Fraunhofer AISEC: "Eroding Trust in Real Speech: A Large-Scale Study of Human Audio Deepfake Perception" - arxiv.org/html/2605.26136
  • University College London (PLOS ONE): "Warning: Humans Cannot Reliably Detect Speech Deepfakes" - journals.plos.org/plosone/article?id=10.1371/journal.pone.0285333

Related

Frequently Asked
Whaling is a whaling phishing attack aimed specifically at senior executives such as CEOs, CFOs, or board members, rather than employees generally. The name plays on the idea that executives represent the largest possible target, or the "whale," in an organization. Whaling attacks typically use more research and a more convincing pretext than a phishing email sent to a broad list.
CEO fraud is a form of business email compromise where an attacker impersonates a chief executive, often by spoofing or compromising their email account, to instruct an employee to wire funds or change payment details. It succeeds by exploiting trust and urgency rather than by breaking into a network, which is why email filters alone rarely stop it.
Standard phishing sends the same message to thousands of people and relies on volume to succeed. Spear phishing executives involves researching one specific person, using details about their deals, travel, or relationships to make the message credible. Spear phishing has much lower volume but a significantly higher success rate against senior, high-value targets.
An executive impersonation scam involves a fraudster posing as a real executive, using a spoofed email, cloned voice, or fabricated video, to convince an employee, vendor, or family member to act. It differs from generic impersonation because the attacker builds the pretext around a real, identifiable person whose authority the target already trusts.
Yes. Voice cloning tools need only a short public sample, such as an earnings call or media interview, to produce a convincing fake. Academic testing has found that people correctly identify AI-cloned voices from commercial tools only around 61 to 66 percent of the time, which is why deepfake executive impersonation is treated as a serious wire fraud risk.
Executive identity theft occurs when an attacker uses a business leader's exposed personal information, such as a Social Security number, home address, or financial account details, to open credit, redirect assets, or bypass identity verification. It often begins with the same research an attacker uses to build a phishing pretext in the first place.
Preventing executive phishing combines phishing-resistant authentication, a verified callback process for any wire or payment change request, and reducing the personal information publicly available about the executive. No single control stops every attempt, which is why a layered approach across email, verification, and personal exposure performs better than any one fix alone.
Fabian Raemy
Fabian Raemy
Editor - Batten Black

Fabian Raemy is the editor of Batten Black, covering cybersecurity, home protection, and emergency preparedness with a research-first approach grounded in real-world risk analysis.

Jake JohnsonReviewed for accuracy by Jake Johnson, Co-Founder & Chief Operating Officer, Batten prior to publication.

Get Started

Your exposure is real, whether you've assessed it or not.

A confidential assessment maps it across every domain and shows you exactly what to do next.

Book a Confidential Assessment