Executive Cybercrime

What Is Executive Phishing? How Cybercriminals Target Business Leaders

Written by Fabian RaemyReviewed by Jake JohnsonPublished August 18, 202624 min read
What Is Executive Phishing? How Cybercriminals Target Business Leaders
The Takeaway

Executive phishing uses real details, trusted relationships, and even cloned voices to target business leaders. Learn how whaling, CEO fraud, and deepfake impersonation work, and how executives can reduce their exposure.

Quick Answer

Executive phishing is a targeted phishing attack, such as whaling, spear phishing, or CEO fraud, that impersonates or targets a specific business leader to steal money, credentials, or data. It succeeds by exploiting an executive's public visibility and authority rather than by hacking a system, and in 2025 it drove more than $3 billion in U.S. business email compromise losses alone.

If you are a CEO, founder, CFO, or general counsel, your name is probably already searchable next to your title, your company, and a rough sense of what you are worth to defraud. Attackers do not need to break into anything to get started. A funding announcement, an earnings call, or a LinkedIn post about a new hire is often enough raw material to build a convincing pretext.

Most phishing training was built for a generic employee inbox, not for someone whose calendar, travel, and signing authority are semi-public. This is exactly where executive phishing cybersecurity has to work differently from standard employee training.

A well-timed email that references a real deal, a real board member, or a real family event does not look like the phishing example from last year's compliance video. It looks like an ordinary Tuesday.

This is why executive phishing attacks succeed against people who would never fall for a lottery scam or a fake delivery text. The lure is built specifically for them, often using information they made public themselves, which is what separates whaling and CEO fraud from the phishing everyone else gets trained to spot.

Key Takeaways

  • Business email compromise cost victims more than $3.05 billion in the United States in 2025 across 24,768 complaints, and $30.26 million of that total involved AI-generated content, according to the FBI's Internet Crime Complaint Center.
  • A University of Texas at San Antonio study found that AI-written phishing emails impersonating a supervisor performed as well as those written by communications professionals, and significantly outperformed them in a time-sensitive scenario.
  • Human listeners correctly identify AI-cloned voices from commercial tools only 61 to 66 percent of the time, while an automated detector in the same 2026 study caught synthetic audio more than 94 percent of the time.
  • The FBI has documented attackers mailing physical extortion letters directly to corporate executives, showing that executive phishing now spans channels well beyond email.
  • Batten Black's six-domain assessment treats executive email security as one piece of a wider exposure picture, since the same public information that fuels a whaling email also drives residential and family targeting. Select a date and time to see exactly what's exposed.
$0B
reported U.S. business email compromise losses in 2025
FBI IC3, 2025
0
BEC complaints filed with the FBI in a single year
FBI IC3, 2025
0%
click rate on phishing emails impersonating a supervisor
UTSA / IEEE Access
0%
best-case human accuracy at identifying an AI-cloned voice
Fraunhofer AISEC, 2026

What Is Executive Phishing?

Executive phishing covers several related attack types that all share one trait: they target a specific, named business leader rather than a broad list of employees. Spear phishing executives means researching one person's role, relationships, and recent activity to write a message that gets past their skepticism.

Whaling is the version of spear phishing aimed specifically at the most senior "whale" in an organization, a CEO, CFO, or board member. It uses more research and a more convincing pretext than a typical phishing email.

Business email compromise, or BEC, describes what happens once that trust is established: an attacker impersonates an executive, an attorney, or a vendor to redirect a wire transfer or change payment instructions. CEO fraud and CEO phishing are the common names for this when the impersonated sender is a chief executive.

The FBI logged 24,768 BEC complaints in 2025 with reported losses of $3,046,598,558, making it the second most costly cybercrime category the bureau tracks, behind only investment fraud.

Executive phishing succeeds by exploiting trust and urgency rather than by breaking through a firewall, which is exactly why a strong spam filter alone does not stop it.

Whaling, Spear Phishing, BEC, and CEO Fraud at a Glance

These terms get used interchangeably in most coverage of the topic, but they describe different points in the same attack chain. The table below separates them by who they target and what the attacker is actually after.

Attack Type Who It Targets How It Typically Arrives Primary Goal
Spear Phishing One specific employee or executive A researched, personalized email Steal credentials or sensitive data
Whaling A senior executive specifically (CEO, CFO, board member) An email built around real, public details Steal credentials, data, or authorize a payment
Business Email Compromise (BEC) Finance, HR, or an assistant with payment authority A spoofed or compromised executive or vendor email Redirect a wire transfer or payment
CEO Fraud / CEO Phishing An employee who reports to or trusts the CEO An urgent message appearing to come from the CEO Authorize an unusual or rushed payment
Deepfake Executive Impersonation Anyone on a call or video with the executive A cloned voice or fabricated video Bypass verbal verification for a payment or data request

How Executive Phishing Attacks Exploit Social Engineering and Public Data

Executive phishing attacks follow a predictable pipeline: research, pretext, urgency, and payload. An attacker starts with whatever is already public, a press mention, a conference bio, an assistant's name on a company directory, and uses it to make the next message feel familiar rather than suspicious.

How the Attack Actually Unfolds

Stage 01

Research

The attacker gathers public details, a recent deal, a travel post, an org chart, that make a future message feel informed rather than generic.

Stage 02

Pretext

Those details get built into a plausible reason for contact, often mimicking a real vendor, attorney, or internal process the target already recognizes.

Stage 03

Urgency

The message adds time pressure, a closing deadline, an angry client, a compliance cutoff, designed to short-circuit the target's normal verification habits.

Stage 04

Payload

The actual ask arrives, usually a wire transfer, a credential entry, or a request to open an attachment, timed to when resistance is lowest.

Social engineering attacks work because they borrow trust that already exists instead of trying to manufacture new trust from nothing. A 2025 University of Texas at San Antonio study published through IEEE Access tested this directly, sending AI-generated and human-written phishing emails impersonating a supervisor to thousands of employees.

The supervisor-impersonation emails, the closest real-world equivalent to a whaling phishing attack, produced click rates around 21 percent and got roughly 11 percent of recipients to enter data, regardless of whether a human or an AI wrote the message. When researchers asked people why they engaged, the strongest factor by far was simply that the email came from what looked like an internal, familiar address.

That single finding explains most of what makes executive phishing dangerous: the message does not need to be clever if the sender identity is convincing enough.

Signs of a Targeted Executive Impersonation Scam

  • Unusual urgency from a known sender: A request from a supervisor, attorney, or partner that demands action within minutes, especially outside normal business hours.
  • A request to bypass normal verification: A message asking you to skip a callback confirmation or a second approver "just this once, given the timing."
  • Personal details that feel too specific: References to a real deal, a real trip, or a real family event that were only ever mentioned publicly, never confirmed privately.
  • A slightly off channel: A message arriving through a personal email address, a new phone number, or a different app than the sender normally uses to reach you.
Spot the red flag Fictional example. No real person, company, or transaction is depicted.
From: Marcus Hale <m.hale@northbridge-partners.co>
To: Dana Reyes, Controller
Subject: Re: Cordell closing, wire out today

Dana,

I am in the Cordell diligence session until six and cannot take calls before then. Legal needs the deposit out today or we lose the exclusivity window.

Updated instructions are attached. The escrow agent moved banks last week, so the account on file is stale. Please run it now and skip the second signature just this once. I will approve retroactively first thing tomorrow.

No need to loop in Priya, she is still on the buy-side call and I do not want this held up.

M.

Six things in this message should stop the payment. Select any highlighted phrase to see which one it is and why it works.

Red flag 01
A lookalike sender domain

The real company domain ends in .com. A one-character change is effectively invisible in an inbox preview, where most clients show only the display name. The sender identity was the single strongest driver of engagement in the UTSA study, and this is the cheapest way to fake it.

Red flag 02
The verification channel is closed in advance

A legitimate sender rarely rules out a phone call in the same message that asks for money. This line exists to pre-empt the one step that would expose the fraud, and it is written to sound like a scheduling detail rather than a refusal.

Red flag 03
Manufactured urgency attached to a real deal

The deadline is what compresses judgment. Attackers anchor it to a genuine transaction, often sourced from a press release, a filing, or a LinkedIn post, because a real deal makes a fabricated deadline credible.

Red flag 04
A last-minute change to payment instructions

This is the actual ask. Nearly every business email compromise loss traces back to payment details that changed shortly before a transfer, for a reason that sounded purely administrative at the time.

Red flag 05
An explicit request to bypass a control

"Just this once" is the phrase that should stop a payment every time. Controls exist for exactly this scenario, and executive authority is the tool attackers use to waive them without argument.

Red flag 06
Isolation from a second approver

Removing the one colleague who might ask a question is deliberate, not incidental. An attacker who has read a public org chart already knows who the second set of eyes would have been.

CEO Fraud and CEO Phishing: How Wire Transfer Fraud Happens

CEO fraud and CEO phishing both describe the moment a whaling attempt turns into an actual financial loss, once an attacker's message convinces someone to move money. The FBI's own case files show how ordinary these requests can look right up until the money is gone.

Real Wire Fraud Cases the FBI Has Documented

Property closing
$0M

A senior citizen closing on a property received an email that appeared to come from the title company, containing wire instructions for an account criminals controlled.

FBI case file
Vendor impersonation
$0M

A city government office wired more than six million dollars after receiving fraudulent payment instructions from an impersonated vendor.

FBI case file
Attorney impersonation
$0K

A homebuyer wired the funds after receiving an email that impersonated their own attorneys during the closing process.

FBI case file
Deepfake video call
$0M

A finance employee at a global engineering firm authorized the transfer after a video call with what turned out to be fabricated colleagues.

Arup / Hong Kong Police, 2024

Wire transfer fraud like this works because the request looks routine. It arrives at a moment when a wire transfer was already expected, from a sender whose name the recipient already recognized, asking for something that only feels unusual in hindsight.

The FBI's Recovery Asset Team was able to freeze funds in the cases above only because the incidents were reported within hours, underscoring how narrow the recovery window really is.

Where BEC and Wire Fraud Losses Concentrate

BEC attacks rarely travel alone. The categories below all show up in the same IC3 dataset, and each one supplies either the money lost or the research an attacker used to get there.

Fraud Type 2025 IC3 Complaints 2025 IC3 Reported Losses Relevance to Executive Phishing
Business Email Compromise 24,768 $3,046,598,558 Directly impersonates an executive or assistant to redirect a wire transfer
Real Estate Fraud 12,368 $275,110,419 Frequently targets executives and principals during property closings
Government Impersonation 32,424 $797,943,193 Used in mail-based extortion letters sent directly to corporate executives
Personal Data Breach 67,456 $1,314,923,988 Supplies the research attackers use to build a credible executive pretext
Identity Theft 31,675 $185,832,657 Exploits an executive's exposed personal records to bypass verification
Employment Fraud 24,688 $362,934,762 Used to harvest internal org-chart and assistant contact details

Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report

A companion piece breaks down how these same fraud categories fit into the broader picture facing wealthy households, in The Real Security Risks Facing High-Net-Worth Individuals.

AI Phishing Attacks and Deepfake Executive Impersonation

AI phishing attacks have moved from a theoretical risk to a line item in federal crime statistics. The FBI attributed $893 million in 2025 losses to AI-related fraud, including $30.26 million specifically tied to AI-enabled business email compromise.

Voice cloning is the sharpest edge of this trend: deepfake executive impersonation has already been used to convince a finance employee at a global engineering firm to wire $25 million after a video call with what turned out to be fabricated colleagues.

How Well Can People Actually Detect a Cloned Voice?

Accuracy at identifying synthetic speech
Human listeners, commercial voice cloning tools
66%
Automated detector, same test set
94%

Human accuracy ranged from 61 to 66 percent depending on the synthesis tool. The upper bound is shown here. Fraunhofer AISEC, 2026.

Detecting these fakes is genuinely difficult, not just for untrained employees. A 2026 study from Fraunhofer AISEC, the largest audio deepfake perception study conducted to date, found that people correctly identify cloned voices from commercial synthesis tools only 61 to 66 percent of the time. An automated detector maintained accuracy above 94 percent across the same test set.

A separate University College London study published in PLOS ONE found nearly identical results years earlier, at 73 percent human accuracy, and documented a real 2019 case in which fraudsters used a cloned executive voice to redirect a €220,000 wire transfer.

Deepfake executive impersonation does not need to be perfect. It only needs to be good enough to survive a few seconds of doubt during a busy afternoon.

If any of this sounds like exposure you already recognize, Book a Confidential Assessment to see exactly what's public about you right now, before someone else uses it.

Why Deepfake Impersonation Fools Even Careful Executives

  • Voice cloning needs very little source audio: A few seconds of a public speech, earnings call, or interview is enough to train a convincing clone.
  • Commercial tools produce the hardest fakes to catch: Fakes generated by accessible, commercial voice APIs were the single hardest category for human listeners to correctly identify.
  • Growing skepticism cuts both ways: The same 2026 research found people are now more likely to wrongly doubt a real recording, a dynamic attackers can exploit by claiming a genuine call was staged.
  • Video adds a second layer of trust: A face on a call reduces suspicion even when something about the voice alone might otherwise raise a flag.

Executive Email Security vs. Standard Corporate Protection

Executive email security is not the same problem as company-wide spam filtering, even though most organizations budget for it as if it were. Standard corporate tools are tuned to catch high-volume, generic phishing. They were never designed to flag a single, well-researched message written for one specific person, using details a generic filter has no way to recognize as risky.

Protection Layer Standard Corporate Email Security Consumer Security Tools Coordinated Executive Advisory
Email filtering and spam detection Catches high-volume phishing Limited or none Included, with review of executive-specific rules
Executive's personal devices and accounts Rarely covered Partial, user-managed Assessed as part of a full exposure review
Family member exposure Not covered Not covered Assessed and addressed directly
Wire transfer verification protocol Sometimes, IT-defined Not applicable Built and tested with the client
Data broker and public record monitoring Not covered Point-solution subscription only Coordinated removal and ongoing monitoring
Incident response after a targeted attempt IT help desk queue Self-directed One advisor coordinates the full response

Where This Coordination Gap Actually Costs Executives

Executive cybersecurity has to close the gap this table shows: the layer that catches spam and the layer that catches a targeted whaling attempt are not the same layer, no matter how good the first one is. This is the same gap addressed in more detail on the page covering executive and founder security advisory, which maps out how exposure changes once a leader's profile becomes public.

Batten Black exists for exactly this gap. Standard corporate email security was built to catch spam at scale, not a single, carefully researched message aimed at one executive.

The six-domain assessment

Email security is one domain. A whaling attempt draws on all six.

6Domains
Domain 01
Digital and Account Security

Devices, personal email, accounts, and communications. This is where a whaling email lands and where a harvested credential gets used. Personal email is the most common entry point to financial accounts and private correspondence, and it is almost never covered by a corporate security program.

Domain 02
Privacy and Data Exposure

Public records, data brokers, and location visibility. This is the raw material stage of the attack pipeline. Reducing what a broker publishes about an executive removes the specific detail that makes a pretext feel informed rather than generic.

Domain 03
Identity and Financial Risk

Identity exposure, credit, and wire fraud protections. This is where a successful CEO fraud attempt turns into a loss. Callback verification, second-approver thresholds, and payment change controls all live here, alongside the identity records attackers use to bypass verification.

Domain 04
Residential and Property Security

Access control, smart home networks, and perimeter. A home address recovered from a property record does double duty: it makes a phishing pretext more convincing and it makes a physical approach possible. The same exposure feeds both.

Domain 05
Travel and Mobility Risk

Pre-travel exposure, destination intelligence, and pattern risk. Conference appearances and travel posts tell an attacker exactly when an executive will be unreachable by phone, which is the window most urgent wire requests are timed to.

Domain 06
Family and Lifestyle Risk

Family visibility, household staff, and routine exposure. A spouse's public post or a household employee's social account often supplies the personal detail that makes an impersonation land, and family members are increasingly the direct target of cloned-voice calls.

Batten Black's six-domain assessment reviews executive email security alongside the personal exposure, family details, and public records that make a whaling attempt or a deepfake call convincing in the first place. One named advisor coordinates the response so a targeted attempt gets caught before it becomes a wire transfer.

Confidential assessment

See exactly what an attacker could already piece together about you.

One advisor, one review across all six domains, and a prioritized plan for closing what's open. Before someone else finds it first.

Book a Confidential Assessment Discreet. No obligation. Initial findings typically delivered within two weeks.

Executive Cybersecurity: How to Prevent Executive Phishing Before It Costs You

Preventing executive phishing starts by assuming any single email, call, or video request could be fabricated, no matter how convincing the sender sounds. No single control catches everything, which is why the strongest defenses stack several layers rather than relying on one.

Close the Credential and Wire Transfer Gaps

Phishing-resistant multi-factor authentication, the kind built on hardware keys rather than text message codes, closes off the credential-harvesting path that most spear phishing depends on. It will not stop a wire transfer request on its own, though, which is why a separate verification protocol for payments matters just as much.

2020 reported
$1.2B
2025 reported
$0B
+192%

Imposter scam losses reported to the Federal Trade Commission, nearly three times the 2020 total, with business impersonation among the fastest-growing categories.

A callback verification protocol means any request to move money or change payment details gets confirmed through a phone number already on file, never one supplied inside the message itself. The FTC recorded more than $3.5 billion in imposter scam losses in 2025, nearly three times what was reported in 2020, with business impersonation among the fastest-growing categories in that total. A verified callback catches most of this fraud before a wire ever leaves the building.

What a Callback Verification Protocol Should Include

Four controls, in order
01

An independently sourced phone number

Call a number already on file or saved in a verified directory, never one included in the request itself. The number inside the message is part of the attack.

02

A second approver for unusual requests

Any payment change or first-time wire above a set threshold requires sign-off from a person who was not part of the original request.

03

A short, documented pause

Build in a brief delay before releasing funds, long enough for a second person to sanity-check the request against normal patterns.

04

A clear escalation path

Make sure every employee who touches payments knows exactly who to call if something feels slightly off, without fear of slowing down a legitimate deal.

Reduce What's Public Before an Attacker Finds It

The other half of prevention happens before an email ever arrives. Reducing what a data broker or a casual search reveals about an executive's home address, travel patterns, and family removes the raw material attackers use to build a credible pretext in the first place, the same OSINT reduction work covered under doxxing protection.

A coordinated review across all six protection domains, outlined in this process breakdown, is what closes the remaining gap between a strong email filter and an executive whose calendar, home address, and family are still fully public.

A Layered Defense, at a Glance

Control What It Stops Where It Lives
Phishing-resistant MFA (hardware keys) Credential harvesting from a spoofed login page Executive's personal and work accounts
Callback verification protocol A fraudulent wire or payment change request Finance and executive assistant workflows
OSINT and data broker reduction The research attackers use to build a pretext Public records, data brokers, social media
Six-domain coordinated review Gaps between digital, financial, and residential exposure One advisor across all six domains

Conclusion: Why Batten Black Is Built to Stop Executive Phishing

Executive phishing works because it is built around one person's real life, not a generic template a spam filter can flag. A whaling email, a CEO fraud wire request, and a cloned voice on a call all rely on the same raw material: an executive's public visibility, routines, and relationships.

Standard IT security stops the phishing everyone else receives. It was never built to catch the one message written specifically for you.

Batten Black closes that gap by treating executive email security as one piece of a coordinated, six-domain assessment rather than an isolated IT problem. One advisor reviews wire transfer protocols, reduces the public data that makes impersonation convincing, and coordinates the response if a targeted attempt gets through.

Two-minute exposure check

How much of a pretext could someone build from what's already public?

Select every statement that is true today. Nothing is recorded or transmitted.

0 of 6 selected

Work through the list above. Most executives find at least three apply once they actually check rather than assume.

If your role, visibility, or signing authority has grown recently, a confidential assessment shows exactly where you stand today.

Book a Confidential Assessment Discreet. No obligation. Initial findings typically delivered within two weeks.

Frequently Asked Questions About Executive Phishing

These are the questions specific to executive phishing. For broader questions about how an engagement works, see the Client FAQ.

What is whaling in cybersecurity?

Whaling is a whaling phishing attack aimed specifically at senior executives such as CEOs, CFOs, or board members, rather than employees generally. The name plays on the idea that executives represent the largest possible target, or the "whale," in an organization. Whaling attacks typically use more research and a more convincing pretext than a phishing email sent to a broad list.

What is CEO fraud and how does it work?

CEO fraud is a form of business email compromise where an attacker impersonates a chief executive, often by spoofing or compromising their email account, to instruct an employee to wire funds or change payment details. It succeeds by exploiting trust and urgency rather than by breaking into a network, which is why email filters alone rarely stop it.

How is spear phishing different from standard phishing attacks targeting executives?

Standard phishing sends the same message to thousands of people and relies on volume to succeed. Spear phishing executives involves researching one specific person, using details about their deals, travel, or relationships to make the message credible. Spear phishing has much lower volume but a significantly higher success rate against senior, high-value targets.

What is an executive impersonation scam?

An executive impersonation scam involves a fraudster posing as a real executive, using a spoofed email, cloned voice, or fabricated video, to convince an employee, vendor, or family member to act. It differs from generic impersonation because the attacker builds the pretext around a real, identifiable person whose authority the target already trusts.

Can AI really clone an executive's voice for fraud?

Yes. Voice cloning tools need only a short public sample, such as an earnings call or media interview, to produce a convincing fake. Academic testing has found that people correctly identify AI-cloned voices from commercial tools only around 61 to 66 percent of the time, which is why deepfake executive impersonation is treated as a serious wire fraud risk.

What is executive identity theft?

Executive identity theft occurs when an attacker uses a business leader's exposed personal information, such as a Social Security number, home address, or financial account details, to open credit, redirect assets, or bypass identity verification. It often begins with the same research an attacker uses to build a phishing pretext in the first place.

How can executives prevent phishing and business email compromise?

Preventing executive phishing combines phishing-resistant authentication, a verified callback process for any wire or payment change request, and reducing the personal information publicly available about the executive. No single control stops every attempt, which is why a layered approach across email, verification, and personal exposure performs better than any one fix alone.

Sources

  • FBI Internet Crime Complaint Center: "2025 Internet Crime Report" - ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  • FBI Internet Crime Complaint Center: "Mail Scam Targeting Corporate Executives Claims Ties to Ransomware" - ic3.gov/psa/2025/psa250306-2
  • Federal Trade Commission: "FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025" - ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025
  • University of Texas at San Antonio (IEEE Access): "Lateral Phishing with Large Language Models: A Large Organization Comparative Study" - arxiv.org/pdf/2401.09727
  • Fraunhofer AISEC: "Eroding Trust in Real Speech: A Large-Scale Study of Human Audio Deepfake Perception" - arxiv.org/html/2605.26136
  • University College London (PLOS ONE): "Warning: Humans Cannot Reliably Detect Speech Deepfakes" - journals.plos.org/plosone/article?id=10.1371/journal.pone.0285333

Related

Fabian Raemy
Fabian Raemy
Editor - Batten Black

Fabian Raemy is the editor of Batten Black, covering cybersecurity, home protection, and emergency preparedness with a research-first approach grounded in real-world risk analysis.

Jake JohnsonReviewed for accuracy by Jake Johnson, Co-Founder & Chief Operating Officer, Batten prior to publication.

Get Started

Your exposure is real, whether you've assessed it or not.

A confidential assessment maps it across every domain and shows you exactly what to do next.

Book a Confidential Assessment