If you are a CEO, founder, CFO, or general counsel, your name is probably already searchable next to your title, your company, and a rough sense of what you are worth to defraud. Attackers do not need to break into anything to get started. A funding announcement, an earnings call, or a LinkedIn post about a new hire is often enough raw material to build a convincing pretext.
Most phishing training was built for a generic employee inbox, not for someone whose calendar, travel, and signing authority are semi-public. This is exactly where executive phishing cybersecurity has to work differently from standard employee training.
A well-timed email that references a real deal, a real board member, or a real family event does not look like the phishing example from last year's compliance video. It looks like an ordinary Tuesday.
This is why executive phishing attacks succeed against people who would never fall for a lottery scam or a fake delivery text. The lure is built specifically for them, often using information they made public themselves, which is what separates whaling and CEO fraud from the phishing everyone else gets trained to spot.
Key Takeaways
- Business email compromise cost victims more than $3.05 billion in the United States in 2025 across 24,768 complaints, and $30.26 million of that total involved AI-generated content, according to the FBI's Internet Crime Complaint Center.
- A University of Texas at San Antonio study found that AI-written phishing emails impersonating a supervisor performed as well as those written by communications professionals, and significantly outperformed them in a time-sensitive scenario.
- Human listeners correctly identify AI-cloned voices from commercial tools only 61 to 66 percent of the time, while an automated detector in the same 2026 study caught synthetic audio more than 94 percent of the time.
- The FBI has documented attackers mailing physical extortion letters directly to corporate executives, showing that executive phishing now spans channels well beyond email.
- Batten Black's six-domain assessment treats executive email security as one piece of a wider exposure picture, since the same public information that fuels a whaling email also drives residential and family targeting. Select a date and time to see exactly what's exposed.
What Is Executive Phishing?
Executive phishing covers several related attack types that all share one trait: they target a specific, named business leader rather than a broad list of employees. Spear phishing executives means researching one person's role, relationships, and recent activity to write a message that gets past their skepticism.
Whaling is the version of spear phishing aimed specifically at the most senior "whale" in an organization, a CEO, CFO, or board member. It uses more research and a more convincing pretext than a typical phishing email.
Business email compromise, or BEC, describes what happens once that trust is established: an attacker impersonates an executive, an attorney, or a vendor to redirect a wire transfer or change payment instructions. CEO fraud and CEO phishing are the common names for this when the impersonated sender is a chief executive.
The FBI logged 24,768 BEC complaints in 2025 with reported losses of $3,046,598,558, making it the second most costly cybercrime category the bureau tracks, behind only investment fraud.
Executive phishing succeeds by exploiting trust and urgency rather than by breaking through a firewall, which is exactly why a strong spam filter alone does not stop it.
Whaling, Spear Phishing, BEC, and CEO Fraud at a Glance
These terms get used interchangeably in most coverage of the topic, but they describe different points in the same attack chain. The table below separates them by who they target and what the attacker is actually after.
| Attack Type | Who It Targets | How It Typically Arrives | Primary Goal |
|---|---|---|---|
| Spear Phishing | One specific employee or executive | A researched, personalized email | Steal credentials or sensitive data |
| Whaling | A senior executive specifically (CEO, CFO, board member) | An email built around real, public details | Steal credentials, data, or authorize a payment |
| Business Email Compromise (BEC) | Finance, HR, or an assistant with payment authority | A spoofed or compromised executive or vendor email | Redirect a wire transfer or payment |
| CEO Fraud / CEO Phishing | An employee who reports to or trusts the CEO | An urgent message appearing to come from the CEO | Authorize an unusual or rushed payment |
| Deepfake Executive Impersonation | Anyone on a call or video with the executive | A cloned voice or fabricated video | Bypass verbal verification for a payment or data request |
How Executive Phishing Attacks Exploit Social Engineering and Public Data
Executive phishing attacks follow a predictable pipeline: research, pretext, urgency, and payload. An attacker starts with whatever is already public, a press mention, a conference bio, an assistant's name on a company directory, and uses it to make the next message feel familiar rather than suspicious.
How the Attack Actually Unfolds
Social engineering attacks work because they borrow trust that already exists instead of trying to manufacture new trust from nothing. A 2025 University of Texas at San Antonio study published through IEEE Access tested this directly, sending AI-generated and human-written phishing emails impersonating a supervisor to thousands of employees.
The supervisor-impersonation emails, the closest real-world equivalent to a whaling phishing attack, produced click rates around 21 percent and got roughly 11 percent of recipients to enter data, regardless of whether a human or an AI wrote the message. When researchers asked people why they engaged, the strongest factor by far was simply that the email came from what looked like an internal, familiar address.
That single finding explains most of what makes executive phishing dangerous: the message does not need to be clever if the sender identity is convincing enough.
Signs of a Targeted Executive Impersonation Scam
- Unusual urgency from a known sender: A request from a supervisor, attorney, or partner that demands action within minutes, especially outside normal business hours.
- A request to bypass normal verification: A message asking you to skip a callback confirmation or a second approver "just this once, given the timing."
- Personal details that feel too specific: References to a real deal, a real trip, or a real family event that were only ever mentioned publicly, never confirmed privately.
- A slightly off channel: A message arriving through a personal email address, a new phone number, or a different app than the sender normally uses to reach you.
CEO Fraud and CEO Phishing: How Wire Transfer Fraud Happens
CEO fraud and CEO phishing both describe the moment a whaling attempt turns into an actual financial loss, once an attacker's message convinces someone to move money. The FBI's own case files show how ordinary these requests can look right up until the money is gone.
Real Wire Fraud Cases the FBI Has Documented
Wire transfer fraud like this works because the request looks routine. It arrives at a moment when a wire transfer was already expected, from a sender whose name the recipient already recognized, asking for something that only feels unusual in hindsight.
The FBI's Recovery Asset Team was able to freeze funds in the cases above only because the incidents were reported within hours, underscoring how narrow the recovery window really is.
Where BEC and Wire Fraud Losses Concentrate
BEC attacks rarely travel alone. The categories below all show up in the same IC3 dataset, and each one supplies either the money lost or the research an attacker used to get there.
| Fraud Type | 2025 IC3 Complaints | 2025 IC3 Reported Losses | Relevance to Executive Phishing |
|---|---|---|---|
| Business Email Compromise | 24,768 | $3,046,598,558 | Directly impersonates an executive or assistant to redirect a wire transfer |
| Real Estate Fraud | 12,368 | $275,110,419 | Frequently targets executives and principals during property closings |
| Government Impersonation | 32,424 | $797,943,193 | Used in mail-based extortion letters sent directly to corporate executives |
| Personal Data Breach | 67,456 | $1,314,923,988 | Supplies the research attackers use to build a credible executive pretext |
| Identity Theft | 31,675 | $185,832,657 | Exploits an executive's exposed personal records to bypass verification |
| Employment Fraud | 24,688 | $362,934,762 | Used to harvest internal org-chart and assistant contact details |
Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report
A companion piece breaks down how these same fraud categories fit into the broader picture facing wealthy households, in The Real Security Risks Facing High-Net-Worth Individuals.
AI Phishing Attacks and Deepfake Executive Impersonation
AI phishing attacks have moved from a theoretical risk to a line item in federal crime statistics. The FBI attributed $893 million in 2025 losses to AI-related fraud, including $30.26 million specifically tied to AI-enabled business email compromise.
Voice cloning is the sharpest edge of this trend: deepfake executive impersonation has already been used to convince a finance employee at a global engineering firm to wire $25 million after a video call with what turned out to be fabricated colleagues.
How Well Can People Actually Detect a Cloned Voice?
Detecting these fakes is genuinely difficult, not just for untrained employees. A 2026 study from Fraunhofer AISEC, the largest audio deepfake perception study conducted to date, found that people correctly identify cloned voices from commercial synthesis tools only 61 to 66 percent of the time. An automated detector maintained accuracy above 94 percent across the same test set.
A separate University College London study published in PLOS ONE found nearly identical results years earlier, at 73 percent human accuracy, and documented a real 2019 case in which fraudsters used a cloned executive voice to redirect a €220,000 wire transfer.
Deepfake executive impersonation does not need to be perfect. It only needs to be good enough to survive a few seconds of doubt during a busy afternoon.
If any of this sounds like exposure you already recognize, Book a Confidential Assessment to see exactly what's public about you right now, before someone else uses it.
Why Deepfake Impersonation Fools Even Careful Executives
- Voice cloning needs very little source audio: A few seconds of a public speech, earnings call, or interview is enough to train a convincing clone.
- Commercial tools produce the hardest fakes to catch: Fakes generated by accessible, commercial voice APIs were the single hardest category for human listeners to correctly identify.
- Growing skepticism cuts both ways: The same 2026 research found people are now more likely to wrongly doubt a real recording, a dynamic attackers can exploit by claiming a genuine call was staged.
- Video adds a second layer of trust: A face on a call reduces suspicion even when something about the voice alone might otherwise raise a flag.
Executive Email Security vs. Standard Corporate Protection
Executive email security is not the same problem as company-wide spam filtering, even though most organizations budget for it as if it were. Standard corporate tools are tuned to catch high-volume, generic phishing. They were never designed to flag a single, well-researched message written for one specific person, using details a generic filter has no way to recognize as risky.
| Protection Layer | Standard Corporate Email Security | Consumer Security Tools | Coordinated Executive Advisory |
|---|---|---|---|
| Email filtering and spam detection | Catches high-volume phishing | Limited or none | Included, with review of executive-specific rules |
| Executive's personal devices and accounts | Rarely covered | Partial, user-managed | Assessed as part of a full exposure review |
| Family member exposure | Not covered | Not covered | Assessed and addressed directly |
| Wire transfer verification protocol | Sometimes, IT-defined | Not applicable | Built and tested with the client |
| Data broker and public record monitoring | Not covered | Point-solution subscription only | Coordinated removal and ongoing monitoring |
| Incident response after a targeted attempt | IT help desk queue | Self-directed | One advisor coordinates the full response |
Where This Coordination Gap Actually Costs Executives
Executive cybersecurity has to close the gap this table shows: the layer that catches spam and the layer that catches a targeted whaling attempt are not the same layer, no matter how good the first one is. This is the same gap addressed in more detail on the page covering executive and founder security advisory, which maps out how exposure changes once a leader's profile becomes public.
Batten Black exists for exactly this gap. Standard corporate email security was built to catch spam at scale, not a single, carefully researched message aimed at one executive.
Batten Black's six-domain assessment reviews executive email security alongside the personal exposure, family details, and public records that make a whaling attempt or a deepfake call convincing in the first place. One named advisor coordinates the response so a targeted attempt gets caught before it becomes a wire transfer.
Executive Cybersecurity: How to Prevent Executive Phishing Before It Costs You
Preventing executive phishing starts by assuming any single email, call, or video request could be fabricated, no matter how convincing the sender sounds. No single control catches everything, which is why the strongest defenses stack several layers rather than relying on one.
Close the Credential and Wire Transfer Gaps
Phishing-resistant multi-factor authentication, the kind built on hardware keys rather than text message codes, closes off the credential-harvesting path that most spear phishing depends on. It will not stop a wire transfer request on its own, though, which is why a separate verification protocol for payments matters just as much.
A callback verification protocol means any request to move money or change payment details gets confirmed through a phone number already on file, never one supplied inside the message itself. The FTC recorded more than $3.5 billion in imposter scam losses in 2025, nearly three times what was reported in 2020, with business impersonation among the fastest-growing categories in that total. A verified callback catches most of this fraud before a wire ever leaves the building.
What a Callback Verification Protocol Should Include
Reduce What's Public Before an Attacker Finds It
The other half of prevention happens before an email ever arrives. Reducing what a data broker or a casual search reveals about an executive's home address, travel patterns, and family removes the raw material attackers use to build a credible pretext in the first place, the same OSINT reduction work covered under doxxing protection.
A coordinated review across all six protection domains, outlined in this process breakdown, is what closes the remaining gap between a strong email filter and an executive whose calendar, home address, and family are still fully public.
A Layered Defense, at a Glance
| Control | What It Stops | Where It Lives |
|---|---|---|
| Phishing-resistant MFA (hardware keys) | Credential harvesting from a spoofed login page | Executive's personal and work accounts |
| Callback verification protocol | A fraudulent wire or payment change request | Finance and executive assistant workflows |
| OSINT and data broker reduction | The research attackers use to build a pretext | Public records, data brokers, social media |
| Six-domain coordinated review | Gaps between digital, financial, and residential exposure | One advisor across all six domains |
Conclusion: Why Batten Black Is Built to Stop Executive Phishing
Executive phishing works because it is built around one person's real life, not a generic template a spam filter can flag. A whaling email, a CEO fraud wire request, and a cloned voice on a call all rely on the same raw material: an executive's public visibility, routines, and relationships.
Standard IT security stops the phishing everyone else receives. It was never built to catch the one message written specifically for you.
Batten Black closes that gap by treating executive email security as one piece of a coordinated, six-domain assessment rather than an isolated IT problem. One advisor reviews wire transfer protocols, reduces the public data that makes impersonation convincing, and coordinates the response if a targeted attempt gets through.
If your role, visibility, or signing authority has grown recently, a confidential assessment shows exactly where you stand today.
Book a Confidential Assessment Discreet. No obligation. Initial findings typically delivered within two weeks.
Frequently Asked Questions About Executive Phishing
These are the questions specific to executive phishing. For broader questions about how an engagement works, see the Client FAQ.
Sources
- FBI Internet Crime Complaint Center: "2025 Internet Crime Report" - ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- FBI Internet Crime Complaint Center: "Mail Scam Targeting Corporate Executives Claims Ties to Ransomware" - ic3.gov/psa/2025/psa250306-2
- Federal Trade Commission: "FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025" - ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025
- University of Texas at San Antonio (IEEE Access): "Lateral Phishing with Large Language Models: A Large Organization Comparative Study" - arxiv.org/pdf/2401.09727
- Fraunhofer AISEC: "Eroding Trust in Real Speech: A Large-Scale Study of Human Audio Deepfake Perception" - arxiv.org/html/2605.26136
- University College London (PLOS ONE): "Warning: Humans Cannot Reliably Detect Speech Deepfakes" - journals.plos.org/plosone/article?id=10.1371/journal.pone.0285333
Related
- The Real Security Risks Facing High-Net-Worth Individuals: the companion piece mapping data broker exposure and wire fraud to the six-domain response.
- The Six Domains of Protection for High-Net-Worth Individuals: the full breakdown of the assessment framework referenced throughout this piece.
- Executive & Founder Security Advisory: how exposure changes the moment a liquidity event or public profile increase hits.
- Our Process: how the six-domain assessment and remediation engagement actually works.

