Phishing vs spear phishing vs whaling: what’s the difference?

Ingi fishing from a jetty with a net, a spear and a hook, showing how phishing targets everyone, spear phishing targets you and whaling targets the boss

An email lands from your bank asking you to confirm a payment. Later that morning, your finance manager gets a message that seems to come from you, asking for a supplier to be paid before lunch. You’ve heard the words phishing, spear phishing and whaling, but it isn’t obvious whether they’re different threats or the same one with new names.

Essentially, they’re the same trick aimed at different people. Think of them as three levels of effort: how much the criminal knows about you, and how much they stand to gain if you believe them. Once you can see which one you’re looking at, it’s easier to decide what your team should check before they click, reply or pay.

What is phishing?

Phishing is a message that pretends to come from someone you trust, so you’ll click on a link, open an attachment or hand over information. It’s a form of social engineering, working on people rather than computers. Cybercriminals send the same message to thousands of email addresses and wait for a few recipients to respond. A fake parcel-delivery notice, a Microsoft 365 “your password expires today” warning and a refund offer from HMRC are all common phishing scams. Delivery notices work especially well, our engineers see “your DPD parcel is waiting” style emails among the most commonly delivered, and often the most clicked!

Example parcel delivery phishing email asking for a small redelivery fee, with the fake sender address, generic greeting, deadline and suspicious link highlighted
(1) The sender’s address isn’t the courier’s real website. (2) A generic greeting, not your name. (3) A small fee with a deadline, to rush you. (4) Hovering over the button shows the link goes to an unrelated website.

The aim is usually your login details, personal data or money. A link might open a copy of the Microsoft sign-in page and ask you to enter your password, which goes straight to the cybercriminals behind it. Opening an attachment might download malware (which can sometimes be ransomware that locks every file on your network).

Phishing is the most common of the cyberattacks UK businesses report. In the government’s Cyber Security Breaches Survey 2025/2026, 38% of businesses had experienced a phishing attack in the past 12 months, and 69% of those that had suffered an attack named phishing the most disruptive.

Unfortunately, it doesn’t stop there. By text message it’s called smishing, and by phone it’s voice phishing or vishing. A vishing attack is when someone rings claiming to be from your bank or Microsoft support.

What is spear phishing?

Spear phishing is phishing aimed at a specific individual or group, using details that make the message believable. Instead of “Dear customer”, it uses your name, mentions a supplier you really work with and arrives at a time that makes sense.

The hacker does some research first, known as reconnaissance, using publicly available information. Your website lists your team. LinkedIn and other social media show who joined last month and who works in accounts. Put together, that’s enough to write a message a new starter would have no reason to doubt: “Hi Sam, welcome to the team. Before your first payroll, can you confirm your bank details on the HR portal?”

This makes a targeted attack harder to spot. The usual warning signs, such as a strange greeting or an unfamiliar company, aren’t there. Some spear phishing campaigns even build trust over several messages before asking for anything. The recent attempts our engineers find most convincing are vague ones that mention “the document” or “the attached file”: specific enough to sound plausible, vague enough to fit almost anyone’s week. They work especially well on people who handle documents all day.

Spelling mistakes are no help either, as our post on AI phishing attacks explains; AI tools can now write a convincing, personal message in seconds.

We’ve covered the first two types in more detail in the difference between phishing and spear phishing.

What is whaling?

Whaling is a type of spear phishing aimed at the most senior people in a business: the managing director or chief executive officer, the finance director or CFO, a partner or a trustee. They’re the “big fish” because they can approve large sums of money, sign contracts and reach confidential information without asking anyone else.

A whaling email may look like a solicitor’s letter about a confidential acquisition, a message from your accountant about a tax problem, or a board document that needs signing today. It’s written carefully and plays on things a C-level executive cares about: urgency, secrecy and reputation.

It also works in reverse. Cybercriminals can impersonate the senior person and target someone junior. That version is often called CEO fraud: a message “from the managing director” asks the finance team to pay a new supplier quickly and quietly. The person receiving it may not want to question the boss, and that reluctance is what the scam relies on. In the past six months, our engineers have definitely seen more of these CEO impersonation attempts.

Example CEO fraud email pretending to be from a managing director and asking for an urgent, secret supplier payment
(1) The display name is real but the address isn’t. (2) An urgent payment and a request for secrecy. (3) Pressure to act now.

Phishing vs spear phishing vs whaling: the key differences

Phishing Spear phishing Whaling
Who it targets Anyone with an email address A named person or team Directors, owners and senior staff
How personal it is Generic, sent in bulk Uses your name, role and suppliers Carefully researched, often about a real deal
What the attacker wants Passwords, card details, a malware install Access to a particular account or system Large payments, contracts, sensitive data
A typical example “Your parcel couldn’t be delivered” “Hi Sam, please update your bank details” “Confidential: payment needed to complete the acquisition”
How hard it is to spot Often easy, once you know the signs Harder, because the details are right Hardest, because it looks like normal senior business

The main difference between spear phishing attacks and whaling is who’s on the receiving end. As the target gets narrower, the attacker spends more time on research and asks for more.

Why smaller businesses are targeted too

It’s tempting to think these attacks only happen to large companies. However, in a business of 20 – 30 people, the managing director often approves payments personally, the finance person knows everyone by first name and requests arrive by email because that’s how the team works. A convincing message from the boss is easier to act on, not harder.

Finance teams feel this most. They’re the department our engineers see targeted most often, and also the one most likely to click when something gets through. When you handle invoices and payment requests all day, a fake one fits right in.

Many of these attacks start with gaining access to a real mailbox. If an attacker gets into one person’s Microsoft 365 account through an ordinary phishing attempt, they can read months of genuine conversations. Their next message can reply to a real invoice thread with new bank details, or come from a look-alike supplier address like our example below. This is known as business email compromise (BEC). If you haven’t already – we’d recommend checking the NCSC’s guidance on how to defend against BEC attacks.

Example spear phishing message from a look-alike supplier address asking for an invoice to be paid to new bank details
(1) A look-alike address with a capital I in place of an L. (2) An urgent subject line. (3) New bank details.

These types of attacks are often connected. A mass phishing message gets one set of login details, and the attacker uses that access to plan a whaling attack on the people who can move money. It’s also common for these attempts to land in accounts that technically still exist after someone has left a business, such as a leaver’s mailbox that’s still being forwarded to a colleague. More on that next week.

When do phishing attacks happen?

Timing plays a part too. KnowBe4’s latest Phishing Threat Trends Report found attackers deliberately time their emails for what it calls the “End-of-Day Blur”. Attacks started to climb after lunch, from around 1pm, and peaked at 5pm before tailing off into the evening. That’s when people are tired, clearing the last few emails of the day and less likely to stop and check.

It’s worth remembering for anyone who approves payments. A request that lands at ten to five, asking for something to be sorted “before you go”, deserves the same checks as one that arrives at 10am.

How can you tell which one you’re looking at?

You don’t need to know whether it’s phishing or whaling to deal with it. It’s more useful to ask what it wants you to do, and whether you’d expect that request to arrive this way.

  • Is it asking for money or bank changes? Treat any request to pay someone new, change bank details or pay urgently as fraudulent until you’ve checked it. Think guilty until proven innocent.
  • Is it asking you to sign in? Go to the website or app yourself instead of using the link.
  • Is it asking for secrecy or speed? “Don’t mention this to anyone” and “I need this done in the next hour” are there to stop you checking.
  • Does the sender’s address match? Look at the full address, not just the display name. Our guide to email spoofing explains how addresses are faked.

A well-researched message can pass every one of those checks, especially if it comes from a genuine mailbox. Security software won’t always catch it either. Your team needs a checking process that doesn’t depend on spotting the fake.

What to do if you get a suspicious email

Don’t click any links, open attachments or reply. Then report it! It matters which button you use.

Microsoft’s built-in ‘Report phishing’ button deletes the email and forwards it to Microsoft. Nobody in your business sees it, investigates it or checks who else received it.

If your business has security awareness training, you may have a separate reporting button. For clients on our security awareness training package, that’s the KnowBe4 Phish Alert Button: it creates a support ticket, and an engineer investigates. They check who else received the email, whether it’s already been blocked and whether anyone clicked. Other training providers have their own versions. If you have a button that gets a person looking at the email, use it rather than Microsoft’s own. If you don’t have one, or you’re not sure which to use, check with your IT support team before you do anything else with the email.

What to put in place

Whaling and spear phishing usually end in a payment request, so we always recommend agreeing a payment rule first. Any new payee, any change of bank details and any unusual urgent payment gets confirmed by phone, using a number you already hold, not one from the message. Make it clear that the managing director or whoever can grant sign-off expects to be called back, so nobody feels awkward checking.

Then protect the accounts cybercriminals want to get into:

  • Multi-factor authentication (MFA) on every Microsoft 365 account, so a stolen password isn’t enough on its own. Phishing-resistant methods, such as passkeys, go further because they won’t work on a fake sign-in page.
  • Email security tools and Microsoft 365 settings that flag external senders and look-alike domains before a message reaches the inbox.
  • Identity threat detection and response, which watches for unusual sign-ins so a compromised mailbox is spotted before the attacker starts replying to invoice threads.
  • Security awareness training for everyone, including directors. Directors are the people these attacks go after, so they need it as much as anyone.

Training makes a measurable difference. In KnowBe4’s 2026 benchmarking report, 33.2% of untrained staff fell for a simulated phishing test; after 12 months of regular training, that dropped to 4.2%, a whopping 87% reduction! We test our clients regularly and see the same thing: staff who’ve been through our KnowBe4 training are clearly better at spotting a fake.

Tips from our engineers

  • Stay out of your junk folder. Spam filters used to be unreliable and would sometimes junk genuine emails, so checking the junk folder made sense. That rarely happens now. Our engineers see people checking their junk folders regularly, and every visit is a risk, because that’s where the most harmful emails end up. Their advice is simple: you don’t need to open it, so stay out.
  • A well-run business is still at risk. Before a client started their KnowBe4 training with us, we sent their team a test email. One in four people clicked the link. We see it time and time again, and it’s common for managing directors and senior staff click just as often as everyone else. It goes to show how easily a convincing email catches people out.

How we help

At Ingenio, we help businesses across Brighton, Sussex and the South East reduce the chance of a phishing message turning into a lost payment. Our KnowBe4 training gives your team regular short lessons and simulated phishing messages, with reports showing who might need more support.

Because many of these attacks start with a stolen Microsoft 365 login, our Microsoft 365 identity protection service, powered by Huntress, watches for attackers using stolen passwords, setting up hidden inbox rules or signing in from unexpected places. We’ll also help you set up MFA and agree a payment-checking process that suits the way your team works.

Frequently asked questions

Is whaling the same as phishing?

Whaling is a form of phishing. Ordinary phishing goes to large numbers of people with a generic message; whaling picks out one senior person, such as a managing director, with a carefully researched message designed to get a large payment or sensitive information.

What are the four types of phishing?

People usually mean bulk phishing, spear phishing, whaling, and phishing by text or phone call. Each type of phishing uses the same social engineering techniques: pretending to be someone you trust and creating a reason to act quickly.

What is CEO fraud?

CEO fraud is when a criminal pretends to be a senior person, often the managing director, and asks a colleague to make a payment or send information. It’s closely related to whaling and is a common form of business email compromise.

Should I check my junk folder for phishing?

No. Modern spam filters rarely send genuine emails to junk, so there’s little reason to look. Opening the junk folder puts you in front of the emails most likely to be harmful. If you’re expecting something important that hasn’t arrived, ask your IT team to check for you.

How do I report a phishing email in the UK?

At work, use your business’s reporting button, ideally one that sends it to your IT team, such as the KnowBe4 Phish Alert Button, so someone can check whether anyone else received it. You can also forward suspicious emails to the NCSC’s Suspicious Email Reporting Service at report@phishing.gov.uk. If money has been lost, contact your bank straight away and report it to Action Fraud.

Can training stop spear phishing?

Training makes people more likely to pause and check, but it works best alongside MFA, email filtering and a payment-checking process. A well-researched message can fool anyone, so the process needs to catch what people miss.

Final thought

You don’t need your team to become experts in naming attacks. You need them to pause when a message asks for money, a login or secrecy, and to know that checking is always the right call, even when the request seems to come from the top.

👉 Talk to us about protecting your team from phishing. We’re happy to talk it through.

Sources