The email lands at 4:42 on a Friday. It is from the owner. The display name is right. The signature block is right, down to the mobile number and the disclaimer nobody reads. The tone is right, because it is short and clipped, which is how he writes when he is between things.
It says: “Are you at your desk? Need you to handle something before end of day. Quietly for now.”
No link. No attachment. No payload, nothing for a security product to detonate. Nothing is technically wrong with that email at all. That is not a gap in the attack. That is the attack.
I have spent more than 25 years in network security and the last 15 running a managed services practice in Central Florida. The incident that consistently costs the most, moves fastest, and leaves people feeling worst about themselves is this one: someone put on the owner’s face and asked a loyal employee to move money.
What follows is that attack stage by stage, using federal reporting data rather than vendor surveys. If you are the owner, read it and forward it. If it was forwarded to you because you touch invoices, payroll, or the bank portal, the most important sentence here is the one your boss needs to say out loud.
Whaling, spear phishing, and BEC: sorting out the terms
These words get used interchangeably in marketing copy. The practical distinction:
- Phishing is bulk and indiscriminate. A hundred thousand copies of one message, hoping a fraction click.
- Spear phishing is targeted at a researched individual. Low volume, far higher hit rate. We covered the difference in detail in Spear Phishing vs Regular Phishing: Why the Targeted Version Gets Through.
- A whaling phishing attack is spear phishing where a senior executive is either the target or the costume. At small and midsize companies the executive is far more often the costume, because impersonating the owner is cheaper than compromising him and works just as well.
- Business email compromise (BEC) is the FBI umbrella category covering all of it.
The attacker does not care which label you use. Your insurance carrier will, so know that when the money is gone, the word on the FBI complaint form is “BEC.”
What the federal data actually says
I will not use the vendor statistics that float around this topic. From the FBI Internet Crime Complaint Center 2025 Internet Crime Report:
| Year | BEC complaints | Reported BEC losses |
|---|---|---|
| 2023 | 21,489 | $2,946,830,270 |
| 2024 | 21,442 | $2,770,151,146 |
| 2025 | 24,768 | $3,046,598,558 |
BEC was the second largest loss category in the report, behind only investment fraud, and complaint volume rose about 16 percent year over year. Dividing the FBI numbers, the average reported BEC loss works out to roughly $123,000.
Read that average carefully. IC3 data is voluntary and self-reported, and businesses that quietly eat a loss never appear in it. It is not a prediction of what a whaling attack would cost your 30 person firm. Use it for direction and scale, not forecasting.
This is a wire and ACH crime, not a crypto crime. Of 24,768 BEC complaints, only 1,526 had any cryptocurrency nexus, under 3 percent of losses. The FBI transaction breakdown puts BEC overwhelmingly in one channel, wire and ACH, at 86 percent. That is relatively good news: wires and ACH run through regulated institutions with recall procedures. Cryptocurrency does not.
And here is the number every owner should remember. The IC3 Recovery Asset Team initiated 3,900 Financial Fraud Kill Chain actions in 2025 against $1,163,919,846 in attempted theft and froze $679,013,183 of it, a 58 percent success rate. Money wired out the door is not automatically gone. It is gone if nobody moves fast enough.
Locally, Florida ranked third nationally in both IC3 complaint volume (71,843) and reported losses ($1,596,138,595).
Anatomy of a whaling attempt
This is the sequence as I have watched it play out, consistent with what the FBI describes in its BEC advisories. It is slower than most people expect.
Stage 1: Reconnaissance
Days, and in the account-compromise version months. Nothing is being hacked yet. The attacker is reading. Your team page names the owner and the office manager. LinkedIn shows who joined recently and is least likely to push back. Florida corporate filings are public and free. Your out-of-office reply says you are gone until Tuesday and who to contact.
The FBI guidance here is blunt and almost nobody follows it: be careful what is posted to social media and company websites, especially job duties, hierarchy, and out of office details.
Stage 2: Picking the costume
Path A, the lookalike. A domain that reads correctly at a glance: an inserted hyphen, a swapped letter, “rn” standing in for “m”. Cheaper still, they register nothing, open free webmail and set the display name to the owner’s name. On a phone, mail apps show the display name and hide the address behind a tap.
Path B, the real mailbox. The attacker phishes credentials or steals a session token and signs in to the actual Microsoft 365 account. There is no lookalike to spot. The message passes SPF, DKIM, and DMARC because it is legitimate, sits in the real thread, and quotes real history. This version produces the large losses.
If you take one detection tip from this article, take this one. In Path B the attacker almost always creates a mailbox rule that moves messages containing “wire,” “invoice,” or the bookkeeper’s name into RSS Subscriptions or Archive and marks them read, so the owner never sees the conversation held in his name from his own inbox. Go check the inbox rules on your executive mailboxes. It takes ninety seconds and I have found live ones doing exactly this.
Stage 3: The opener
The first message is deliberately low stakes and contains nothing to scan. “Are you at your desk?” “Do you have a minute? Heading into a meeting.” No link, no attachment, no request. Its only job is to get a reply, which proves the target is live, willing to respond to the boss, and now inside a thread. Everything after inherits the legitimacy of that first exchange, including in the target’s own memory. Asked later how they knew it was really the owner, the honest answer is usually “because we had already been talking.”
Stage 4: Taking control of the channel
Next the attacker closes the routes that would expose them, with a reason conversation is impossible: in a closing, on a plane, in surgery. Do not call, just reply here. Often they escalate to text, which feels personal and sits entirely outside your email security stack. “It is Jason, new cell, old phone died.” The FBI has noted these numbers are typically VOIP and often active only briefly.
Stage 5: The ask
The request, in rough order of how often I see each:
- Vendor banking change. “We have moved banks, please update our remittance details.” Biggest losses, because it hides inside a payment you were already going to make.
- Payroll direct deposit change. Aimed at HR rather than accounting. Individually small, which is why it goes unnoticed, and it repeats.
- Gift cards. Crude, aimed at junior staff, still working because the amounts are low enough nobody verifies.
- W-2s or an employee roster. No money moves today. The FBI is explicit that the scam is not always a funds-transfer request. This one sets up tax fraud against your staff next filing season.
Stage 6: Pressure plus secrecy
This is the combination that should trip the wire. Urgency alone is not suspicious, because real business is urgent constantly. Confidentiality alone is not either. What is not normal in any healthy company is a request that is urgent AND arrives with a reason you must not confirm it with anyone else. “Do not loop in accounting yet.” “Keep this between us until it is announced.”
The FBI says it in one line: be suspicious of requests for secrecy or pressure to take action quickly. I go further and treat that combination as disqualifying on its own, whatever the story and whoever the name on it.
Stage 7: The money moves
Funds land in a mule account, frequently held by a real person who is themselves being defrauded. Then comes the second hop, often international, and the window closes.
The 2025 IC3 report shows why reporting matters. In March 2025 a Missouri homebuyer wired over $1.3 million to what appeared to be the title company, and the Recovery Asset Team froze the receiving account. In April an Oregon city government reported a $6 million BEC loss headed to that same account. Because of the earlier freeze, the receiving bank flagged the wire and the full $6 million was recalled. Somebody else filing a complaint is why that city got its money back.
What these messages actually look like
People expect a scam to look like a scam. These do not:
- “Quick question. What is our current wire cutoff time with the bank?”
- “Our bank flagged the last transfer so we have switched institutions. Updated W-9 and remittance attached.”
- “I need you to process a payment for an acquisition we are closing. Confidential, not to be discussed internally until the announcement.”
Notice what is missing. No misspellings. No broken grammar. No “Dear Valued Employee.” No link to hover over. The detection advice most of us were taught fifteen years ago is useless against all three.
Why your email filter did not catch it
This is the first question every owner asks, usually some version of “what are we paying for?”
- There is no payload. Filters are good at malicious attachments and known-bad URLs. A plain text question about your wire cutoff contains neither.
- The domain is clean. A domain registered eleven days ago has no bad reputation because it has never done anything. In Path B the domain is not merely clean, it is yours.
- DMARC does not solve this. I configure SPF, DKIM, and DMARC for every client, as described in How to Stop Someone From Sending Email in Your Company’s Name. But be clear what it does: it stops others being fooled by mail forged to look like your domain. It does nothing about a lookalike domain, a display name spoof from free webmail, or a compromised mailbox.
- Impersonation protection depends on your license. Per Microsoft documentation, impersonation settings (user impersonation, domain impersonation, mailbox intelligence) live in Microsoft Defender for Office 365, not base Exchange Online Protection. On Business Basic or Standard you do not have them. Business Premium includes Defender Plan 1, which does.
That last point has a second half. Even with the right license, nothing is protected by default: an administrator must add each person and partner domain to the protected list manually. Microsoft also documents a real limitation, that user impersonation protection does not apply when sender and recipient have previously corresponded. Configure it early or it has nothing to compare against. I would bet most Central Florida businesses on Business Premium are paying for impersonation protection that was never switched on. We went deeper on the limits of filtering in Email Filtering for Small Businesses.
Why it works on your best people
A whaling attack does not exploit stupidity. It exploits three things you actively want in an employee: hierarchy, because doing what the owner asks promptly is literally the job; helpfulness; and tolerance of time pressure. The bookkeeper who processes a wire fastest is your best bookkeeper. Competence, loyalty, and speed are the failure modes, which is why the fix has to be structural rather than attitudinal. Treating it as carelessness makes you less safe, because it guarantees the person who gets suspicious stays quiet rather than look foolish. There is more on this pattern in What Social Engineering Actually Looks Like Inside a Small Business.
The AI layer, without the hype
The 2025 IC3 report tracked artificial intelligence as a formal crime descriptor for the first time: 22,364 complaints and $893,346,472 in losses across all crime types. Within BEC, complaints with an AI nexus numbered 135, with $30,256,592 in losses.
Let me be honest about that. 135 out of 24,768 is a small slice, and the FBI notes victims often do not recognize AI involvement, so the real number is higher. But I will not tell a 40 person company in Longwood that voice cloning is the likeliest thing to hit them this quarter. A lookalike domain and a plausible invoice is.
What has genuinely changed is smaller and more consequential. The grammar tell is dead. For twenty years we taught people to watch for stilted phrasing as the marker of a foreign-language scammer, and generative text retired that signal permanently. If your security awareness training still leans on spotting bad English, it trains people on a tell that no longer exists. The report also notes voice cloning used to request wire payments, which means a voice on a call is no longer proof of identity. A call verifies identity only when you dialed the number.
Controls that actually stop this
Ordered by how much they matter, not by what they cost.
- Out-of-band callback on a previously known number. This is the control. Any request to move money or change payment instructions gets verified by voice on a number already in your records, never one supplied in the message. The FBI has repeated this for a decade: use previously known numbers, not the numbers provided in the email request. Apply it to everyone, hardest to the owner.
- Dual authorization above a dollar threshold. Two named people approve anything over a set amount. Pick a number that stings a little, not one so high it never triggers.
- A written vendor banking change procedure. Any change triggers a callback to the contact already on file, a 24 hour hold, and a logged record of who verified it. No exceptions for long-standing vendors. Long-standing vendors are the target.
- The same procedure for payroll and direct deposit changes. HR gets less scrutiny than accounts payable and is the softer door.
- Bank-side controls you probably already qualify for. ACH debit blocks and filters, positive pay, and a written wire callback agreement. Cheap or free, and most have never asked. Learn your bank recall process before you need it.
- Microsoft 365 tenant hardening. Phishing-resistant MFA where you can. Block legacy authentication protocols such as POP, IMAP, and basic SMTP, which the FBI has flagged as the route used to sidestep MFA. Disable external auto-forwarding. Turn on mailbox auditing and retain logs at least 90 days. Enable the external sender banner, and configure Defender impersonation protection for your owner, finance staff, and top vendor domains. Get DMARC to enforcement and register the obvious lookalike variants of your domain.
- One sentence from the owner, said out loud, in front of everyone. “You will never be in trouble for calling me to verify a payment, even if I sound annoyed, even if I said it was urgent, even if I said keep it quiet.” Say it at a staff meeting, and again in six months. Without it, every control above fails the moment a junior employee weighs irritating the boss against a fraudulent wire.
Honest tradeoffs and what this does not fix
- A callback policy adds friction. It will slow legitimate payments and some vendors will find it irritating. That cost is real. I still think it is the cheapest insurance in business.
- None of this fixes the credential theft behind the compromised-mailbox version. That is a separate discipline: MFA, conditional access, and token protection, covered in Identity Is the New Perimeter.
- Cyber insurance is not the backstop most owners assume. Social engineering and funds transfer fraud are commonly written as a sublimit rather than at the full policy limit, and carriers increasingly require a documented verification procedure as a condition of paying. I am not a licensed insurance advisor. Ask your broker to walk you through those endorsements specifically.
The realistic goal is not immunity. It is making the fraud require two independent failures instead of one.
If it already happened, the first hour matters more than the first week
Print this and tape it inside a cabinet door. Given that 58 percent freeze rate, speed is not optional.
- Call your bank immediately. Request a recall and ask what indemnification documents they need.
- File at ic3.gov with complete transaction details. This is the input that feeds the Recovery Asset Team. File regardless of amount.
- Contact the receiving bank fraud department directly. Do not assume the two banks are talking.
- Preserve evidence. Do not delete the mailbox. Capture message headers, check for attacker-created inbox rules, and pull sign-in logs.
- Assume the mailbox is still compromised. Revoke active sessions and refresh tokens, not just the password. A reset alone does not evict an attacker holding a valid session token.
- Tell your staff the same day. The second attempt usually arrives within days, aimed at someone else.
- Notify your local FBI field office and your insurance carrier. Most policies have notification windows measured in days.
Where I have a stake in this
Harmony MSP sells managed IT and security services across Orlando and Central Florida. Several items on that control list, the tenant hardening, the Defender configuration, the mailbox auditing, are things we configure and monitor for money. Read this with that in mind.
So let me be direct about the part that does not involve me. The highest-value item on that list is the callback policy plus the sentence the owner says out loud. Neither requires a vendor, a license, or a call to me. I would rather you do those and buy nothing than buy something from me and skip them.
If you want a second set of eyes
If you want a second set of eyes on how your business verifies payments, or you are not sure whether the impersonation protection you already pay for in Microsoft 365 is switched on, we are happy to look and tell you what we find. Call us at (407) 720-6540. No pitch required.
Frequently asked questions
What is the difference between a whaling attack and spear phishing?
Whaling is a form of spear phishing where a senior executive is either the target or the identity being impersonated. The mechanics are the same. The difference is authority: a request that appears to come from the owner gets acted on faster and questioned less, which is exactly what the attacker is buying.
Can email filtering stop a whaling attack?
Only partly. Filtering catches lookalike domains, display name spoofs, and messages from known-bad infrastructure. It cannot catch a plain text request sent from a genuinely compromised mailbox, because that message passes every technical check. A written callback rule is the control that covers the gap.
Is the money gone once a fraudulent wire is sent?
Not necessarily. The FBI Recovery Asset Team froze 58 percent of the funds in the cases reported to it in 2025. Recovery depends almost entirely on speed. Call your bank and file at ic3.gov the same day, ideally within hours.
Does my business really need a callback policy if we are small?
Small businesses are the easier target, not the safer one. Fewer approval layers means a single person can move money, and that is the condition the attack is designed to exploit. The policy costs nothing to write and is the single highest-value control on the list.
Sources
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report
- FBI IC3, Business Email Compromise crime information and prevention guidance
- FBI IC3 PSA, Business Email Compromise: The $55 Billion Scam
- FBI IC3 PSA, BEC Through Exploitation of Cloud-Based Email Services
- FBI, Business E-Mail Compromise, on reconnaissance and voice verification
- Microsoft Learn, Anti-phishing policies in EOP and Microsoft Defender for Office 365
A note on statistics: all complaint counts and dollar figures above come directly from the FBI IC3 2025 Internet Crime Report. Secondary-source figures that could not be traced to a primary document have been excluded.



