{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,28]],"date-time":"2026-08-28T17:16:47Z","timestamp":1787937407414,"version":"build-2784847793"},"reference-count":89,"publisher":"SAGE Publications","issue":"3","license":[{"start":{"date-parts":[[2020,6,3]],"date-time":"2020-06-03T00:00:00Z","timestamp":1591142400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Technology"],"published-print":{"date-parts":[[2020,9]]},"abstract":"<jats:p>Whaling is one of the most financially damaging, well-known, effective cyberattacks employed by sophisticated cybercriminals. Although whaling largely consists of sending a simplistic email message to a whale (i.e. a high-value target in an organization), it can result in large payoffs for cybercriminals, in terms of money or data stolen from organizations. While a legitimate cybersecurity threat, little information security research has directed attention toward whaling. In this study, we begin to provide an initial understanding of what makes whaling such a pernicious problem for organizations, executives, or celebrities (e.g. whales), and those charged with protecting them. We do this by defining whaling, delineating it from general phishing and spear phishing, presenting real-world cases of whaling, and provide guidance on future information security research on whaling. We find that whaling is far more complex than general phishing and spear phishing, spans multiple domains (e.g. work and personal), and potentially results in spillover effects that ripple across the organization. We conclude with a discussion of promising future directions for whaling and information security research.<\/jats:p>","DOI":"10.1177\/0268396220918594","type":"journal-article","created":{"date-parts":[[2020,6,3]],"date-time":"2020-06-03T07:39:56Z","timestamp":1591169996000},"page":"214-231","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":29,"title":["Protecting a whale in a sea of phish"],"prefix":"10.1177","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0171-6372","authenticated-orcid":false,"given":"Daniel","family":"Pienta","sequence":"first","affiliation":[{"name":"Baylor University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jason Bennett","family":"Thatcher","sequence":"additional","affiliation":[{"name":"The University of Alabama, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Allen","family":"Johnston","sequence":"additional","affiliation":[{"name":"The University of Alabama, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"179","published-online":{"date-parts":[[2020,6,3]]},"reference":[{"key":"bibr1-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2012.6282648"},{"key":"bibr2-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1080\/07421222.2014.1001260"},{"key":"bibr3-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2307\/25750686"},{"key":"bibr4-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2015.21"},{"key":"bibr5-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1016\/j.chb.2014.05.046"},{"key":"bibr6-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1146\/annurev.psych.60.110707.163621"},{"key":"bibr7-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2307\/41409963"},{"key":"bibr8-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2307\/23044053"},{"key":"bibr9-0268396220918594","unstructured":"BBC News (2019) Attacker \u201cfound victim through photo reflection.\u201d Available at: https:\/\/www.bbc.com\/news\/world-asia-50000234 (accessed 22 November 2019)."},{"key":"bibr10-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1287\/orsc.2016.1046"},{"key":"bibr11-0268396220918594","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2015\/39.4.5"},{"key":"bibr12-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1080\/10919392.2019.1552745"},{"key":"bibr13-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2013.106"},{"key":"bibr14-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2105\/AJPH.91.3.465a"},{"issue":"4","key":"bibr15-0268396220918594","doi-asserted-by":"crossref","first-page":"1023","DOI":"10.25300\/MISQ\/2018\/13631","volume":"42","author":"Chen A","year":"2019","journal-title":"MIS Quarterly"},{"key":"bibr16-0268396220918594","unstructured":"CIO Review (2015) Mimecast and Kaspersky Labs warn enterprises of whaling and phishing threats. CIOReview. Available at: https:\/\/www.cioreview.com\/news\/mimecast-and-kaspersky-labs-warn-enterprises-of-whaling-and-phishing-threats-nid-11199-cid-21.html (accessed 24 June 2019)."},{"key":"bibr17-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1177\/0268396291006003-409"},{"key":"bibr18-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1111\/j.1539-6924.2008.01142.x"},{"key":"bibr19-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1145\/3210530.3210533"},{"key":"bibr20-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222290204"},{"key":"bibr21-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1100.0284"},{"key":"bibr22-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2006.10.009"},{"key":"bibr23-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2307\/258191"},{"key":"bibr24-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2307\/258557"},{"key":"bibr25-0268396220918594","doi-asserted-by":"publisher","DOI":"10.5465\/amj.2007.24160888"},{"key":"bibr26-0268396220918594","unstructured":"Fox-Brewster T (2017) Iranian hackers targeted Deloitte via a seriously convincing Facebook fake [WWW Document]. Forbes. Available at: https:\/\/www.forbes.com\/sites\/thomasbrewster\/2017\/10\/05\/facebook-fake-hacks-deloitte-employee-iran-cyber-spies-suspected\/ (accessed 24 June 2019)."},{"key":"bibr27-0268396220918594","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00447"},{"key":"bibr28-0268396220918594","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00308"},{"key":"bibr29-0268396220918594","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00294"},{"key":"bibr30-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1145\/2063176.2063197"},{"key":"bibr31-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2013.0501"},{"key":"bibr32-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1110.0393"},{"key":"bibr33-0268396220918594","unstructured":"Infosec Resources (2017) Whaling case study [WWW Document]. Available at: https:\/\/resources.infosecinstitute.com\/category\/enterprise\/phishing\/spear-phishing-and-whaling\/whaling-case-study\/ (accessed 24 June 2019)."},{"key":"bibr34-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1057\/palgrave.jit.2000023"},{"key":"bibr35-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1145\/1290958.1290968"},{"key":"bibr36-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1007\/11507840_9"},{"key":"bibr37-0268396220918594","doi-asserted-by":"publisher","DOI":"10.24251\/HICSS.2017.520"},{"key":"bibr38-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1080\/07421222.2017.1334499"},{"key":"bibr39-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2307\/25750691"},{"key":"bibr40-0268396220918594","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2015\/39.1.06"},{"key":"bibr41-0268396220918594","unstructured":"Kahneman D, Egan P (2011) Thinking, Fast and Slow. New York: Farrar, Straus and Giroux."},{"key":"bibr42-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1016\/j.bushor.2016.03.008"},{"key":"bibr43-0268396220918594","first-page":"2012","volume":"9","author":"Kayworth T","year":"2010","journal-title":"MIS Quarterly Executive"},{"key":"bibr44-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1145\/1754393.1754396"},{"key":"bibr45-0268396220918594","doi-asserted-by":"crossref","unstructured":"Litt E, Hargittai E (2014) Smile, snap, and share? A nuanced approach to privacy and online photo-sharing. Poetics 42: 1\u201321. https:\/\/doi.org\/10.1016\/j.poetic.2013.10.002","DOI":"10.1016\/j.poetic.2013.10.002"},{"key":"bibr46-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1037\/0021-9010.71.3.402"},{"key":"bibr47-0268396220918594","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00051"},{"key":"bibr48-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1145\/1985347.1985353"},{"key":"bibr49-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2307\/259290"},{"key":"bibr50-0268396220918594","volume-title":"Proceedings of the 23rd Americas conference on information systems","author":"Marabelli M","year":"2017"},{"key":"bibr51-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2015.0587"},{"key":"bibr52-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1057\/s41303-017-0058-x"},{"key":"bibr53-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2308\/isys-52481"},{"key":"bibr54-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1177\/0170840607081138"},{"key":"bibr55-0268396220918594","doi-asserted-by":"publisher","DOI":"10.5465\/19416520802211644"},{"key":"bibr56-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2307\/25148783"},{"key":"bibr57-0268396220918594","unstructured":"Pew Research Center (2017) What Americans knows about cybersecurity. Available at: https:\/\/www.pewinternet.org\/2017\/03\/22\/what-the-public-knows-about-cybersecurity\/ (accessed 2 June 2019)."},{"key":"bibr58-0268396220918594","volume-title":"Proceeding of the international conference on information systems workshop on information security and privacy","author":"Pienta D","year":"2018"},{"key":"bibr59-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1080\/07421222.2015.1138374"},{"key":"bibr60-0268396220918594","unstructured":"Rapid7 (2019) Whaling phishing attacks explained: What is whaling? [WWW Document]. Available at: https:\/\/www.rapid7.com\/fundamentals\/whaling-phishing-attacks\/ (accessed 24 June 2019)."},{"key":"bibr61-0268396220918594","unstructured":"Reed Smith LLP (2019) Phishing the insurance coverage gap\u2014Perspectives [WWW Document]. Available at: https:\/\/www.reedsmith.com\/en\/perspectives\/2017\/02\/phishing-in-the-insurance-coverage-gap (accessed 11 April 2019)."},{"key":"bibr62-0268396220918594","unstructured":"Reuters (2017) Austria\u2019s FACC, hit by cyber fraud, fires CEO [WWW Document]. Available at: https:\/\/www.reuters.com\/article\/us-facc-ceo\/austrias-facc-hit-by-cyber-fraud-fires-ceo-idUSKCN0YG0ZF (accessed 24 June 2019)."},{"key":"bibr63-0268396220918594","unstructured":"Robinson M (2018) The 24-year-old daughter of tech billionaire Michael Dell shares what \u2018growing up Dell\u2019 taught her about life and business. Business Insider. Available at: https:\/\/www.businessinsider.com\/alexa-dell-shares-life-lessons-from-michael-dell-2018-3 (accessed 22 April 2020)."},{"key":"bibr64-0268396220918594","volume-title":"The Nature of Human Values","author":"Rokeach M","year":"1973"},{"key":"bibr65-0268396220918594","first-page":"1210","volume-title":"International conference on information systems, ICIS 2012","author":"Rowe F","year":"2012"},{"key":"bibr66-0268396220918594","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2016\/40.3.07"},{"key":"bibr67-0268396220918594","volume-title":"20th Pacific Asia conference on information systems (PACIS 2016)","author":"Schuetz SW","year":"2016"},{"key":"bibr68-0268396220918594","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2014\/38.3.11"},{"key":"bibr69-0268396220918594","unstructured":"The New York Times (2019) He tried to Bilk Google and Facebook Out of $100 million with fake invoices [WWW Document]. Available at: https:\/\/www.nytimes.com\/2019\/03\/25\/business\/facebook-google-wire-fraud.html (accessed 24 June 2019)."},{"key":"bibr70-0268396220918594","unstructured":"Trend Micro USA (2019) Whale phishing\u2014Definition [WWW Document]. Available at: https:\/\/www.trendmicro.com\/vinfo\/us\/security\/definition\/whale-phishing (accessed 24 June 2019)."},{"key":"bibr71-0268396220918594","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2018\/14124"},{"key":"bibr72-0268396220918594","doi-asserted-by":"publisher","DOI":"10.7208\/chicago\/9780226346960.001.0001"},{"key":"bibr73-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1145\/3078861.3078875"},{"key":"bibr74-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.04.004"},{"key":"bibr75-0268396220918594","volume-title":"Paper presented at the thirty-sixth international conference of information systems","author":"Wade J","year":"2015"},{"key":"bibr76-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1037\/a0015848"},{"key":"bibr77-0268396220918594","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00442"},{"key":"bibr78-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2016.0680"},{"key":"bibr79-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222250206"},{"key":"bibr80-0268396220918594","unstructured":"White M (2017) Tech Firm Ubiquiti Suffers $46M Cyberheist\u2014Krebs on security. Available at: https:\/\/krebsonsecurity.com\/2015\/08\/tech-firm-ubiquiti-suffers-46m-cyberheist\/ (accessed 24 June 2019)."},{"key":"bibr81-0268396220918594","first-page":"15","volume":"48","author":"Whitten D","year":"2008","journal-title":"Journal of Computer Information Systems"},{"key":"bibr82-0268396220918594","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2013\/37.1.01"},{"key":"bibr83-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1111\/isj.12129"},{"key":"bibr84-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1111\/isj.12058"},{"key":"bibr85-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222270111"},{"key":"bibr86-0268396220918594","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2014.0522"},{"key":"bibr87-0268396220918594","doi-asserted-by":"publisher","DOI":"10.24251\/HICSS.2018.668"},{"key":"bibr88-0268396220918594","doi-asserted-by":"publisher","DOI":"10.2307\/20721425"},{"key":"bibr89-0268396220918594","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00399"}],"container-title":["Journal of Information Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0268396220918594","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0268396220918594","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0268396220918594","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T23:04:50Z","timestamp":1777503890000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0268396220918594"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,3]]},"references-count":89,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2020,9]]}},"alternative-id":["10.1177\/0268396220918594"],"URL":"https:\/\/doi.org\/10.1177\/0268396220918594","relation":{},"ISSN":["0268-3962","1466-4437"],"issn-type":[{"value":"0268-3962","type":"print"},{"value":"1466-4437","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,6,3]]}}}