Whaling
Spear phishing aimed at senior executives, where a single success unlocks unusually high authority.
Executives make attractive targets because their requests are rarely questioned and their calendars, travel, and public statements give an attacker plenty of material. A message timed to a conference the CFO is genuinely attending is far harder to dismiss than a generic one.
The defense is procedural as much as technical. Payment changes and unusual approvals should require verification through a channel the requester did not choose, and that rule needs to apply to the chief executive exactly as it applies to everyone else.
Where this comes up
Whaling sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.