> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/simulations/whatsapp-phishing-simulations.md).

# WhatsApp Phishing Simulations

Build, send, and track WhatsApp phishing campaigns to test how your team responds to social engineering on the world's most-used messaging app.

{% hint style="info" %}
WhatsApp simulations are currently in **early access**. The channel is enabled per organization by Herd and doesn't appear in the Simulations channel switcher until it has been turned on for you. Contact your Herd representative if you'd like to take part.
{% endhint %}

## Overview

WhatsApp joins email and SMS as a phishing-simulation channel. Attackers increasingly move lures onto messaging apps, where messages arrive from unfamiliar numbers, links can't be hovered, and the platform's personal feel lowers people's guard. Herd lets you simulate exactly that: a WhatsApp text from an unknown business number carrying a personalized lure and a tracked link.

WhatsApp campaigns follow the same two-step pattern as email and SMS: build a **template** (the message), then launch a **campaign** that sends it to your chosen recipients.

To get there, expand **Simulations** in the left-hand sidebar and pick **WhatsApp** (alongside **Email**, **SMS**, and, where enabled, **Voice**). The WhatsApp area is organized into **Campaigns**, **Templates**, **Pages**, and **Reports** tabs. A **Reviews** tab also appears when WhatsApp template approval is turned on, or whenever there are templates waiting for review — and only for people who can approve.

{% hint style="info" %}
Access is also controlled by its own permission family (WhatsApp view, template manage, template approve, campaign manage). Approving is the **Whatsapp > Template > Approve** permission: admins always hold it, operators hold it through a group that's been granted it in **Users → Groups**, and members can't approve. There's no approver picker in the simulation settings drawer. See [Managing Roles, Groups, and Permissions](/herd-security-docs/how-to-documentation/managing-roles-groups-and-permissions.md#who-can-approve-simulation-templates).
{% endhint %}

***

## Connecting your WhatsApp Business account

Herd sends WhatsApp simulations through the **Meta WhatsApp Cloud API** from your organization's own WhatsApp Business sender. Before you can launch a campaign, connect the account:

1. From any WhatsApp simulations page, open the simulation settings (the gear icon) and find the **WhatsApp Business account** tile under **WhatsApp**.
2. Click **Connect WhatsApp Business**. A Meta sign-in window opens; sign in and pick the business account and sender number Herd should use. Allow pop-ups for the Herd site if the window doesn't open.
3. Once connected, the tile shows the sender's **Verified name**, **Sender (phone number ID)**, **Business account ID**, **Display name**, **Quality** rating, and **Webhooks** status. Herd warns you here if Meta lowers the sender's messaging quality rating.

Connecting authorizes Herd to send simulations on behalf of your business account and to receive delivery, opt-out, and template review updates for it. **Disconnect** at any time from the same tile; scheduled campaigns using that sender will fail until you reconnect.

Until an account is connected, the campaign form shows a warning that WhatsApp isn't connected for your organization and **Send Campaign** stays disabled.

### How delivery works

A few things that make WhatsApp different from SMS:

* **Any international number works.** WhatsApp accepts any valid E.164 phone number, while Herd's SMS channel is limited to +1 territories and Ukraine, making WhatsApp the channel of choice for global teams.
* **Read receipts are real.** WhatsApp reports when a recipient has read the message, so results include a genuine **Read** signal that SMS can't provide.
* **Phone numbers come from your identity provider** (Okta, Entra ID, Google Workspace), just as with [smishing](/herd-security-docs/simulations/sms-phishing-smishing-simulations.md). Users without a number on file are hidden from the recipient picker.
* **Recipients can opt out.** Anyone who replies **STOP** to a simulation is excluded from future WhatsApp sends automatically, and your organization's admins are notified in Slack or Teams. Replying **START** re-enrolls them.
* **Sending is paced and capped.** Messages go out gradually rather than all at once, and each organization has daily and monthly WhatsApp send limits set by Herd. A launch that would exceed the remaining limit is rejected with a message explaining which cap was hit.

***

## Creating a WhatsApp template

Open the **Templates** tab and click **Create Template**. A template has:

* **Template Name**: a clear, descriptive identifier.
* **From Phone Number**: choose **Use all phone numbers (recommended)** or pin a specific sender. The list shows the numbers registered on your connected WhatsApp Business account, labelled with the number and its verified business name. If a pinned number is later removed from the account, it stays selectable but is marked **(no longer available)** so you can pick a replacement.
* **Message**: the text the recipient receives, including the `{{link}}` placeholder for the tracked link. A live phone-style preview renders the message the way it appears to recipients: an inbound message from an **Unknown sender**.
* **Description (Optional)**: a note explaining the scenario.
* **Landing Page (Optional)**: the page recipients see after tapping the link. Landing pages are shared with email and SMS phishing, and any submitted credentials are counted for analytics but never stored.

Saved templates get an inline **Template tags** editor, and you can tag several at once by ticking them in the table and clicking **Tag selected**. Once your library has tags, a **Filters** button in the table header lets you narrow the list by tag.

The **Pages** tab opens the shared [landing-page library](/herd-security-docs/simulations/phishing-simulations/landing-pages.md) so you can create and edit pages without leaving the WhatsApp channel. A landing page that's in use by an active WhatsApp campaign can't be deleted until that campaign finishes.

{% hint style="info" %}
Herd can also generate WhatsApp templates for you: ask [Herd AI](/herd-security-docs/herdai/herdai.md) to draft one in chat and it shows a **WhatsApp Template Preview** card with a **Publish** button and, once published, a **View Template** link. The nightly template generator can also keep your pool fresh. If your organization requires review, generated templates wait in the **Reviews** tab until approved, with an optional **Bypass review for auto-generated WhatsApp templates** setting in the simulation settings drawer.
{% endhint %}

***

## Creating and sending a campaign

Open the **Campaigns** tab and click **Create Campaign**. The form mirrors the other channels:

* **Campaign Name** and an optional description.
* **Template**: pick the WhatsApp template to send. Only templates that are usable in a campaign are listed; unapproved templates don't appear while approval is required.
* **Sending domain**: leave on **Default** or pick one of your verified short-link domains.
* **Target Recipients**: add users or groups. Campaigns are capped at **200 recipients**.
* **Schedule Campaign (Optional)**: pick a date and time, or leave empty to send immediately when launched.

Click **Create Campaign** to save the draft, then open it and click **Send Campaign**. The **Launch WhatsApp Campaign** dialog shows the recipient count and an estimated delivery time; confirm to start sending. Like the other channels, WhatsApp supports ongoing campaigns (a rolling re-phish schedule with pause and resume), **Retry Failed** for retryable deliveries, and **Re-run Campaign** to spin up a fresh draft against the same audience.

***

## Results

The campaign's **Results** tab tracks each recipient through **Queued**, **Sent**, **Clicked**, **Submitted credentials**, **Failed (retrying)**, and **Permanent failure**, alongside a delivery summary of the **Transmission rate**, **Read** count, **Click rate**, **Failure rate**, and how many deliveries are **Retryable**. Tapping the tracked link is the failure signal, and it feeds the recipient's risk score like any other simulation failure. Deliveries that fail are retried up to your organization's retry limit (three attempts by default) before they're marked as permanent failures.

For the organization-wide view (**Total Campaigns**, **Messages Sent**, **Delivery Rate**, **Click Rate**), open the **Reports** tab, or the [Reports hub](/herd-security-docs/reports/reports.md#simulations) where WhatsApp sits alongside Email and SMS under the Simulations tab.

***

Pair WhatsApp with [email](/herd-security-docs/simulations/phishing-simulations.md), [SMS](/herd-security-docs/simulations/sms-phishing-smishing-simulations.md), and [voice](/herd-security-docs/simulations/voice-simulations.md) campaigns to give your team practice spotting social engineering on every channel they actually use.
