WhatsApp Phishing Simulations
Build, send, and track WhatsApp phishing campaigns to test how your team responds to social engineering on the world's most-used messaging app.
Overview
WhatsApp joins email and SMS as a phishing-simulation channel. Attackers increasingly move lures onto messaging apps, where messages arrive from unfamiliar numbers, links can't be hovered, and the platform's personal feel lowers people's guard. Herd lets you simulate exactly that: a WhatsApp text from an unknown business number carrying a personalized lure and a tracked link.
WhatsApp campaigns follow the same two-step pattern as email and SMS: build a template (the message), then launch a campaign that sends it to your chosen recipients.
To get there, open Simulations in the left-hand sidebar and pick WhatsApp in the channel switcher at the top of the page (alongside Email and SMS). The WhatsApp area is organized into Campaigns, Templates, Pages, and Reports tabs. A Reviews tab also appears when WhatsApp template approval is turned on, or whenever there are templates waiting for review.
Connecting your WhatsApp Business account
Herd sends WhatsApp simulations through the Meta WhatsApp Cloud API from your organization's own WhatsApp Business sender. Before you can launch a campaign, connect the account:
From any WhatsApp simulations page, open the simulation settings (the gear icon) and find the WhatsApp Business account tile under WhatsApp.
Click Connect WhatsApp Business. A Meta sign-in window opens; sign in and pick the business account and sender number Herd should use. Allow pop-ups for the Herd site if the window doesn't open.
Once connected, the tile shows the sender's Verified name, Sender (phone number ID), Business account ID, Display name, Quality rating, and Webhooks status. Herd warns you here if Meta lowers the sender's messaging quality rating.
Connecting authorizes Herd to send simulations on behalf of your business account and to receive delivery, opt-out, and template review updates for it. Disconnect at any time from the same tile; scheduled campaigns using that sender will fail until you reconnect.
Until an account is connected, the campaign form shows a warning that WhatsApp isn't connected for your organization and Send Campaign stays disabled.
How delivery works
A few things that make WhatsApp different from SMS:
Any international number works. WhatsApp accepts any valid E.164 phone number, while Herd's SMS channel is limited to +1 territories and Ukraine, making WhatsApp the channel of choice for global teams.
Read receipts are real. WhatsApp reports when a recipient has read the message, so results include a genuine Read signal that SMS can't provide.
Phone numbers come from your identity provider (Okta, Entra ID, Google Workspace), just as with smishing. Users without a number on file are hidden from the recipient picker.
Recipients can opt out. Anyone who replies STOP to a simulation is excluded from future WhatsApp sends automatically, and your organization's admins are notified in Slack or Teams. Replying START re-enrolls them.
Sending is paced and capped. Messages go out gradually rather than all at once, and each organization has daily and monthly WhatsApp send limits set by Herd. A launch that would exceed the remaining limit is rejected with a message explaining which cap was hit.
Creating a WhatsApp template
Open the Templates tab and click Create Template. A template has:
Template Name: a clear, descriptive identifier.
From Phone Number: choose Use all phone numbers (recommended) or pin a specific sender. The list shows the numbers registered on your connected WhatsApp Business account, labelled with the number and its verified business name. If a pinned number is later removed from the account, it stays selectable but is marked (no longer available) so you can pick a replacement.
Message: the text the recipient receives, including the
{{link}}placeholder for the tracked link. A live phone-style preview renders the message the way it appears to recipients: an inbound message from an Unknown sender.Description (Optional): a note explaining the scenario.
Landing Page (Optional): the page recipients see after tapping the link. Landing pages are shared with email and SMS phishing, and any submitted credentials are counted for analytics but never stored.
Saved templates get an inline Template tags editor, and you can tag several at once by ticking them in the table and clicking Tag selected. Once your library has tags, a Filters button in the table header lets you narrow the list by tag.
The Pages tab opens the shared landing-page library so you can create and edit pages without leaving the WhatsApp channel. A landing page that's in use by an active WhatsApp campaign can't be deleted until that campaign finishes.
Creating and sending a campaign
Open the Campaigns tab and click Create Campaign. The form mirrors the other channels:
Campaign Name and an optional description.
Template: pick the WhatsApp template to send. Only templates that are usable in a campaign are listed; unapproved templates don't appear while approval is required.
Sending domain: leave on Default or pick one of your verified short-link domains.
Target Recipients: add users or groups. Campaigns are capped at 200 recipients.
Schedule Campaign (Optional): pick a date and time, or leave empty to send immediately when launched.
Click Create Campaign to save the draft, then open it and click Send Campaign. The Launch WhatsApp Campaign dialog shows the recipient count and an estimated delivery time; confirm to start sending. Like the other channels, WhatsApp supports ongoing campaigns (a rolling re-phish schedule with pause and resume), Retry Failed for retryable deliveries, and Re-run Campaign to spin up a fresh draft against the same audience.
Results
The campaign's Results tab tracks each recipient through Queued, Sent, Clicked, Submitted credentials, Failed (retrying), and Permanent failure, alongside a delivery summary of the Transmission rate, Read count, Click rate, Failure rate, and how many deliveries are Retryable. Tapping the tracked link is the failure signal, and it feeds the recipient's risk score like any other simulation failure. Deliveries that fail are retried up to your organization's retry limit (three attempts by default) before they're marked as permanent failures.
For the organization-wide view (Total Campaigns, Messages Sent, Delivery Rate, Click Rate), open the Reports tab, or the Reports hub where WhatsApp sits alongside Email and SMS under the Simulations tab.
Pair WhatsApp with email and SMS campaigns to give your team practice spotting social engineering on every channel they actually use.
Last updated