“Please pay this £47,500 invoice before 3pm. I’m in meetings — do not call.”
Every request has the same five parts.
16 requests, across 4 worlds. Each one is trying to move something valuable, and each can be stopped by exactly one of the three controls you are offered. Pick one and try to stop it.
Start the trace↓- 01WORLD
- 02ASK
- 03YOU
- 04DO
- 05VALUE
- 01Pick a worldInbox, Slack, Browser or Agent.
- 02Pick a requestFour in each — read what it is asking for.
- 03Try to stop itThree controls are offered. Only one meets this attack.
Your Inbox World
A familiar sender can still carry an unfamiliar ask.
Ask Do
“Sure — I’ll authorise it now.”
New vendor payment
Verify the vendor and call back on a known number.
Impersonate the CEO
Rush a payment to a newly controlled account.
It lands on one desk.
It never stops there.
The attacker borrows the C-Level identity to move Accounts / Finance. Stopping it safely also needs Managers and IT — which is why training one desk in isolation tends to leave the rest of the route untouched.
The six questions a hardened process passes
- Have they been trained on this attack?
- Yes — on this one, not on phishing in the abstract.
- When was their last training?
- It could have been the day after the attack was first seen in the wild.
- Do they understand how they will be manipulated?
- Well enough to recognise it under pressure, rather than only in a quiz.
- Do they know what action to take here?
- Yes — and so does everyone else on the route.
- Have the impersonated and the targeted actually spoken?
- Yes. They have had the chance to agree how this gets checked.
- Is the process’s resilience self-healing?
- It is. When someone leaves and someone new arrives, they are brought up to speed by design.
- 01 / THE THREAT ARRIVES“ceo@work.com”External route · display name matched
- 02 / WEARING AN IDENTITYC-LevelA colleague, borrowed
- 03 / IT LANDS HEREAccounts / FinanceWhere the ask has to be judged
- 04 / THE ROUTE CROSSESManagers and ITEveryone a safe answer depends on
- C-LevelIdentity borrowed
- Accounts / FinanceReceives the ask
- ManagersOn the route
- ITOn the route
- BoardNot involved
- HRNot involved
- AdminsNot involved
- SalesNot involved
- HelpdeskNot involved
Built for this attack, not for attacks in general.
The impersonated and the targeted have actually spoken.
The stopping point is in the process, not in someone’s memory.
Five parts.
One chain.
Every incident above is the same five links in a row. Naming them is what lets a team argue about where to put a control, instead of arguing about whose fault it was.
What you are told
The story, instruction or pretext that asks for belief.
Everything that makes a request feel genuine can be borrowed.
A trusted route. A real history. A plausible story. Arriving at exactly the right moment. That is the entire formula for belief — and every term in it can be supplied by someone else.
Which is why identity is never settled by the request that claims it. The check that holds is the one it cannot answer for itself — a route to the real person, or the real system, that it did not hand you.

It started because I could not let a question go.
In 2016 I registered a lookalike domain and emailed a senior figure at the White House. He replied within minutes. I did it more than 150 times after that — Wall Street chief executives, the Governor of the Bank of England — and the interesting part was never the technology, because there wasn’t any. It was the half-second in which someone decided I was who I said I was.
I have never really stopped picking at that half-second. Why a request feels legitimate. What a person is actually checking when they believe they are checking. Which kind of pressure makes a careful professional move quickly.
Ask&Do is what the obsession turned into — a way to name the parts of a request so a team can point at where a control belongs, instead of arguing about who clicked. These days I build tools at QuilrAI against the thing I used to demonstrate, and I have briefed the US Secret Service and worked with the UK’s NCSC along the way.
James Lintonjames-linton.com
Trace your own requests.
If you want this run against the asks your people actually receive — in your channels, with your assets — start a conversation.
j@james-linton.com