Phishing Awareness Lesson Plan Digital Shield
Teacher Lesson Plan
Grade 8 • 45 Minutes
Core Objective
Students will be able to identify common signs of phishing attacks and demonstrate safe online behaviors to protect their personal information.
Materials Needed
Classroom Slide Deck
Phishing Awareness Worksheet
Phishing Awareness Quiz
Whiteboard & Markers
Instructional Flow
05
mins
Introduction: Hook & Definition
Define Phishing : A digital scam where attackers masquerade as trusted entities to steal sensitive data (usernames, passwords, credit card info).
Opening Question: "Have you or someone you know ever received a suspicious email or text? What did it look like? Did anything about it feel 'off'?"
Briefly touch on the financial and personal stakes of cybersecurity.
20
mins
Activity: Inbox Inspection
Distribute the Phishing Awareness Worksheet .
Students work individually or in pairs to analyze 3 specific email/message scenarios.
Task: Highlight the specific "red flags" (urgent tone, bad grammar, weird links, generic greetings).
Teacher circulates to guide students who might miss subtle clues.
10
mins
Discussion: Cyber Strategy
Facilitate a class-wide debrief using the Discussion Guide .
Focus on why these attacks work (psychology of urgency/fear).
Discuss the "hover test" (hovering over links to see the real destination).
Ask: "If you realize you fell for a scam, what should you do first?" (Change passwords, tell an adult, contact bank/service).
05
mins
Assessment: Knowledge Check
Administer the Phishing Awareness Quiz .
Quick individual check to ensure they can differentiate between safe and suspicious content.
05
mins
Closure: Digital Citizen Pledge
Recap the Big 3: Inspect the sender, Ignore the urgency, Indicate (report) the scam.
Challenge students to go home and check their family's inbox with their new "Digital Detective" skills.
Inbox Inspector Slides Cyber Awareness
INBOX
INSPECTOR
Protecting Your Digital Identity
What is Phishing?
A fraudulent attempt to obtain sensitive information by disguising as a trustworthy entity in an electronic communication.
Think of it like this:
Criminals "fishing" for your data using bait (emails, texts, or social media messages).
Don't Get Hooked
Why do they do it?
Profit
Stealing bank info or selling your personal data on the dark web.
Identity
Pretending to be you to commit crimes or trick your friends.
Access
Getting into private networks or school/work databases.
Red Flag Radar
Extreme Urgency
"Act NOW or your account will be DELETED!"
Grammar & Spelling
Professional companies rarely make sloppy mistakes.
Suspicious Links
Does the URL look weird? Hover over it to see the real path.
Generic Greetings
"Dear Valued Customer" instead of your actual name.
Discussion Point
"Have you ever received a message that felt slightly 'off'? What was your first clue?"
The Digital Defense
1
Think Before Clicking
Never click links or open attachments from unknown sources.
2
Verify the Source
Contact the company directly using a known official number or site.
3
Use MFA
Multi-Factor Authentication is your best second line of defense.
Secure Your Data Phishing Awareness Worksheet Inbox Inspector
Digital Detective Worksheet
Name:
Date:
Mission: Analyze the following digital messages. Your goal is to spot the "Red Flags" that indicate a phishing attempt. Circle or underline the clues in the text, then answer the questions below.
CASE 001
The Urgent Alert
From: secure-noreply@amaz0n-security.xyz
Subject: [URGENT] YOUR ACCOUNT WILL BE CLOSED IN 2 HOURS
Dear Customer,
We noticed unusual activity on your account from a device in Russia. For your safety, we have temporarly locked your login. To prevent permanent deletion of your account data, you must verify your identity immediately.
Click Here to Login and Confirm Identity
Thank you,
The Customer Service Team
1. Identify the signs of phishing in this email. What "Red Flags" did you find?
CASE 002
The Prize Winner
Message from: +1 (555) 923-0102
CONGRATS!! You are the lucky 10,000th visitor today! You have won a $1,000 Apple gift card. 🍏 Claim it now before it expires in 10 minutes: http://bit.ly/claim-prize-free-99
2. Describe exactly how you would handle this text message. What steps would you take?
CASE 003
The Protection Plan
List three specific actions you can take starting today to protect your personal information from phishing attacks.
Phishing Awareness Discussion Guide Cyber Strategist
Teacher Discussion Guide
This guide is designed to facilitate a 10-minute classroom debrief following the worksheet activity. The goal is to move beyond identification to understanding the "why" and "how" of cyber defense.
1
Why do you think phishing attacks are so common?
Key Discussion Points:
Low Cost: Sending millions of emails is virtually free for attackers.
Numbers Game: If 1,000,000 emails are sent and only 10 people fall for it, the attacker still wins.
Emotional Manipulation: Attackers exploit human feelings like fear, curiosity, and greed.
Global Reach: Attackers can be anywhere in the world, making them hard to catch.
2
What were the most obvious "Red Flags" you found?
Encourage Students to Share:
Hovering over links: Explain how to hover (don't click!) to see the actual URL in the bottom corner of the browser.
The "Sender" Check: Look for misspellings in the domain (e.g., @amaz0n.com vs @amazon.com).
Language: Professional companies use formal language and high-quality graphics.
Unexpectedness: "If you weren't expecting a prize or a warning, it's probably fake."
3
What should you do if you realize you've been "hooked"?
Crucial Recovery Steps:
Step 1: Immediately change the password of the account involved.
Step 2: If financial info was shared, alert parents and contact the bank.
Step 3: Report the message as "Phishing" or "Spam" to the email/app provider.
Step 4: Check other accounts that might use the same password.
Teacher Pro-Tip
Remind students that even tech-savvy adults fall for phishing. There is no shame in being tricked; the most important thing is acting fast to secure the data. Encourage a "culture of reporting" rather than "culture of fear."
Phishing Awareness Quiz Knowledge Check
Phishing Awareness Quiz
Student Name
Date
1
Which of the following is a sign of a phishing email?
An email from a known contact with no spelling errors
An email with urgent language asking for personal information
An email with attachments from a trusted source
An email with a familiar domain name
2
What should you do if you receive a suspicious email?
Click the link to check if it’s legitimate
Delete it immediately without reading it
Forward it to friends to warn them
Report it to your email provider and then delete it
3
True or False: Only clicking on links from people you know is a reliable way to avoid phishing attacks.
True
False
Teacher Note: This assessment evaluates the ability to identify red flags and proper digital hygiene. Ensure students understand that hacked accounts can send "trusted" links that are actually malicious.
Phishing Awareness Answer Key Answer Key
Teacher Resource • Digital Shield
STRICTLY FOR TEACHER USE
Phishing Awareness Quiz
1. Which of the following is a sign of a phishing email?
Answer: An email with urgent language asking for personal information.
2. What should you do if you receive a suspicious email?
Answer: Report it to your email provider and then delete it.
3. True or False: Only clicking on links from people you know is reliable...
Answer: False.
Reasoning: Friends' accounts can be hacked, or attackers can "spoof" (fake) the sender's display name to look like a friend.
Worksheet: Inbox Inspector
CASE 001: The Urgent Alert
Expected Red Flags:
Sender Address: "amaz0n" (uses a zero instead of an 'o') and the domain ".xyz".
Urgency/Threat: "URGENT", "WILL BE CLOSED IN 2 HOURS", "permanent deletion".
Spelling: "temporarly" is misspelled.
Generic Greeting: "Dear Customer" instead of the user's name.
CASE 002: The Prize Winner
Expected Response Steps:
Do not click the link.
Block the sender number.
Delete the message.
Report the spam to the phone carrier (usually by forwarding to 7726).
CASE 003: The Protection Plan
Accepted Actions (Any 3):
Enable Multi-Factor Authentication (MFA).
Use a password manager for unique, complex passwords.
Hover over links before clicking.
Contact companies directly via official channels if a message seems suspicious.
Keep software/antivirus updated.