Zum Inhalt springen

English:Phishing, Scams, and Social Engineering

Aus MOOCsWiki Staging
Die Druckversion wird nicht mehr unterstützt und kann Darstellungsfehler aufweisen. Bitte aktualisiere deine Browser-Lesezeichen und verwende stattdessen die Standard-Druckfunktion des Browsers.

Phishing, Scams, and Social Engineering



Introduction

Phishing, scams, and social engineering are attempts to trick people into giving away information, money, account access, or control of a device. The technology may change, but the basic idea is often the same: a scammer tries to make you act before you have time to check.

This aiMOOC is designed for Grades 7–8. You will learn how to read messages critically, notice warning signs, verify claims through a trusted second route, protect your accounts, and respond safely if something goes wrong. The goal is not to make you suspicious of everyone. The goal is to help you slow down, check evidence, and make safer decisions online and offline.

A useful rule is: Stop. Check. Verify. Report. If a message creates pressure, asks for secrecy, requests a password or verification code, demands money, or sends you to an unfamiliar link, do not rush.

The image above comes from an educational animation created by the U.S. Federal Trade Commission. It uses the idea of “bait” to explain why a suspicious message should be checked before you respond.

The CISA animation above introduces a simple habit: recognize suspicious messages and report them rather than acting on them.


Learning Goals

By the end of this aiMOOC, you should be able to explain the difference between Phishing, a Scam, and social engineering. You should also be able to identify common pressure tactics, evaluate a message without clicking its links, verify an identity through a trusted channel, protect important accounts with strong sign-in habits, and explain what to do after a mistake.

You will also connect Cybersecurity with English, Media literacy, Critical thinking, and Digital literacy. Scam detection is partly a language skill: you examine claims, tone, evidence, audience, purpose, and persuasive techniques.


What Are Phishing, Scams, and Social Engineering?


Phishing

Phishing is a form of social engineering in which someone pretends to be a trusted person or organization in order to make you reveal information, open a harmful attachment, visit a fake website, or take another risky action. Phishing often arrives by email, but similar tricks can appear in text messages, social media messages, games, school platforms, and other online services.

A phishing message may copy a real logo, use a familiar name, or imitate the design of a genuine service. That is why appearance alone is not proof that a message is real.

This fictional bank email was created to show common clues in a phishing attempt. When you study an example, focus on the sender, the claim, the request, the link destination, and the pressure used.

This Federal Trade Commission video gives another short introduction to avoiding phishing scams.


Scams

A scam is a dishonest scheme designed to get something of value from a person. A scammer may want money, login details, personal information, gift cards, cryptocurrency, access to a device, or a verification code. Some scams are digital, while others happen by phone or in person.

Common stories include a fake prize, a fake emergency, a fake delivery problem, a fake job, a fake charity, a fake technical problem, or an impersonator pretending to be someone you trust. The story can change, but the pressure pattern is often similar: the scammer wants you to act quickly and skip normal checks.

The Federal Trade Commission presentation above explains general ways to avoid scams and stay safer online.


Social Engineering

Social engineering is the broader use of deception and psychological pressure to influence a person into taking an action that benefits the attacker. Instead of trying only to break a technical system, the attacker tries to influence a human decision.

Social engineering can use:

  1. Authority: “I am from the school office, your bank, or technical support.”
  2. Urgency: “Do this in the next five minutes.”
  3. Fear: “Your account will be closed.”
  4. Reward: “You won a prize.”
  5. Curiosity: “Look at this shocking photo.”
  6. Trust: “I am your friend using a new account.”
  7. Secrecy: “Do not tell anyone about this.”

These tactics are not proof of a scam by themselves. The important question is whether the request can be independently verified.


Common Forms of Social Engineering


Email Phishing

Email phishing often imitates a familiar service, teacher, school, store, bank, game, or online platform. The sender may ask you to “confirm” an account, open a document, reset a password, or pay an unexpected bill.

This older fictional example still demonstrates an important idea: a message can look official while leading somewhere untrustworthy. Modern phishing can be much more polished, so correct spelling and professional design do not prove that a message is genuine.


Smishing: Deceptive Text Messages

Smishing is a name for deceptive messages sent by SMS or similar text services. A common example claims that a parcel cannot be delivered unless you click a link, pay a small fee, or confirm personal details.

This fictional parcel-delivery message shows how a short text can combine urgency with a link.

A real-looking phone message can still lead to a fake login page. The safest response is usually to avoid the message link and check the claim through an official app, a bookmarked site, or a known contact method.

This family-focused video explains phishing, vishing, and smishing in simple language.


Vishing: Deceptive Voice Calls

Vishing uses phone calls or voice messages. A caller may pretend to be a bank employee, delivery company, government worker, technical-support agent, relative, teacher, or other trusted person. Caller ID can be misleading, so a familiar name or number is not enough to prove who is calling.

If a caller asks for a password, a one-time verification code, remote access to a device, or urgent payment, end the call and verify the claim using a number you already know is genuine.


Spoofing and Impersonation

Spoofing means disguising information such as a sender name, email address, phone number, or web address so that it appears to come from a trusted source. Sometimes the change is small: one letter may be replaced, added, or removed.

Impersonation is pretending to be another person or organization. A scammer may copy a profile photo, writing style, logo, or public information from social media. This is why identity should be checked through a separate trusted route when a request is unusual.


Pretexting

Pretexting is creating a believable story, or pretext, to make a request seem reasonable. For example, a person may claim to be collecting school survey information and then ask for details that the real school would not need.

Ask: Why does this person need this information? Did I expect this request? Can I check the request with the organization directly?


Tech-Support Scams

A tech-support scam tries to convince you that a device or account has a serious problem. A pop-up, call, or message may claim that a virus has been found and that you must call a number, install software, or allow remote access.

Do not trust a frightening pop-up just because it looks technical. Close the message if you safely can, do not call a number from the warning, and ask a trusted adult, teacher, or legitimate technical-support service for help.

The Federal Trade Commission video above explains how tech-support scams work and how to avoid them.


Spam Is Not Always Phishing

Spam is unwanted bulk messaging. Some spam is merely annoying advertising; some is fraudulent; and some may contain phishing links. Therefore, “spam” and “phishing” are related but not identical ideas.

A crowded inbox can make careful reading harder. Filters help, but no filter is perfect. You still need to evaluate unexpected messages.


How Scammers Influence Decisions

A scam often works by controlling your attention. Instead of giving you time to compare evidence, the message tries to push you toward one fast action.

Urgency makes waiting feel dangerous. Fear makes you focus on a possible loss. Excitement makes a reward feel more important than checking details. Authority makes a request seem difficult to question. Scarcity suggests that an opportunity will disappear. Social proof claims that “everyone” is doing something. Secrecy tries to separate you from people who might help you check the story.

These are also useful ideas in English and Media literacy. When you analyze a persuasive text, ask who created it, who the audience is, what action it wants, what emotion it creates, and what evidence supports the claim.


Red Flags to Notice

One warning sign is not always enough to prove that something is a scam. Look for a pattern.

  1. Unexpected request: You did not expect the message, call, invoice, login alert, prize, or delivery problem.
  2. Pressure tactic: You are told to act immediately or face a serious consequence.
  3. Sensitive information: Someone asks for a password, PIN, account recovery code, or one-time verification code.
  4. Unusual payment: Someone insists on a hard-to-reverse payment method or asks you to move money for “safety.”
  5. Suspicious identity: The sender address, username, phone number, or web address does not match what you expect.
  6. Unusual link: The visible text and the actual destination do not clearly match, or the site name is slightly misspelled.
  7. Unexpected attachment: You are asked to open a file you were not expecting.
  8. Secrecy: You are told not to ask a parent, guardian, teacher, friend, bank, or other trusted person.
  9. Emotional pressure: The message tries to make you frightened, excited, embarrassed, or curious before you can check.

Remember: poor spelling can be a warning sign, but perfect spelling is not proof of safety.


A Safe Response Routine

Use the following routine whenever a message feels unusual.

  1. Stop: Do not click, reply, pay, download, or share information while you are uncertain.
  2. Check: Read the sender information and request carefully. Ask what the message wants you to do and why.
  3. Verify: Contact the person or organization through a separate route you already trust. Use an official app, a bookmarked website, a known phone number, or an in-person conversation.
  4. Report: Use the platform’s report or spam function when appropriate, and tell a trusted adult, teacher, parent, guardian, or school IT contact.
  5. Delete or block: After saving any information needed for a report, remove or block the suspicious contact if appropriate.

The key idea is independent verification. Do not use the suspicious message itself to prove that the suspicious message is genuine.


Protecting Your Accounts

Even careful people can make mistakes. Good account security reduces the damage a scam can cause.

Use a long, unique password for each important account and store passwords safely. A password manager can help you avoid reusing the same password. Turn on multi-factor authentication when it is available. This adds another sign-in step, such as a code or device approval.

Never give a one-time verification code to a person who contacts you unexpectedly. A code meant to prove that you are signing in can also be valuable to someone trying to take over your account.

Keep devices and apps updated. Use screen locks. Review privacy settings. Limit public personal details that could help someone guess security answers or make an impersonation story more believable.


If You Clicked, Replied, or Shared Information

A mistake is a signal to act, not to hide. Fast reporting can reduce harm.

If you entered a password on a suspicious site, go to the real service through a trusted route and change the password. If that password was reused elsewhere, change it on those accounts too. Turn on multi-factor authentication if possible.

If you shared payment or banking information, tell a trusted adult immediately and contact the real bank or payment provider through an official channel. If you installed unknown software or gave someone remote access, stop using the device for sensitive tasks and get help from a trusted adult, school IT team, or legitimate technical-support provider.

Save useful evidence, such as the sender address, message text, date, and screenshots, but do not continue communicating with the scammer just to collect more evidence.


AI, Deepfakes, and Newer Scam Techniques

Artificial intelligence can help create polished text, realistic images, or convincing synthetic voices. This means you should not depend on grammar, image quality, or a familiar voice as your only proof of identity.

A safer question is: Can I verify this request through a second, trusted channel? For a surprising family message, call the person using a number you already know. For a school request, check with the teacher or office directly. For an account warning, open the official app or type the known site address yourself.

Deepfakes and voice cloning make verification habits more important, but the basic defensive strategy stays the same: slow down, use independent evidence, and do not let urgency replace checking.


Safe Classroom Scenario Lab

Work only with fictional examples. Do not send real phishing messages, collect real passwords, imitate real school accounts, or test classmates without permission.

Consider this fictional message:

From: School Support Team
Subject: Final warning — storage full
“Your school account will be deleted today. Sign in now using the link below to keep your files. Do not contact your teacher because the system is overloaded.”

Ask yourself:

  1. What emotion is the message trying to create?
  2. What action does it want?
  3. Which details should be independently checked?
  4. Why is the request for secrecy suspicious?
  5. What would be a safer way to verify the claim?
  6. Who should receive a report?

A strong answer explains the reasoning, not just the final decision.


Interactive Tasks


Quiz: Test Your Knowledge

What is phishing? (A deceptive attempt to make someone reveal information or take a risky action) (!A method for making a computer run faster) (!A rule for organizing email folders) (!A type of school network cable)




What is the safest response to an unexpected account warning with a link? (Open the official app or known website separately and check there) (!Click the link quickly before the warning expires) (!Reply and ask the sender if the message is real) (!Forward the link to several friends for testing)




Which choice best describes social engineering? (Using deception or pressure to influence a person into taking an action) (!Repairing damaged computer hardware) (!Designing a bridge for a community) (!Sorting files into folders)




What does smishing use most often? (Text messages) (!Printed textbooks) (!Computer fans) (!Wireless chargers)




What does vishing use most often? (Voice calls or voice messages) (!Video game scores) (!Search engine maps) (!Photo editing tools)




Why is urgency a common scam tactic? (It can push a person to act before checking the claim) (!It automatically encrypts a message) (!It proves that a sender is official) (!It makes every link safe)




What is independent verification? (Checking a claim through a separate trusted route) (!Asking the suspicious sender to confirm the same message) (!Clicking a second link in the same message) (!Reading the message several times without checking elsewhere)




Which information should you avoid giving to an unexpected caller? (A one-time account verification code) (!The name of your favorite school subject) (!A public library opening time) (!The title of a book you recommend)




What should you do after entering a password on a suspicious website? (Go to the real service through a trusted route and change the password) (!Wait several weeks to see what happens) (!Send the same password to a friend for checking) (!Post the password publicly so others know it was stolen)




Which statement about spelling in scam messages is most accurate? (A well-written message can still be a scam) (!Perfect spelling proves that a message is safe) (!Every scam contains obvious spelling mistakes) (!Spelling is the only clue that matters)





Memory Game

Phishing Deceptive messages that try to steal information or trigger a risky action
Smishing Fraudulent communication sent through text messaging
Vishing Fraudulent communication delivered through voice calls or recordings
Spoofing Disguising sender information so it appears to come from a trusted source
Pretexting Using an invented story to make a request seem believable
Verification Checking a claim through a separate trusted route
Authentication Proving that a person or device is allowed to access an account





Drag and Drop

Match the correct terms. Topic
Pause before acting Urgent request
Use an official contact route Identity check
Keep verification codes private Account protection
Tell a trusted adult or school contact Suspicious message
Change the password through the real service Exposed password




...


Crossword Puzzle

Phishing What online trick pretends to be trustworthy in order to steal information or cause a risky action?
Smishing What word describes deceptive text-message attacks?
Vishing What word describes deceptive voice-call attacks?
Spoofing What technique disguises sender information to look trustworthy?
Urgency What pressure tactic tries to make you act immediately?
Verification What process checks a claim through a trusted independent route?





LearningApps


Cloze Text

Complete the text.

A deceptive message that imitates a trusted source may be an example of

. A scammer who uses a text message may be using

. A deceptive voice call is often called

. A fake sender identity may involve

. A scammer may create

so that you act before checking. The safest way to check an unusual request is independent

. A one-time account code should be kept

. An extra sign-in step can be provided by multi-factor

. If you entered a password on a fake site, you should

it through the real service. Suspicious messages should be

to an appropriate trusted person or service.




Open-Ended Tasks


Easy

  1. Phishing Red-Flag Poster: Create a one-page poster showing five warning signs of a suspicious message and one safe response for each sign.
  2. Message Close Reading: Annotate a fictional scam message by marking its claim, target audience, emotional language, requested action, and missing evidence.
  3. Verification Script: Write a short conversation showing how a student can politely refuse an urgent request and verify it through a trusted second route.
  4. Cyber Safety Vocabulary Cards: Make illustrated study cards for phishing, smishing, vishing, spoofing, pretexting, and verification using your own clear definitions.


Standard

  1. Scam Scenario Comic: Create a six-panel comic in which a character notices pressure tactics, stops, verifies the story, reports the message, and stays safe.
  2. Trusted Channel Interview: Interview a teacher, librarian, parent, guardian, or school IT worker about how they verify unusual digital requests and summarize three useful habits.
  3. Scam Language Investigation: Compare three teacher-provided fictional messages and explain how authority, fear, reward, secrecy, or urgency is used in each one.
  4. Cyber Safety Video: Produce a one-minute video for younger students that teaches the Stop, Check, Verify, Report routine without showing real passwords, links, or account details.


Advanced

  1. School Scam-Response Guide: Design a student-friendly decision tree that begins with an unexpected message and leads to safe verification, reporting, and account-protection steps.
  2. Deepfake Verification Plan: Develop a protocol for checking an urgent voice or video message that appears to come from a family member or teacher, and justify why each check reduces risk.
  3. Phishing Awareness Study: With teacher approval, run an anonymous class survey about which warning signs students recognize, graph the results, and propose a short awareness lesson without collecting passwords or sensitive data.
  4. Digital Trust Campaign: Create a multi-format campaign with a poster, short announcement, and social-media-style graphic that teaches students how to verify surprising requests before acting.



Learning Assessment

  1. Evidence-Based Message Analysis: Analyze a fictional message and identify at least four clues, then explain which clue is strongest and why.
  2. Verification Decision: Given an unexpected request from a familiar-looking account, design a safe verification route that does not use any contact information from the suspicious message.
  3. Compare Attack Types: Explain how phishing, smishing, vishing, spoofing, and pretexting can overlap in one scam scenario.
  4. Account Recovery Reasoning: Create a response plan for a student who entered a reused password on a fake website and justify the order of the recovery steps.
  5. Persuasion and Cybersecurity: Explain how urgency, fear, authority, reward, or secrecy can influence decision-making and describe one strategy for resisting each pressure tactic.
  6. Transfer Challenge: Apply the Stop, Check, Verify, Report routine to a new scenario involving a game account, delivery message, school notice, or family emergency claim.




Evidence of Learning

  1. Knowledge: You can accurately explain phishing, scams, social engineering, smishing, vishing, spoofing, pretexting, verification, and multi-factor authentication.
  2. Skills: You can inspect a suspicious request, identify persuasion tactics, choose a trusted verification route, protect sensitive information, and report concerns appropriately.
  3. Products: You can create clear safety materials such as annotated examples, posters, comics, decision trees, videos, surveys, or awareness campaigns.
  4. Transfer: You can apply the same reasoning to unfamiliar messages, new platforms, AI-assisted impersonation, voice calls, school accounts, games, shopping, and social media.




OERs on the Topic


Useful open and public educational resources include:

  1. CISA: Recognize and Report Phishing: Practical guidance on recognizing suspicious messages and checking them safely.
  2. Federal Trade Commission: How to Recognize and Avoid Phishing Scams: Consumer-focused explanations of phishing signs, prevention, response, and reporting.
  3. FBI: Spoofing and Phishing: Explanations of spoofing, phishing, vishing, smishing, and protective habits.
  4. Wikimedia Commons: Phishing: Freely licensed images and media related to phishing.
  5. Wikipedia: Social engineering in security: Background reading about manipulation techniques used to influence people.


Linked Learning Areas

This topic connects English reading skills with computer science and personal safety. You use close reading to identify claims and persuasive language, media literacy to evaluate sources and identities, computer science concepts to understand account security, and citizenship skills to make careful decisions and report harmful behavior.


aiMOOC Projects