Passwords, phishing and your privacy settings
One weak password or one clicked phishing link can cause real damage.
Live demo: teacher goes to haveibeenpwned.com and enters a generic example email. Show students that millions of passwords are already known. "This is what you're up against."
Students work through a phishing detection challenge: given 6 emails/messages, annotate each one identifying legitimate vs phishing, with evidence. Then they create a "Phishing Warning Card" for a younger sibling (visual, clear, useful). Finally, they audit their own social media privacy settings (or a fictional account) using a checklist.
Display the best phishing warning cards. What made them effective for the audience?
AI is increasingly used to make phishing emails more convincing — grammatically perfect, personalised. The red flags are getting harder to spot.
Annotated phishing examples + phishing warning card (exported)
Audit one account you use. Change the password to a passphrase. Enable MFA if possible. Write a short note: what did you change and why?
Phishing checklist with explicit clues to look for
Research the most expensive cyberattack in UK history. What was the human error that allowed it? What could have prevented it?