Beginner Module B9

Phishing and Social Engineering Defense

Learn how manipulation works, inspect suspicious communication safely, verify through trusted channels, report useful evidence, and recover after possible interaction.

Module Snapshot

TrackHigh School Beginner
ModuleB9 of 15
Lessons7
Module Test25 questions

Module Mission

Recognize manipulation, verify safely, and report clearly.

Phishing is not limited to email. Deceptive requests can appear through texts, calls, direct messages, social posts, fake support chats, QR codes, links, attachments, and account alerts. Students will learn a consistent defensive process without engaging with suspicious content.

Safety Reminder

Every sender, message, account, call, link, attachment, QR code, website, and support request in this module is fictional. Students should not open suspicious content, contact suspicious senders, or submit real passwords, codes, payment details, or private information.

Visual Framework

The phishing-defense workflow

Strong defenders pause, inspect the evidence, verify through a separate official channel, report correctly, and recover any affected accounts or devices.

1

Pause

Stop before clicking, replying, calling, downloading, approving, paying, or sharing information.

2

Inspect

Review sender identity, wording, pressure, request, destination, attachment, context, and whether the message was expected.

3

Verify

Use a separate official website, known number, school portal, directory, teacher, guardian, or technology team.

4

Report

Preserve safe details and use the approved reporting process without forwarding dangerous content.

5

Recover

Secure credentials, MFA, recovery settings, sessions, devices, and connected accounts when interaction may have occurred.

Fake Message Panel

Communication Review Events

Fake Data
EmailUnknown sender claims the school account expires todayPause and verify
TextDelivery message requests payment through a shortened linkDo not engage
CallFake support agent requests an MFA codeEnd and report
SocialImpersonated friend requests emergency moneyVerify separately

This panel is fictional. Students inspect displayed evidence only and never open links, answer calls, download files, scan codes, or contact suspicious accounts.

Learning Path

B9 Lessons

Each lesson uses fictional messages, calls, support requests, links, files, evidence panels, and reporting scenarios to build safe phishing-defense judgment.

B9.1

Lesson 1

How Social Engineering Manipulates People

Study how urgency, fear, trust, curiosity, authority, scarcity, and rewards can influence decisions.

Safe Lab

Analyze fictional persuasion attempts and identify the emotion, pressure tactic, target action, and safest pause point.

Open →

B9.2

Lesson 2

Phishing Email Warning Signs

Inspect sender details, subject lines, wording, requests, links, attachments, and context without engaging with suspicious content.

Safe Lab

Review fake email panels and classify evidence as normal, suspicious, or report-first.

Open →

B9.3

Lesson 3

Smishing, Vishing, and Social Media Scams

Compare deceptive text messages, phone calls, direct messages, posts, and account-recovery scams.

Safe Lab

Evaluate fictional mobile, phone, and social-platform scenarios using safe verification choices.

Open →

B9.4

Lesson 4

Impersonation and Fake Support Messages

Recognize copied identities, fake authority, support impersonation, account warnings, and requests for credentials or codes.

Safe Lab

Compare fake support conversations and choose a separate official verification channel.

Open →

B9.5

Lesson 5

Safe Link and Attachment Judgment

Judge links and attachments by source, context, destination clues, file identity, security warnings, and expected purpose.

Safe Lab

Sort fictional links and files without opening, scanning, forwarding, uploading, or testing them.

Open →

B9.6

Lesson 6

Reporting Workflows and Trusted Help

Learn how to preserve safe evidence, write a useful report, choose the correct trusted contact, and secure an account after interaction.

Safe Lab

Build a fictional phishing report with timeline, evidence, immediate actions, escalation, and follow-up.

Open →

B9.7

Lesson 7

Phishing Defense Lab

Apply manipulation, email, text, call, social media, impersonation, link, attachment, and reporting skills.

Safe Lab

Complete a multi-stage fictional phishing incident and produce a defender recommendation.

Open →

Objectives

By the end, students can:

Explain how social engineering uses emotion, trust, authority, urgency, scarcity, and rewards.

Inspect fictional email, text, phone, social media, link, and attachment evidence safely.

Recognize impersonation, fake support, credential requests, and verification-code requests.

Verify suspicious requests through separate official channels without engaging with the suspicious source.

Create clear reports and choose trusted help after suspicious interaction or possible credential exposure.

Module Assessment

B9 Module Test

The module ends with a 25-question scored test covering phishing indicators, manipulation tactics, email clues, smishing, vishing, social media scams, impersonation, fake support, safe link and attachment judgment, reporting workflows, trusted help, and fictional message analysis. Answers and explanations remain hidden until submission.

Open Module Test →