- Fulfills Step 5 of GSUSA Junior Cybersecurity Investigator badge requirements.
- Fulfills Step 2 of GSUSA Cadette Cybersecurity Investigator badge requirements.
Info Needed for badge requirements: Phishing is when cyber criminals try to trick you into sharing private information, like passwords, addresses, or credit card numbers. They create fake messages that look real, such as emails, texts, or posts on social media. These messages often try to get you to click on bad links, download harmful attachments, or share your personal details.
Phishing messages often:
- Create a sense of urgency (e.g., “act now”).
- Play with emotions to make you worried or excited.
- Use small clues, like bad grammar or fake links, that give away they are not real.
To protect yourself:
- Always think before you click.
- Never share private information like passwords or payment details through email.
- If you get a message from a company, don’t click on links in the email. Instead, open a browser and go directly to the company’s website to log in.
Items Needed
- VTK Phishy Messages for each team of two scouts (Sample Message 1 is fake, Sample Message 2 is real, pre-cut them so you can give them one message at a time)
- VTK Is It Phishy by GSUSA, one for each team of two scouts
- Highlighter, one for each team of two scouts
Instructions
- Divide scouts into pairs. Give each team a copy of Is It Phishy, the first sample message, and a highlighter.
- Scouts use the checklist to spot anything suspicious in the first sample message, highlighting any problems they find.
- After analyzing the first message, each team shares what they found with the group.
- Give teams the second sample message and ask them to compare it to the first one. Scouts determine which one is a scam and explain why using the checklist.
- Discuss together:
- Which message was a scam? (Answer: Sample Message 1 is a scam, Sample Message 2 is real.)
- What clues on the checklist helped identify the scam? Examples: Spelling mistakes, offers that are too good to be true, requests for private information, urgent language, or attachments to click.
Phishing Checklist
- Does the email have spelling mistakes? Fake emails often contain misspellings or grammar errors.
- Is the email offering something too good to be true? Scammers might claim you can get free electronics or other expensive items. They often use phrases like, “Act now, it’s free!”
- Does the email look like an advertisement? If it’s making an offer that seems like an ad, it’s likely spam.
- Is the email asking for private information? Never share personal details, like passwords or financial information, through email.
- Is the email marked as “urgent” or threatening something? Scammers often pressure you with words like, “You must act now!” or “Urgent!”
- Does the email include an attachment? Never open attachments unless you know the person who sent the email and trust them.
Other Sample Message
Sample Message #3 (Real Email):
Subject: Troop Cookie Sale Reminder
Hello Scout!
We wanted to remind you about the upcoming troop cookie sale this weekend. Please bring your assigned cookie box and any materials you need. Let’s make this year’s sale the best ever!
See you soon,
Your Scout Leader
Sample Message #4 (Scam Email):
Subject: You’ve Won a Free Trip!
Congratulations, Scout!
You’ve been selected to win a FREE trip to a theme park! To claim your prize, just send us your private details like your name, address, and phone number.
Hurry—this offer ends today!
Click the link below:
http://faketripoffer.com
Best regards,
Vacation S.
Sample Message #5 (Real Email):
Subject: Important Troop Announcement
Hi Scout!
There’s a change to our meeting location this week. We will now meet at the library instead of the park. Please bring your troop binder and water bottle as usual.
Thanks,
Scout Leader
Sample Message #6 (Scam Email):
Subject: Free Video Games for Scouts!
Hey Scout,
We’re giving away free video games to anyone who signs up with their private info! Don’t miss this chance to get games for free—just click the attachment and tell us your email password to claim your prize!
http://scammysite.com
Thank you,
Game Surfers