How do I use this pack?
The teacher pack complements the main page in teacher mode with everything you need to print. It is built so that you can print it once and reuse it for years. The topic is online safety & scams within media and digital literacy, prepared for lower secondary (Years 6–9).
Recommended sequence
- Preparation: First read through the main page in teacher mode. For each chapter it gives you learning goals, timing, discussion prompts and quiz answers. The interactive “Spot the scam” game works beautifully on the projector.
- Print the material: Print the worksheets that follow here (ideally one per student minus one, with one held in reserve). Print the parent letter as a class set.
- In the lesson: Follow the lesson overview below. The worksheets serve as an activity, not a test.
- Assessment: Optional class test at the end of the unit. Grade using the included rubric.
What's included?
- Lesson overview & learning goals — double lesson and weekly module, with Bloom competence levels.
- 5 worksheets — analyse a phishing email, password strength, match the scams, act safely, scam radar (synthesis). With an answer key directly underneath.
- Class test — 32 points across the whole unit, with a grading rubric.
- 15 homework tasks — tasks per topic in 3 difficulty tiers.
- Parent letter — a template to adapt, including notes on protecting seniors in the family and neighbourhood.
- Curriculum overview — mapped to Austrian, German and Swiss educational standards.
Printing tips
- Press Ctrl+P (Windows) or ⌘+P (Mac). In the print dialog you can also choose “Save as PDF”.
- When printing, the navigation and background colours are hidden — the result works in black and white.
- Each worksheet starts on a new page. You can select individual pages in the print dialog.
- The answer keys sit in a green-bordered box directly under each worksheet — cut them off before printing the class set, or select only the student pages.
Lesson overview & learning goals
The unit can be used flexibly. The double lesson is the quickest route; the weekly module allows more practice and the final test.
Overarching learning goals
By the end of the unit, students can …
- … recognise phishing messages by their typical features and check link destinations before clicking.
- … create a strong, unique password (passphrase) and explain why reusing one is dangerous.
- … name the most common scams (phishing, smishing, shock call, fake shop, romance scam, crypto/investment fraud, job/advance-fee fraud) and their warning signs.
- … synthesise today's scams into their invariant structure (pressure or too-good-to-be-true + an immediate payment/code/data request) and apply the rule “Stop – Check – Call back”.
- … explain protective habits (updates, 2FA, backups, screen lock) and their benefit.
- … act calmly and step by step if something goes wrong, and seek help.
- … pass on their knowledge — especially to older relatives, who are more often targeted by scams.
Competence levels (Bloom's taxonomy)
| Level | Label | Example from this unit |
|---|---|---|
| L1 | Knowledge | Name the warning signs of a phishing email; reproduce terms (2FA, passphrase, smishing) |
| L2 | Comprehension | Explain why reused passwords are dangerous; what the padlock symbol means |
| L3 | Application | Build your own passphrase; complete the “Spot the scam” game; check a link destination |
| L4 | Analysis | Systematically take a phishing email apart; match scams to their features |
| L5 | Evaluation | Justify your own position on “How do I help my grandparents?” |
| L6 | Creation | Design an awareness message/poster for older people |
Variant A — double lesson (90 min)
| Time | Phase | Content & method |
|---|---|---|
| 10 min | Warm-up | Prompt: “What would happen if someone had your most important password?” — board brainstorm. |
| 15 min | Passwords & logins | Chapter 2 on the projector. Build a strong passphrase together. Worksheet 2 (password strength). |
| 15 min | Scams | Chapter 3: the most common scams and their psychology. Worksheet 3 (match). |
| 20 min | Practice | Chapter 4 “Spot the scam” on the projector + the phishing checklist. Worksheet 1 (analyse a mail). |
| 15 min | Scam radar | Chapter 5: today's scams — the Stop–Check–Call-back rule, structural rather than content tells. Worksheet 5 (scam radar). |
| 10 min | Safe habits | Chapter 6: updates, backups, Wi-Fi, screen lock, permissions. |
| 10 min | Closing | Chapter 7: the emergency plan. Discussion “calm, not anxious” + homework. |
Variant B — weekly module (3 × 50 min)
- Lesson 1: Passwords, logins, 2FA & passkeys (Ch. 2) — Worksheet 2.
- Lesson 2: Scams, “Spot the scam” & the scam radar (Ch. 3–5) — Worksheets 1, 3 & 5.
- Lesson 3: Safe habits & the emergency plan (Ch. 6–7) — Worksheet 4 + class test.
Worksheets
Each worksheet suits about 15–20 minutes of individual or pair work. The answer key is in a green box directly underneath — cut it off before printing the class set, or print double-sided (student side at the front, answer key at the back — do not hand to students).
Worksheet 1 — Analyse a phishing email
Read the following (made-up) email closely. It contains several warning signs.
1 Dear Customer,
2 we have detected unusual activity. Your account will be suspended within 24 hours!
3 For security reasons we kindly ask you to verifie your details immediately.
4 👉 [ Confirm account now ] (link points to: http://customer-login.yourbnak-security-uk.info/verify)
5 To do so, confirm your PIN and one-time code, plus £1.00 by gift card.
6 Kind regards, Your Bank
1. Find the warning signs (6 points)
Mark them in the text and note them here: which six warning signs can you spot? For each, write the line and the feature.
2. The link (2 points)
Why is the link in line 4 suspicious — even though it says “Confirm account now”?
3. Reacting correctly (2 points)
What is the safest way to log in to the real bank instead of following this link?
4. Transfer (2 points)
Some phishing emails today are written without any mistakes. Name two warning signs that still work even then.
Total points: ___ / 12
🔑 Answer key for teachers — Worksheet 1
1. Six warning signs: (L1) impersonal greeting “Dear Customer” · (L2) time pressure/threat “suspended within 24 hours” · (L3) spelling mistake “verifie” · (L4) fake link (destination differs, unfamiliar domain) · (L5) request for PIN/one-time code and payment by gift card · plus, in the header, the fake sender address “yourbnak-security-uk.info” (typo + unusual ending). Accept 6 plausible answers.
2. The displayed text and the real destination do not match. The link points to an unfamiliar address (not the official bank domain). You can tell by hovering over the link (without clicking) and reading the destination in the status bar.
3. Do not click the link. Instead use the official banking app, or type the bank's address yourself from a saved bookmark in the browser. When in doubt, call the bank on its known phone number.
4. Even with flawless text, these stay suspicious: the sender address/domain, the real link destination, the artificial time pressure, the request for credentials and the unusual payment method. (Any two will do.)
Worksheet 2 — How strong is a password?
1. Ranking (3 points)
Order the following passwords from 1 = weakest to 5 = strongest:
a) 123456 | Rank: ____ |
b) Lena2011 (name + birth year) | Rank: ____ |
c) P@ssw0rd! | Rank: ____ |
d) Tiger-Cloud-Coffee-7-Moon (passphrase) | Rank: ____ |
e) xK9 | Rank: ____ |
2. Justify (2 points)
Why is a long passphrase (d) stronger than P@ssw0rd! (c), even though c has special characters?
3. Build your own passphrase (2 points)
Make your own strong passphrase from at least four random words. (Do not use your real password!)
4. Reusing passwords (3 points)
Tom uses the same password for his gaming account, his email and an online shop. The online shop is hacked. Explain what danger now arises for Tom's other accounts.
5. Protective tools (2 points)
Explain in one sentence what a password manager does — and in one sentence what two-factor authentication (2FA) does.
Total points: ___ / 12
🔑 Answer key — Worksheet 2
1. A sensible order: a (1) – 123456 is the most-cracked password of all · e (2) – only 3 characters, tried instantly · b (3) – name + year is easy to guess/research · c (4) – short, but with special characters; a well-known pattern · d (5) – long passphrase, strongest. (Accept e and a swapped, as both are very weak.)
2. Length beats complexity: every extra character multiplies the possibilities. A passphrase of 4–5 random words is much longer and therefore has more “entropy” than a short password with special characters. P@ssw0rd! is also a well-known pattern (letters swapped for symbols) that attacker programs already know.
3. Accept: any phrase of ≥ 4 random, unrelated words (bonus: a number or a separator). Reject: song lyrics, proverbs, “I love you” — too predictable.
4. In credential stuffing, scammers automatically try the leaked email/password pair across many other services. Because Tom uses the same password everywhere, they can get into his email too (especially dangerous, since passwords get reset via it) and his gaming account. Solution: a separate password for every service.
5. Password manager: an encrypted vault that creates and stores a separate strong password for every service — you only remember one master password. 2FA: in addition to the password, a second proof is required (a code from your phone or a fingerprint), so a stolen password alone is not enough.
Worksheet 3 — Match the scams
1. Connect each scam to its description (5 points)
Draw lines (or write the letters in the brackets):
| a) Phishing email | ( ___ ) Text message “Your parcel is waiting, please pay customs” with a link |
| b) Smishing | ( ___ ) Call: “Grandma, I've had an accident, I need money right now!” |
| c) Shock call / grandparent scam | ( ___ ) Email pretending to be from your bank |
| d) Fake shop | ( ___ ) An online acquaintance who, after weeks, suddenly needs money |
| e) Romance scam | ( ___ ) Brand-name trainers at half price, prepayment only, no company details |
2. The shared lever (3 points)
Almost all scams want to achieve the same thing. Which feeling do they exploit, and what are you meant to do? Name the common trick.
3. Your counter-strategy (2 points)
You receive a message that pressures you. What is the one thing that exposes almost any scam?
4. Practise a shock call (2 points)
Someone calls and claims a relative is in trouble and needs money immediately. Describe in note form what you do.
Total points: ___ / 12
🔑 Answer key — Worksheet 3
1. b → text message with a parcel link · c → shock call “Grandma, accident” · a → bank email · e → online acquaintance asking for money · d → brand-name trainers, prepayment, no company details.
2. They exploit feelings — above all fear, time pressure, pity or greed (too good to be true). The common trick: you are meant to act immediately and without thinking. This is called social engineering — the person is manipulated, not the technology.
3. Pause. Take a breath, don't act at once, and check via an independent route (open the site yourself, ask the real person/organisation on their known number). Pressure is always the signal to stop.
4. Accept: hang up · take a breath · call the person back on their known number · hand over no money or valuables · talk to someone you trust. Important: real relatives and real authorities never pressure anyone like this.
Worksheet 4 — Behaving safely and acting if something goes wrong
1. Good habits (4 points)
Connect each habit to the reason it protects you:
| a) Install updates | ( ___ ) saves photos & files, even against ransomware |
| b) Make backups | ( ___ ) protects accounts if the phone is lost |
| c) Screen lock | ( ___ ) closes security holes that attackers use to get in |
| d) Check app permissions | ( ___ ) stops apps from needlessly accessing location/camera |
2. The padlock symbol (2 points)
What does the padlock symbol in the browser's address bar mean — and what does it not mean?
3. Emergency plan (3 points)
You have accidentally entered bank details on a scam site. Name the first three steps in the correct order.
4. Protect others (3 points)
Your grandmother tells you about a “bank text message” she received. How do you help her without making her anxious? Write 2–3 sentences.
Total points: ___ / 12
🔑 Answer key — Worksheet 4
1. a → closes security holes · b → saves photos & files (even against ransomware) · c → protects accounts if the device is lost · d → stops needless access to location/camera.
2. The padlock means: the connection is encrypted (HTTPS), and the data can't be read along the way. It does not mean the site is genuine or trustworthy — scam sites can have a padlock too. You also have to check the address (domain).
3. 1) Call the bank immediately and have your account/card blocked. 2) Change passwords, ideally from a different, clean device (email and bank first). 3) Report it to the police (online or by phone) and secure the evidence (screenshots). Also: tell someone you trust.
4. Accept: respond calmly and warmly (“good that you're asking, this happens to many people”), look at the text together, do not tap the link, call the real bank number from the card/statement, explain the checklist to her. Full marks: no blame, concrete help, the reminder “when in doubt, contact the site/organisation yourself”.
Worksheet 5 — Scam radar (today's scams)
In Chapter 3 you met individual scams. This is not about one more scam, but about the shared pattern: no matter what a scam message looks like, the structure is almost always the same. Whoever spots the structure also sees through scams they have never seen before.
1. Match the scam to its channel (4 points)
Write the matching letter in the brackets. Which current scam is behind each description?
| a) Parcel/customs text (smishing) | ( ___ ) An app chat promises “a guaranteed 18% profit per month”; the portfolio rises, but to withdraw you must first pay “15% tax” |
| b) Crypto/investment fraud (pig butchering) | ( ___ ) “Your parcel is waiting, please pay a £2.99 customs fee” — a short, unfamiliar web address, a 48-hour deadline |
| c) Job/advance-fee fraud | ( ___ ) Brand-name trainers for £39 instead of £189, a countdown running, prepayment only, “company details on request” |
| d) Fake shop | ( ___ ) A well-paid work-from-home job that first asks you for a “deposit for equipment” |
2. Stop-rule cloze (4 points)
Fill the gaps with the matching words from the box:
Word bank: pause · pressure · yourself · code · hang up · second
If a message applies _______________ or sounds too good to be true and at the same time wants an immediate payment, a _______________ or your data: _______________, _______________, and check it via a _______________ channel you chose _______________.
3. Three-step memory aid (2 points)
The short formula is Stop – Check – Call back. Explain in one sentence each what you concretely do at every step.
4. Which tell disappears because of AI? (2 points)
Scams used to give themselves away through clumsy spelling. Why does that feature help less today — and which structural warning signs do you rely on instead? Name two.
Total points: ___ / 12
🔑 Answer key — Worksheet 5
1. b → app chat “18% guaranteed” + “tax up front” (pig butchering) · a → parcel/customs text with a short, unfamiliar address · d → brand-name trainers, prepayment, no company details (fake shop) · c → work-from-home job that first asks for a “deposit” (job/advance-fee fraud).
2. “If a message applies pressure or sounds too good to be true and at the same time wants an immediate payment, a code or your data: pause, hang up, and check it via a second channel you chose yourself.”
3. Stop = don't react at once, take a breath, deliberately ignore the artificial time pressure. Check = verify the request independently (open the site/app yourself, not the supplied link). Call back = contact the real person/organisation on the known number — not the number in the message.
4. AI text is now usually flawless, so the “spelling tell” falls away. What still holds are the structural tells (any two): artificial time pressure / pressure · an unexpected, unfamiliar link or channel · the demand for an immediate payment, code or credentials · a channel through which the request cannot be confirmed. Teaching note: this is the synthesis lesson — it draws the individual scams from Chapter 3 together into one decision rule, rather than repeating them.
Class test — final assessment
Duration: 45 min · Points: 32 · Grade: per rubric below
The test does not fit into a 90-minute double lesson — recommended as its own lesson at the end of the weekly module (3 × 50 min).
Part A: Multiple choice 1 pt each · 6 pts
1. Which password is the safest?
123456- Your first name and birth year
- A passphrase made of several random words
abc123
2. How do you best recognise a phishing email?
- It has an image attached
- An impersonal greeting, time pressure and a link whose destination differs
- It is written in your language
- It arrives at the weekend
3. What does two-factor authentication (2FA) do?
- It makes the password twice as long
- It requires a second proof in addition to the password
- It stores the password in the browser
- It encrypts the hard drive
4. What does the padlock symbol in the address bar mean?
- The site is guaranteed genuine and reputable
- The connection is encrypted (HTTPS)
- The site is free of charge
- The site has no adverts
5. Which demand is a clear scam alarm signal?
- “Please log in via the app.”
- “Pay with gift cards.”
- “Update your operating system.”
- “Save your invoice as a PDF.”
6. What is a passkey?
- A particularly long password
- A passwordless sign-in via fingerprint/face that cannot be phished
- A spare key for the front door
- A code that arrives by text message
Part B: Short answer 2 pts each · 8 pts
7. Name two features by which you recognise a phishing email:
8. Why should you use a different password for every service?
9. What is the most effective reaction when a message puts you under time pressure?
10. Why does a backup help against ransomware?
Part C: Application 12 pts
11. You receive this text message: “Courier: your parcel could not be delivered. Pay a £1.99 customs fee: http://parcel-status-uk.info”. Explain why this is suspicious, and what you do (4 pts):
12. You have accidentally entered your bank password on a fake site. Describe the first three steps in the correct order (4 pts):
13. Scam radar: A parcel text, a fake shop and a crypto “investment” look completely different. Name the shared pattern that connects almost all of today's scams, and describe the three-step rule you use to stop any of them (4 pts):
Part D: Reflection 6 pts
14. Write 5–8 sentences: “How would I explain to my grandparents how to protect themselves from scams online?” Name at least three concrete tips and explain why older people are especially often targeted by scams.
🔑 Answer key for teachers — class test
Part A: 1c · 2b · 3b · 4b · 5b · 6b
Part B:
7. Two of: fake sender address · impersonal greeting · time pressure/threat · fake link (destination differs) · request for PIN/one-time code/password · spelling mistakes · unusual payment method.
8. If one service is hacked, scammers automatically try the leaked password across other services (credential stuffing). With unique passwords, the damage stays limited to that one account.
9. Pause — don't act at once, take a breath and check via an independent route (open the site yourself / ask the real organisation).
10. Ransomware encrypts the files. With a current, separate backup you can simply restore the data and don't have to pay a ransom.
Part C:
11. An ideal answer includes: an unexpected text with a link (smishing) · the suspicious domain “parcel-status-uk.info” (not the real courier) · real couriers don't ask for a “customs fee” via a text link · a payment/data request. Reaction: don't tap the link, open the courier's official app or website yourself, delete/report the message. Points: 2 for the reasoning, 2 for the correct reaction.
12. 1) Call the bank, block the account/card. 2) Change the password from a clean device (email/bank first). 3) Report it to the police and secure the evidence. About 1.3 pts per correct step in the right order; the note “tell someone you trust” as a bonus.
13. Shared pattern (2 pts): they all want you to act immediately — with a payment, a code or data — over a channel you cannot check independently; they create pressure or a “too good to be true” promise. Rule (2 pts): Stop (don't react, take a breath) – Check (open the site/app yourself, not the link) – Call back (the real organisation on the known number / a second channel you chose yourself). Bonus: recognises that the structure is what matters, not the outward appearance.
Part D:
14. Full marks: ≥ 3 concrete, correct tips (e.g. don't click links in emails/texts; never hand out a PIN/one-time code; when in doubt, hang up and call back; the banking app instead of a link; talk to someone) and a plausible reason why seniors are targeted more often (less routine with technology, more trust in “authorities”, often deciding alone, a sense of shame). The assessment rewards clarity and a respectful, empowering tone — not a particular opinion.
Grading rubric
| Points | Grade (DE/AT) | Grade (CH) | Descriptor |
|---|---|---|---|
| 29 – 32 | 1 / Very good | 5.5 – 6.0 | Full understanding, confident application, independent and empowering reflection. |
| 25 – 28 | 2 / Good | 4.5 – 5.0 | Secure knowledge, minor gaps, reflection present. |
| 20 – 24 | 3 / Satisfactory | 3.5 – 4.0 | Warning signs understood in principle, application superficial. |
| 15 – 19 | 4 / Sufficient | 3.0 – 3.4 | Key terms in place, many gaps in application. |
| 0 – 14 | 5 / Insufficient | < 3.0 | Basic rules not understood — revision recommended. |
The DE/AT 1–5 and Swiss 6–1 scales are given as a guide; map the point bands to your own school's grading scheme (e.g. UK GCSE 9–1, US letter grades, percentages) as needed.
Weighting recommendation
- Knowledge (Parts A + B): 14 pts — assessable with a clear right/wrong line.
- Application (Part C): 12 pts — room for partial marks per task (incl. the scam-radar synthesis).
- Reflection (Part D): 6 pts — the depth of argument and a respectful tone are assessed, not a particular position.
Homework collection — 3 difficulty tiers
Three tasks per topic: Easy Medium Challenging. Answer hints are in fold-out details directly underneath (collapsible on screen, always open when printed).
Passwords & logins
Invent three of your own passphrases, each from four random words. Write them down and underline the one you can remember most easily. (Do not use your real passwords!)
🔑 Answer hint
Accept: three phrases of ≥ 4 random, unrelated words. The aim is the insight: long + random + still memorable.
Find out how to switch on two-factor authentication for one service you use (e.g. an email provider or a game). Describe the steps in 3–5 sentences.
🔑 Answer hint
Accept: a documented route via Settings → Security → 2FA / two-step verification. Bonus: mentions the difference between an app code and a text message (an app is safer).
Research what a “data breach” is and what services like Have I Been Pwned do. Write half a page: how can you check whether one of your email addresses is affected, and what do you do then?
🔑 Answer hint
Full marks: data breach explained correctly (credentials are stolen) · HIBP checks an email against known breaches · the consequence: change affected passwords at once, use unique passwords + 2FA everywhere. Bonus: mentions that the password itself never has to be entered/transmitted.
Phishing & scams
Create a small “warning-sign checklist” (6 points) for a phishing email that you could pin above your desk.
🔑 Answer hint
Accept: sender · greeting · time pressure/threat · check the link · data request · spelling (also: unusual payment). Bonus: designed poster-style.
Play through “Spot the scam” (Chapter 4). Afterwards, write your own made-up phishing email with at least four warning signs — and mark them.
🔑 Answer hint
Accept: a made-up email with ≥ 4 clearly marked warning signs. Full marks: realistic and each sign named correctly. Important: don't copy real brands/people.
Interview an adult around you: have they ever been the target of a scam attempt (email, text, call)? How did they react? Write a mini report (max. 400 words) and add what you would advise them for the future.
🔑 Answer hint
Accept: a documented interview + your own analysis + concrete advice. Full marks: respectful handling (no exposing the person), linked to the warning signs that were learned.
Scam radar — today's scams
Write the three-step rule “Stop – Check – Call back” on an index card and explain, in one sentence each, what you do at every step. Put it up where you'll see it.
🔑 Answer hint
Accept: Stop = don't react at once, take a breath · Check = open the site/app yourself rather than the link · Call back = the real organisation on the known number / a second channel you chose yourself. The aim is to anchor the rule, not the exact wording.
Collect (with permission) one real suspicious message from around you — or invent one for a current scam (parcel text, fake shop, crypto “investment”, job offer). Take it apart using the scam radar: which pressure/promise, which channel, which demand (payment/code/data)?
🔑 Answer hint
Full marks: all three structural elements named correctly + the note that the outward appearance is interchangeable while the structure stays the same. Don't copy real brands/people; defuse links to hxxp.
“Explain it to your grandparents”: Teach an older person the scam radar — not a single scam, but the shared pattern and the rule “Stop – Check – Call back”. While you're at it, agree on a family code word for supposed emergency calls. Afterwards, write down: what was easy, what was hard to explain, what helped?
🔑 Answer hint
Full marks: a documented mini coaching with honest reflection that conveys the pattern (not just one scam), agrees the code word, and is respectful and patient. This is the transfer crown task of the chapter — knowledge is anchored in the family. Note on AI voices: how scammers imitate voices with AI (voice cloning) is explained on the sister site Understanding Deepfakes — here it is enough to note that the code word is exactly what protects against it.
Safe habits
Check on your own device (with permission): are automatic updates on? Is a screen lock set? Note down what you found and changed, if anything.
🔑 Answer hint
Accept: a documented self-check. The goal is practical implementation — the reflection is assessed, not the device.
Look at the app permissions of three apps on a device. Which permission surprised you? Explain the principle “as few rights as necessary” using an example.
🔑 Answer hint
Example: “a torch app wants location” → unnecessary, revoke it. Full marks: the principle of least privilege explained correctly + one concrete example.
Explain the “3-2-1 rule” for backups and design a concrete backup plan for your most important photos and documents (which media, how often?). Half a page.
🔑 Answer hint
3-2-1 = three copies, two different media, one off-site/offline. Full marks: the rule correct + a realistic, workable plan. Bonus: explains why this helps against ransomware.
Protecting others / seniors around you
Write your personal “5 golden rules for online safety” large enough to put up on a wall.
🔑 Answer hint
Accept: any rules that show real understanding — e.g. “no links from emails”, “never hand out a PIN/one-time code”, “when in doubt, pause”, “unique passwords + 2FA”, “updates & backups”.
Design a small poster (one A4 sheet or digital) for older people: “How to recognise a shock call.” Audience: grandparents.
🔑 Answer hint
Full marks: clear, large type, no jargon, a concrete action (“hang up, take a breath, call back on the known number”). Respectful, not preachy.
Teach an older person (a grandparent, a neighbour) how to check link destinations and, when in doubt, contact the real bank/organisation themselves. Afterwards, write down: what was easy, what was hard to explain? What helped?
🔑 Answer hint
Accept: a documented “mini coaching” with honest reflection. Full marks: patience and respect evident, one concrete bit of progress for the person described. This is the most valuable task in the unit — knowledge is passed on.
Parent-letter template
You can adapt this template to your school and class. Replace the [placeholders in grey] with your own details and print the template for your class.
[Your school]
[Address]
[Date]
To the parents of class [Year X]
Subject: Teaching unit “Safe Online — passwords, phishing & scams”
Dear parents,
over the coming [weeks / double lesson], your child's class will be working on the topic of online safety. The aim is to enable your children to move around online calmly and competently — without fear, but with an alert eye for typical traps.
What your child will learn:
- What a strong password looks like and why you never reuse one.
- What two-factor authentication and password managers are.
- How to recognise phishing emails, scam texts and shock calls.
- Which habits protect you (updates, backups, screen lock).
- How to act calmly and step by step if something goes wrong.
Material and source: We use the freely available learning platform sicher-im-netz.webhoch.com, provided by the Austrian Webagentur Hochmeir e.U. under a free licence (CC BY 4.0). The content is prepared in an age-appropriate way for [Year 6/7/8/9]. All example messages, names and addresses are entirely fictitious.
How you can support at home:
- Talk with your child about suspicious messages that you receive yourself — looking at them together sharpens the eye.
- Agree on a simple family rule: “When there's pressure and haste, pause first and ask.”
- Consider a family code word for a supposed emergency call (a “shock call”) — real relatives can say it.
- Never reveal personal data (passwords, PIN/one-time codes) over the phone or via links in emails/texts.
Especially important: protecting older relatives. Seniors are targeted by scams at an above-average rate — above all in shock calls (the “grandparent scam”), fake bank messages and at the front door. We expressly encourage the children to pass their knowledge on to grandparents and older neighbours. You can help at home by raising the topic together and agreeing: when in doubt, hang up, take a breath and call the person concerned, or the real bank, back on the known number. No one should feel ashamed of a scam attempt — talking about it is the best protection.
A family code word against the shock call. Agree on a simple secret code word within the family. Anyone who can't say the word during a supposed emergency call is not the real relative — just hang up and call back on the known number. Scammers can now imitate voices with artificial intelligence convincingly (“voice cloning”); the code word protects against exactly that. How this voice forgery works technically is explained, in plain terms, on our sister site Understanding Deepfakes — here it is enough to know that a familiar voice on the phone is no longer proof of identity today.
Notes on media use:
- Many online services and apps have an age limit (often 13+ or 16+). Please check the terms of use.
- In lessons we work with made-up examples [supervised / as a demo on the projector]; no real student credentials are entered.
- For questions or concerns: [Your email address]
We are glad that your child is gaining this important everyday skill — and we appreciate your support along the way.
Kind regards,
[Your name]
[Role / class teacher]
Curriculum mapping
This unit covers central strands of media and digital literacy. The point bands and references can be adapted to your own setting; the table below maps to Austrian, German and Swiss educational standards as a worked example, and the strands (online safety, privacy, responsible media use) sit comfortably in any lower-secondary computing or digital-citizenship curriculum (e.g. England's Computing programme of study, the US CSTA / ISTE standards, the IB).
Curriculum links (Austria, Germany lower secondary, Switzerland Lehrplan 21)
| Framework | Competence area | Reference in this unit |
|---|---|---|
| AT — compulsory exercise “Digitale Grundbildung” (basic digital education) | Security; data protection & privacy; responsible media use | whole unit |
| DE — KMK “Education in the digital world” | Competence area 4: Protecting and acting safely (4.1 acting safely in digital environments, 4.2 personal data/privacy) | Ch. 2, 6, 7 |
| CH — Lehrplan 21, module “Media and computer science” | MI.1 Media (opportunities/risks, protecting one's identity) | Ch. 3, 4, 5, 7 |
| Computing / media education | Explain how authentication & encryption work | Ch. 2, 6 (In-Detail mode) |
| Language / English | Critically examine texts, argue, write for an audience | Worksheets 1, 4; class test Part D |
| Ethics / social learning (PSHE) | Responsibility, helpfulness, looking out for the vulnerable (protecting seniors) | Homework “Protecting others” |
Note for DE/AT/CH: the German (KMK), Austrian (Digitale Grundbildung) and Swiss (Lehrplan 21) references above are named explicitly; for other systems, the unit aligns naturally with any online-safety / digital-citizenship strand.
Cross-curricular competences
- Critical thinking: questioning messages and links systematically instead of reacting on impulse.
- Self-regulation: pausing under pressure — the core of almost every protective strategy.
- Social responsibility: passing knowledge on, especially to vulnerable groups.
- Problem-solving: working through an orderly plan if something goes wrong.
Timing variants
| Variant | Breakdown | Recommended for |
|---|---|---|
| Double lesson (90 min) | All topics in excerpts, “Spot the scam” on the projector, 1–2 worksheets | Project day, cover lesson, taster course |
| Weekly module (3 × 50 min) | Lesson 1: passwords · Lesson 2: scams, “Spot the scam” + scam radar · Lesson 3: habits/emergency + test | Standard teaching over a week |
| Project week (5 × 90 min) | One topic per day with independent research; day 5: an awareness project for seniors + presentations | In-depth study, theme week, peer teaching |
Where does this fit in?
- Helpful beforehand: basic familiarity with a smartphone, a browser and the term “app”.
- Builds towards: data protection/GDPR, dealing with misinformation, deepfakes, cyberbullying, evaluating sources.
- Sister sites in the »verstehen« series: Understanding Data Protection, Understanding the Internet, Understanding Deepfakes.
- Going further: national cybercrime-prevention and consumer-protection bodies (phishing alerts & fake-shop finders), and watchlists for online scams.