Digital Defense
Advanced cybersecurity awareness: phishing, password hygiene, data privacy, deepfakes, and digital rights. Six modules that turn teens into the most security-savvy person in the room.
About this course
Teens face the most sophisticated online threats of any age group. They are targeted by phishing scams, their data is collected by hundreds of companies, and AI-generated content is making it harder than ever to tell what is real. Digital Defense gives them real technical skills they can use immediately, plus the critical thinking habits to stay safe as technology evolves.
Each module includes hands-on labs, real-world case studies, and a practical challenge. Teens finish with a Personal Security Audit and a set of habits that will protect them for life.
Lessons
-
Key Idea: Phishing is the gateway to almost every major cyberattack. It is how hackers steal passwords, install malware, and gain access to personal and corporate systems. Modern phishing is sophisticated, personalized, and uses AI to create convincing fake emails, texts, and websites. The only defense is training your brain to spot the patterns and verify before you trust.
How Modern Phishing Actually Works
Phishing has evolved far beyond the “Nigerian prince” emails of the past. Today’s attacks are:
- Highly targeted (spear phishing): Attackers research you on social media and craft personalized messages
- AI-generated: ChatGPT and similar tools create perfect grammar and convincing scenarios
- Multi-channel: The same scam hits your email, text messages, and social media simultaneously
- Time-sensitive: “Your account will be closed in 24 hours” creates pressure to act without thinking
The psychology behind it: Phishing exploits basic human emotions — fear (your account is compromised), greed (you won something), curiosity (someone tagged you in a photo), and authority (your boss needs this urgently).
The Seven Red Flags (Updated for 2026)
- Urgent or threatening language: “Act now,” “Your account will be suspended,” “Immediate action required”
- Mismatched sender information: Email says it’s from Netflix but comes from a Gmail address
- Suspicious URLs: Hover over links — does “netflix.com” actually go to “netf1ix-security.com”?
- Requests for sensitive information: Legitimate companies never ask for passwords or SSNs via email
- Too-good-to-be-true offers: Free iPhones, lottery winnings, exclusive deals just for you
- Unexpected attachments: PDFs, Word docs, or zip files you were not expecting
- Generic greetings: “Dear Customer” instead of your actual name (though targeted attacks will use your name)
Advanced Link Inspection Techniques
Desktop: Hover your mouse over any link without clicking. Look at the bottom-left corner of your browser — the real URL will appear there.
Mobile: Long-press the link. A preview will show the actual destination.
What to look for:
- Domain spoofing: “arnazon.com” instead of “amazon.com”
- Subdomain tricks: “amazon.com.evil-site.com” (the real domain is evil-site.com)
- URL shorteners: bit.ly, tinyurl.com links that hide the real destination
- Suspicious TLDs: .tk, .ml, .ga domains are often used for scams
Pro tip: When in doubt, do not click the link. Go directly to the company’s website by typing their URL into your browser.
Social Engineering: The Human Hack
Social engineering is the art of manipulating people into giving up information or access. Common techniques:
- Pretexting: Creating a fake scenario (“I’m from IT, I need your password to fix your account”)
- Baiting: Offering something enticing (“Free USB drive” that contains malware)
- Quid pro quo: “I’ll help you with X if you give me Y”
- Authority: Impersonating someone in power (“This is your CEO, I need you to…”)
- Scarcity: “Only 3 left in stock, buy now!”
- Social proof: “All your friends are doing this”
Smishing and Vishing: Beyond Email
SMS Phishing (Smishing): Fake text messages claiming to be from your bank, delivery companies, or social media platforms. Often include malicious links or ask you to call a fake number.
Voice Phishing (Vishing): Phone calls from “Microsoft support,” “your credit card company,” or “the IRS.” They create urgency and ask for personal information or remote access to your computer.
Red flags for phone scams: Unsolicited calls about problems you did not know you had, requests for remote computer access, pressure to act immediately, or requests for gift cards as payment.
Hands-On Lab: Phishing Detection Challenge. Examine 10 real examples (5 legitimate emails, 5 phishing attempts). For each one, identify: (1) Is it legitimate or phishing? (2) What specific clues led to your decision? (3) What would happen if someone fell for the fake ones? Then create your own educational phishing email to understand the attacker’s mindset.
Incident Response Plan: If you think you clicked a phishing link or gave information to a scammer: (1) Change passwords immediately on all important accounts, (2) Enable two-factor authentication everywhere, (3) Check your account activity for unauthorized access, (4) Run a malware scan on your device, (5) Report the phishing attempt to the company being impersonated, (6) Monitor your credit report for suspicious activity.
Vocabulary: Phishing, spear phishing, smishing, vishing, social engineering, pretexting, domain spoofing, URL inspection, malware
-
Key Idea: Most people use the same weak password everywhere. That means one data breach exposes your entire digital life. Good password hygiene and two-factor authentication are the single biggest security upgrade you can make in under an hour.
What you will learn:
- Why “Password123!” is a terrible password and how hackers crack weak passwords in seconds using dictionary attacks and brute force
- How password managers work and why you should use one (Bitwarden, 1Password, Apple Passwords)
- The three types of two-factor authentication: SMS codes (weakest), authenticator apps (better), hardware security keys like YubiKey (strongest)
- What biometric security is (fingerprint, face ID) and its pros and cons
- How to check if your accounts have been compromised using Have I Been Pwned
Lab: Install a password manager. Generate a unique 20-character password for one of your accounts. Enable two-factor authentication on your email, your social media, and your gaming accounts. Check your email address on Have I Been Pwned.
Vocabulary: Brute force attack, dictionary attack, password manager, two-factor authentication (2FA), biometrics, encryption
-
Key Idea: Every app, website, and service you use collects data about you. Most people have no idea how much. Understanding what is collected, who has it, and your rights under the law puts you back in control.
What you will learn:
- What data companies collect: location, browsing history, purchase history, contacts, biometric data, and inferred interests
- How the ad-tech industry builds a profile of you and sells access to it in real-time auctions (programmatic advertising)
- Your rights under Canadian privacy law (PIPEDA) and how to request your data from any company
- Practical steps to reduce your data footprint: browser privacy settings, tracker blocking, VPNs, and opting out of data brokers
- The privacy paradox: why we say we care about privacy but rarely act on it, and how to break that pattern
Lab: Download your data from Google, Instagram, or TikTok. Look at what they have on you. Then install a tracker blocker (uBlock Origin or Privacy Badger) and watch how many trackers it blocks on your favorite websites in one day.
Vocabulary: PIPEDA, GDPR, data broker, programmatic advertising, VPN, tracker, opt-out
-
Key Idea: AI can now generate photorealistic images, clone voices, and create video of people saying things they never said. This technology is advancing faster than our ability to detect it. Knowing how it works and how to verify what you see is essential.
What you will learn:
- How generative AI creates images, audio, and video: GANs, diffusion models, and voice cloning in plain language
- The telltale signs of AI-generated content: inconsistent lighting, weird hands and teeth, unnatural blinking, audio artifacts
- How deepfakes are being used for scams, political manipulation, and non-consensual content, and why this matters to you
- Verification techniques: reverse image search, metadata analysis, checking multiple independent sources, and the SIFT method (Stop, Investigate, Find better coverage, Trace claims)
- The ethics of synthetic media: when is it OK to use AI-generated content and when is it harmful?
Lab: We will show you a mix of real and AI-generated images and videos. Your job is to sort them and explain your reasoning. Then use a reverse image search tool to verify the origin of a viral image you have seen recently.
Vocabulary: Deepfake, GAN, diffusion model, synthetic media, SIFT method, metadata, verification
-
Key Idea: With great digital skills comes great responsibility. The most security-savvy person in the room has a duty to help others. Being a positive voice and a trusted source of good information makes the entire internet safer for everyone.
What you will learn:
- How to share security knowledge with friends and family without sounding preachy or paranoid
- Becoming a trusted source: how to share verified information and correct misinformation respectfully
- Digital leadership in online communities: moderating, setting norms, and modeling good behavior
- How to handle it when YOU make a mistake online: owning it, apologizing, and doing better
- Career paths in cybersecurity: the massive demand for security professionals and how to start learning now
Activity: Create a one-page “Digital Safety Tips” guide for a younger sibling, cousin, or friend. Use what you have learned in this course. Make it clear, friendly, and actionable.
Vocabulary: Digital leadership, community norms, de-escalation, cybersecurity career paths, mentorship
-
Key Idea: The threats are going to keep changing. AI will get better. Scams will get more convincing. But the fundamentals of good security hygiene, critical thinking, and healthy skepticism do not change. Building habits now protects you for decades.
What you will learn:
- Emerging threats to watch: AI-powered social engineering, quantum computing and encryption, IoT device vulnerabilities, biometric spoofing
- The security mindset: how to think like a security professional and evaluate new technology before adopting it
- Building a personal security routine: monthly password audits, software updates, backup strategy, and account reviews
- How to stay informed without getting overwhelmed: trusted sources for security news and when to pay attention
- Your Personal Security Audit: a complete review of your digital life and a plan for keeping it secure
Final Project: Complete your Personal Security Audit. Document every account you have, check every password, enable 2FA everywhere, review your privacy settings on every platform, and write a one-page summary of your security posture and your plan for maintaining it.
Vocabulary: Threat modeling, security posture, zero-trust, IoT, quantum computing, attack surface
