Teaching children to spot phishing and scams: what actually works
Scams are the internet's oldest constant, and children meet them earlier than most curricula admit: free-robux links, fake giveaway DMs, "your account will be deleted" emails, prize popups. The good news from two decades of anti-phishing research: susceptibility is trainable. The bad news: the way most organizations "train" it — annual awareness messaging — measurably barely works, and schools mostly imported that model.
What the adult research established
- Awareness alone fails. The consistent finding across corporate and lab studies: knowing that phishing exists does not reduce clicking. People fail in the moment — under time pressure, in familiar-looking contexts — not for lack of the concept.
- Embedded, feedback-timed training works better. The Carnegie Mellon research program (Kumaraguru et al.'s "embedded training" studies; the Anti-Phishing Phil game — Sheng et al., 2007) showed the durable gains come from practicing the judgment and getting feedback at the moment of the mistake — the teachable moment being the click itself, in a safe setting. Game-based cue training measurably improved discrimination, not just suspicion.
- The failure mode of bad training is indiscriminate distrust. Training that only rewards "don't click" produces people who distrust everything — costly in real life and unstable (indiscriminate rules collapse the first time they're wrong). Good training improves discrimination: real from fake, both directions (the same calibration principle as source evaluation).
The cue-set worth teaching (age-adjusted)
Cues that survive contact with primary-aged capability, roughly in teaching order:
- Urgency and jackpot are the tells. "Act NOW", "you've WON" — manufactured hurry and unearned prizes are the scam's two engines. Feelings-as-signal is teachable young: if a message makes you rush or drool, slow down.
- The ask is the giveaway. Legitimate services don't ask you to "confirm" your password, secret, or personal details by message. Any message asking for a secret is the answer to itself.
- Look at where it claims to be from — sender addresses and lookalike URLs: reading the road signs is a skill we teach explicitly (rnicrosoft, paypa1, the hyphenated imposter).
- Too-good economics: free things that cost a login aren't free; the login is the price.
- When unsure: don't act inside the message. Close it; go to the real site/app yourself; ask an adult. The exit ramp matters more than the diagnosis — a child who can't classify a message but knows the ramp is safe.
- Report, don't just delete — reporting protects the next child, and rehearsing the report button makes it a reflex (and in Australia, the eSafety pathways).
What the evidence doesn't say
- It doesn't say children (or adults) can reach zero susceptibility — well-crafted spear-phishing beats trained adults; the goal is raising the cost, catching the common, and building the pause.
- It doesn't support one-off assembly talks — decay is rapid without spaced re-practice, which is true of every judgment skill (spacing).
- It doesn't license shame as pedagogy: punishing the child who clicked teaches concealment; the research-supported response is feedback at the moment, no stakes, try again.
In the classroom
- Drill with mixed decks: real and fake messages together, always — discrimination is the skill; all-fake decks teach paranoia.
- Coach at the click, not after the unit: the wrong call, met immediately with why, is the highest-value moment in the whole topic.
- Rehearse the exit ramp until it's boring: close, go direct, ask.
- Refresh on a spaced schedule — a two-minute scam-or-real warm-up each month outperforms an annual e-safety day.
How Wiz Kids applies this
Scam recognition runs as judgment scenarios and embedded simulation: a phishing owl sits in a real-looking inbox (report it, don't reply), lookalike URLs appear in the browser realm's road-signs lessons, prize popups and urgency arrive in fiction — and every wrong call gets immediate, kind coaching with a retry, exactly the moment the research says teaches. Reviews resurface the judgments on the spaced schedule, mixed decks always include genuine messages, and the fiction repeats the ramp: close it, go direct, ask.
References
- Sheng, S., Magnien, B., Kumaraguru, P., Acquisti, A., Cranor, L., Hong, J., & Nunge, E. (2007). Anti-Phishing Phil: The design and evaluation of a game that teaches people not to fall for phish. SOUPS 2007.
- Kumaraguru, P., et al. (2007–2010). The embedded-training research program (PhishGuru studies), Carnegie Mellon CyLab.
- Sheng, S., Holbrook, M., Kumaraguru, P., Cranor, L., & Downs, J. (2010). Who falls for phish? A demographic analysis of phishing susceptibility and effectiveness of interventions. CHI 2010.
- Lastdrager, E., Gallardo, I. C., Hartel, P., & Junger, M. (2017). How effective is anti-phishing training for children? SOUPS 2017 — one of the few child-specific studies (training helped; effects decayed, arguing for spaced refresh).
© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.