🧙 Wiz Kids
LearnOnline Safety & Digital Citizenship

Teaching children to spot phishing and scams: what actually works

Evidence grade: PROMISING. Phishing-training research is substantial for adults (with clear findings about what fails and what helps); child-specific studies are sparser. The transferable core — practice with feedback beats awareness messaging; cue-based judgment beats rule memorization — rests on solid ground.

Scams are the internet's oldest constant, and children meet them earlier than most curricula admit: free-robux links, fake giveaway DMs, "your account will be deleted" emails, prize popups. The good news from two decades of anti-phishing research: susceptibility is trainable. The bad news: the way most organizations "train" it — annual awareness messaging — measurably barely works, and schools mostly imported that model.

What the adult research established

The cue-set worth teaching (age-adjusted)

Cues that survive contact with primary-aged capability, roughly in teaching order:

  1. Urgency and jackpot are the tells. "Act NOW", "you've WON" — manufactured hurry and unearned prizes are the scam's two engines. Feelings-as-signal is teachable young: if a message makes you rush or drool, slow down.
  2. The ask is the giveaway. Legitimate services don't ask you to "confirm" your password, secret, or personal details by message. Any message asking for a secret is the answer to itself.
  3. Look at where it claims to be from — sender addresses and lookalike URLs: reading the road signs is a skill we teach explicitly (rnicrosoft, paypa1, the hyphenated imposter).
  4. Too-good economics: free things that cost a login aren't free; the login is the price.
  5. When unsure: don't act inside the message. Close it; go to the real site/app yourself; ask an adult. The exit ramp matters more than the diagnosis — a child who can't classify a message but knows the ramp is safe.
  6. Report, don't just delete — reporting protects the next child, and rehearsing the report button makes it a reflex (and in Australia, the eSafety pathways).

What the evidence doesn't say

In the classroom

  1. Drill with mixed decks: real and fake messages together, always — discrimination is the skill; all-fake decks teach paranoia.
  2. Coach at the click, not after the unit: the wrong call, met immediately with why, is the highest-value moment in the whole topic.
  3. Rehearse the exit ramp until it's boring: close, go direct, ask.
  4. Refresh on a spaced schedule — a two-minute scam-or-real warm-up each month outperforms an annual e-safety day.

How Wiz Kids applies this

Scam recognition runs as judgment scenarios and embedded simulation: a phishing owl sits in a real-looking inbox (report it, don't reply), lookalike URLs appear in the browser realm's road-signs lessons, prize popups and urgency arrive in fiction — and every wrong call gets immediate, kind coaching with a retry, exactly the moment the research says teaches. Reviews resurface the judgments on the spaced schedule, mixed decks always include genuine messages, and the fiction repeats the ramp: close it, go direct, ask.

References


© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.