1"use strict";(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[4081],{22897:(e,a,o)=>{o.d(a,{OM:()=>l,LQ:()=>h,aI:()=>i});let t={"spotting-phishing":{title:"C\xf3mo detectar correos de phishing",icon:"\uD83C\uDFA3",duration:"10 min",slides:[{type:"title",timer:5,title:"C\xf3mo detectar correos de phishing",subtitle:"Aprenda a identificar correos enga\xf1osos antes de hacer clic",objectives:["Identifique las 6 se\xf1ales de alerta comunes del phishing","Analice correos reales frente a falsos","Practique con escenarios realistas"]},{type:"concept",timer:12,title:"\xbfQu\xe9 es el phishing?",content:"El phishing es un ciberataque en el que los delincuentes env\xedan mensajes enga\xf1osos dise\xf1ados para enga\xf1arlo y hacer que revele informaci\xf3n confidencial, haga clic en enlaces maliciosos o descargue archivos adjuntos da\xf1inos. Es la causa n\xfamero uno del inicio de las filtraciones de datos.",stats:[{value:"91%",label:"de las filtraciones comienzan con phishing"},{value:"3.4B",label:"correos de phishing enviados a diario en todo el mund
1o"},{value:"$4.9M",label:"costo promedio por filtraci\xf3n de datos"}],callout:{icon:"\uD83D\uDCE7",title:"C\xf3mo funciona",text:"Los atacantes env\xedan correos que parecen provenir de alguien en quien usted conf\xeda: su distrito escolar, su director o un proveedor. Quieren que haga clic en un enlace, abra un archivo adjunto o comparta sus credenciales. Basta un solo clic."}},{type:"keypoints",timer:25,title:"Las 6 se\xf1ales de alerta",points:[{icon:"â°",label:"Urgencia",desc:"\xab\xa1Act\xfae ya!\xbb \xab\xa1Su cuenta ser\xe1 suspendida!\xbb La presi\xf3n para actuar r\xe1pido le impide pensar con claridad.",color:"#ef4444"},{icon:"\uD83D\uDC64",label:"Remitente falsificado",desc:"El nombre visible parece correcto, pero la direcci\xf3n de correo tiene una ligera diferencia: [email protected]",color:"#f97316"},{icon:"\uD83D\uDD17",label:"Enlaces sospechosos",desc:"Pase el cursor por encima antes de hacer clic. El texto que se muestra dice una cosa, pero la URL real lleva a un lugar completamente distinto.",color:"#eab308"},{icon:"\uD83D\uDCCE",label:"Archivos adjuntos inesperados",desc:"\xbfEsperaba este archivo? Los archivos .exe, .zip y .docm de remitentes desconocidos son peligrosos.",color:"#22c55e"},{icon:"âï¸",label:"Gram\xe1tica deficiente",desc:"Los errores de ortograf\xeda, las frases mal construidas y los errores de formato suelen ser se\xf1al de contenido generado autom\xe1ticamente o de origen extranjero.",color:"#3b82f6"},{icon:"\uD83C\uDF81",label:"Demasiado bueno para ser verdad",desc:"\xab\xa1Ha ganado!\xbb \xab\xa1Tarjeta de regalo gratis!\xbb Si suena demasiado bueno para ser verdad, casi con certeza lo es.",color:"#8b5cf6"}]},{type:"email_exercise",timer:0,title:"Detecte el correo de phishing",instruction:"Lea el correo con atenci\xf3n y decida: \xbfes real o un intento de phishing?",email:{from:{name:"Soporte de TI",address:"[email protected]"},to:"[email protected]",time:"Hoy, 9:42 a. m.",subject:"â ï¸ URGENTE: la contrase\xf1a de su correo vence en 2 horas",body:"Estimado miembro del personal:\n\nLa contrase\xf1a de su correo vencer\xe1 en 2 horas. Para evitar perder el acceso a su cuenta, verifique sus credenciales de inmediato haciendo clic en el enlace de abajo.\n\nVERIFIQUE SU CONTRASE\xd1A AHORA â https://diocse-portal.com/verify\n\nSi no realiza la verificaci\xf3n en un plazo de 2 horas, su cuenta se bloquear\xe1 de forma permanente y se eliminar\xe1n todos sus correos.\n\nGracias,\nEquipo de Soporte de TI",isPhishing:!0,redFlags:[{highlight:"di0cese-tech.com",explanation:"El dominio del remitente usa un cero en lugar de una \xabo\xbb: no es su dominio real."},{highlight:"vence en 2 horas",explanation:"La urgencia artificial es una t\xe1ctica cl\xe1sica del phishing. Los departamentos de TI reales le dan d\xedas, no horas."},{highlight:"diocse-portal.com",explanation:"El dominio del enlace est\xe1 mal escrito: lleva a un sitio falso."},{highlight:"bloqueada de forma permanente",explanation:"Amenazar con la eliminaci\xf3n permanente genera p\xe1nico. Un \xe1rea de TI real nunca har\xeda esto."}]}},{type:"email_exercise",timer:0,title:"Detecte el correo de phishing",instruction:"Aqu\xed tiene otro. \xbfEste correo es leg\xedtimo o es phishing?",email:{from:{name:"Sarah Mitchell",address:"[email protected]"},to:"[email protected]",time:"Hoy, 2:15 p. m.",subject:"Agenda de la reuni\xf3n de personal: jueves a las 3 p. m.",body:"Hola a todos:\n\nSolo un recordatorio de que nuestra reuni\xf3n semanal de personal es el jueves a las 3 p. m. en la sala de profesores.\n\nPuntos de la agenda:\n⢠Actualizaci\xf3n sobre la planificaci\xf3n de la campa\xf1a de recaudaci\xf3n de primavera\n⢠Cambios en el formulario de autorizaci\xf3n para excursiones\n⢠Demostraci\xf3n del nuevo sistema de control de asistencia\n\nAv\xedsenme si tienen algo que agregar a la agenda.\n\nGracias,\nSarah Mitchell\nSubdirectora",isPhishing:!1,redFlags:[],legitimateReasons:"Este correo tiene un dominio de remitente leg\xedtimo, no usa t\xe1cticas de urgencia, no tiene enlaces sospechosos y su tono es natural y conversacional. \xa1Es seguro!"}},{type:"scenario",timer:0,title:"\xbfQu\xe9 har\xeda usted?",steps:[{text:"Usted recibe un correo que parece ser de su director, en el que le pide con urgencia que compre $500 en tarjetas de regalo de Apple para un evento de reconocimiento al personal. El correo indica que lo mantenga en secreto.",choices:[{label:"Comprar las tarjetas de regalo: \xa1lo pidi\xf3 el director!",next:1},{label:"Responder el correo para pedir m\xe1s detalles",next:2},{label:"Ir en persona a la oficina del director para confirmar",next:3},{label:"Reportarlo como sospechoso con el bot\xf3n Reportar",next:4}]},{text:"Compr\xf3 las tarjetas de regalo y envi\xf3 los c\xf3digos. Lamentablemente, se trataba de una estafa de compromiso del correo de la organizaci\xf3n (OEC). El correo proven\xeda de un atacante que se hac\xeda pasar por su director. Los $500 se perdieron y no se pueden recuperar.",outcome:"bad",lesson:"Las solicitudes de tarjetas de regalo por correo casi siempre son estafas. Ninguna organizaci\xf3n leg\xedtima compra tarjetas de regalo de esta forma.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"Usted respondi\xf3 pidiendo detalles. El atacante responde con m\xe1s urgencia: \xabPor favor, ap\xfarese, \xa1el evento es hoy! Estoy en una reuni\xf3n y no puedo hablar\xbb. Esta es una t\xe1ctica com\xfan para impedir que usted verifique.",choices:[{label:"Est\xe1 bien, comprarlas ahora",
1next:1},{label:"Llamar al n\xfamero de tel\xe9fono conocido del director",next:3},{label:"Reportar el correo como sospechoso",next:4}]},{text:"Usted fue a la oficina del director (o llam\xf3 a su n\xfamero conocido). El director no tiene idea de qu\xe9 le habla: nunca envi\xf3 ese correo. \xa1Acaba de evitar una p\xe9rdida de $500!",outcome:"good",lesson:"Verifique siempre las solicitudes inusuales por un canal aparte. Nunca conf\xede en los datos de contacto que aparecen en el propio correo sospechoso.",choices:[{label:"Continuar",next:-1}]},{text:"Usted report\xf3 el correo con el bot\xf3n Reportar sospechoso. El administrador de TI investig\xf3 y confirm\xf3 que se trataba de un ataque OEC dirigido a varios miembros del personal. \xa1Su r\xe1pida acci\xf3n protegi\xf3 a toda la escuela!",outcome:"best",lesson:"Reportar correos sospechosos ayuda a proteger a todos. Cuanto antes se identifiquen las amenazas, m\xe1s r\xe1pido se podr\xe1n bloquear.",choices:[{label:"Continuar",next:-1}]}]},{type:"quiz",timer:0,title:"Comprobaci\xf3n de conocimientos",questions:[{q:"\xbfQu\xe9 debe hacer si un correo genera una sensaci\xf3n de urgencia extrema?",options:["Actuar de inmediato seg\xfan las instrucciones","Tomarse un momento y verificar por otro canal","Reenviarlo a todo el personal","Eliminarlo e ignorarlo"],correct:1,explanation:"La urgencia es una t\xe1ctica de manipulaci\xf3n. T\xf3mese siempre un momento y verifique por un canal aparte y de confianza."},{q:"\xbfCu\xe1l direcci\xf3n de remitente es sospechosa?",options:["[email protected]","[email protected]","[email protected]","[email protected]"],correct:1,explanation:"El cero en \xabamaz0n\xbb es un truco de sustituci\xf3n de caracteres. Revise siempre las direcciones con cuidado."},{q:"Su director le env\xeda un correo pidi\xe9ndole que compre tarjetas de regalo. \xbfCu\xe1l es la mejor respuesta?",options:["Comprarlas: \xa1es el director!","Responder el correo para confirmar","Llamar al director a un n\xfamero de tel\xe9fono conocido","Preguntarle a un compa\xf1ero de trabajo"],correct:2,explanation:"Verifique siempre por un canal completamente aparte. Llamar a un n\xfamero conocido es lo m\xe1s seguro."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["Revise siempre la direcci\xf3n de correo real del remitente, no solo el nombre visible","T\xf3mese un momento cuando los correos generen urgencia: eso es una se\xf1al de alerta","Pase el cursor sobre los enlaces antes de hacer clic para verificar la URL real","Ante la duda, verifique por un canal aparte (tel\xe9fono, en persona)"]}]},"password-hygiene":{title:"Higiene y seguridad de contrase\xf1as",icon:"\uD83D\uDD11",duration:"10 min",slides:[{type:"title",timer:5,title:"Higiene y seguridad de contrase\xf1as",subtitle:"Las contrase\xf1as seguras son su primera l\xednea de defensa",objectives:["Cree contrase\xf1as verdaderamente seguras","Comprenda por qu\xe9 reutilizar contrase\xf1as es peligroso","Configure la autenticaci\xf3n multifactor"]},{type:"concept",timer:20,title:"Por qu\xe9 importan las contrase\xf1as",content:"Su contrase\xf1a es la llave de su vida digital. Las contrase\xf1as d\xe9biles o reutilizadas son la forma m\xe1s f\xe1cil de que los atacantes accedan a los sistemas escolares, los registros de los estudiantes y las cuentas financieras.",stats:[{value:"81%",label:"de las filtraciones involucran contrase\xf1as d\xe9biles o robadas"},{value:"23M",label:'de personas todav\xeda usan "123456" como contrase\xf1a'},{value:"< 1seg",label:"para descifrar una contrase\xf1a de 6 caracteres"}],callout:{icon:"\uD83D\uDC80",title:"El efecto domin\xf3",text:"Cuando reutiliza la misma contrase\xf1a en varios sitios, una sola filtraci\xf3n lo expone todo. Si la contrase\xf1a de su correo personal es la misma que la de su inicio de sesi\xf3n escolar, una filtraci\xf3n de datos en cualquier sitio que use les da a los atacantes acceso a los sistemas de su escuela."}},{type:"keypoints",timer:20,title:"\xbfQu\xe9 hace que una contrase\xf1a sea segura?",points:[{icon:"\uD83D\uDCCF",label:"Longitud antes que complejidad",desc:'"correcthorsebatterystaple" es m\xe1s segura que "P@$$w0rd!": las contrase\xf1as m\xe1s largas tardan exponencialmente m\xe1s en descifrarse.',color:"#22c55e"},{icon:"\uD83D\uDEAB",label:"Nunca reutilice",desc:"Cada cuenta lleva una contrase\xf1a \xfanica. Punto. Una sola filtraci\xf3n no deber\xeda comprometerlo todo.",color:"#ef4444"},{icon:"\uD83D\uDDDDï¸",label:"Use un gestor de contrase\xf1as",desc:"Herramientas como Bitwarden (gratis) o 1Password generan y recuerdan por usted contrase\xf1as seguras y \xfanicas.",color:"#3b82f6"},{icon:"\uD83D\uDCF1",label:"Active la MFA en todas partes",desc:"La autenticaci\xf3n multifactor significa que, aunque le roben la contrase\xf1a, los atacantes de todos modos no pueden entrar.",color:"#8b5cf6"},{icon:"\uD83D\uDD12",label:"M\xe9todo de frase de contrase\xf1a",desc:'Encadene 4 o m\xe1s palabras al azar: "purple-elephant-drives-tuesday": f\xe1cil de recordar y casi imposible de descifrar.',color:"#f97316"}]},{type:"concept",timer:20,title:"\xbfQu\xe9 tan r\xe1pido se puede descifrar su contrase\xf1a?",content:"Las computadoras modernas pueden probar miles de millones de combinaciones de contrase\xf1as por segundo. La longitud y la complejidad de su contrase\xf1a determinan cu\xe1nto tardar\xeda en descifrarse.",stats:[{value:"Instant\xe1neo",label:"6 caracteres, solo min\xfasculas"},{value:"3 horas",label:"8 caracteres, may\xfasculas y min\xfasculas + n\xfameros"},{value:"34 a\xf1os",label:"12 caracteres, may\xfasculas y min\xfasculas + n\xfameros + s\xedmbolos"}],callout:{icon:"\uD83D\uDEE1ï¸",title:"El punto ideal",text:'Use 16 o m\xe1s caracteres (una frase de contrase\xf1a) con una mezcla de palabras. "sunflower-piano-rocket-blue42" tardar\xeda millones de a\xf1os en descifrarse por fuerza bruta, y de verdad puede recordarla.'}},{type:"scenario",timer:0,title:"Escenario de contrase\xf1a",steps:[{text:'Necesita crear una nueva contrase\xf1a para su correo escolar. La anterior era "StMarys2024!": \xbfqu\xe9 elige?',choices:[{label:"StMarys2025! (solo actualizar el a\xf1o)",next:1},{label:"Usar la misma contrase\xf1a que mi Gmail personal",next:2},{label:"Generar una con un gestor de contrase\xf1as",next:3},{label:'Escribir "purple-walrus-teaches-math" en una nota adhesiva',next:4}]},{text:'Los patrones predecibles, como aumentar el a\xf1o, son lo primero que prueban los atacantes. "StMarys2025!" se descifrar\xeda en minutos con un ataque de diccionario dirigido contra su escuela.',outcome:"bad",lesson:"Nunca use variaciones predecibles de contrase\xf1as antiguas. Cada contrase\xf1a debe ser completamente distinta.",choices:[{label:"Intente de nuevo",next:0}]},{text:"Reutilizar contrase\xf1as es el error n\xfamero uno con las contrase\xf1as. Si alguna vez filtran su Gmail (y Google ha tenido incidentes), los atacantes probar\xe1n de inmediato esa contrase\xf1a en su correo escolar, su banco y todas las dem\xe1s cuentas.",outcome:"bad",lesson:"Cada cuenta necesita una contrase\xf1a \xfanica. Una sola filtraci\xf3n nunca deber\xeda comprometer varias cuentas.",choices:[{label:"Intente de nuevo",next:0}]},{text:"Un gestor de contrase\xf1as genera una contrase\xf1a segura, \xfanica y aleatoria, y la recuerda por usted. Solo necesita recordar una contrase\xf1a maestra. Este es el est\xe1ndar de oro en seguridad de contrase\xf1as.",outcome:"best",lesson:"Los gestores de contrase\xf1as como Bitwarden (gratis) o 1Password eliminan la necesidad de recordar decenas de contrase\xf1as.",choices:[{label:"Continuar",next:-1}]},{text:'La frase de contrase\xf1a "purple-walrus-teaches-math" en realidad es muy segura, \xa1pero escribirla en una nota adhesiva arruina el prop\xf3sito! Cualquiera que pase por su escritorio puede verla. Mejor use un gestor de contrase\xf1as.',outcome:"good",lesson:"Las frases de contrase\xf1a son excelentes, pero gu\xe1rdelas de forma segura: en un gestor de contrase\xf1as, no en papel.",choices:[{label:"Continuar",next:-1}]}]},{type:"quiz",timer:0,title:"Comprobaci\xf3n de conocimientos",questions:[{q:"\xbfCu\xe1l contrase\xf1a es la m\xe1s segura?",options:["P@$$
1w0rd!","correct-horse-battery-staple","12345678","qwerty2024"],correct:1,explanation:"Las frases de contrase\xf1a largas son mucho m\xe1s seguras que las contrase\xf1as cortas y complejas. La longitud le gana a la complejidad siempre."},{q:"\xbfCu\xe1l es el mayor riesgo de reutilizar contrase\xf1as?",options:["Es dif\xedcil de recordar","Una sola filtraci\xf3n compromete todas sus cuentas","Hace m\xe1s lenta su computadora","Nada: reutilizar est\xe1 bien"],correct:1,explanation:"Cuando se filtra un sitio, los atacantes prueban esas credenciales en todos los dem\xe1s sitios. Una filtraci\xf3n = todas las cuentas comprometidas."},{q:"\xbfCu\xe1l es la mejor manera de gestionar contrase\xf1as \xfanicas para cada cuenta?",options:["Escribirlas en un cuaderno","Usar un gestor de contrase\xf1as","Usar la misma base con distintas terminaciones","Dejar que su navegador las guarde"],correct:1,explanation:"Los gestores de contrase\xf1as generan, almacenan y autocompletan contrase\xf1as seguras y \xfanicas. Son la opci\xf3n m\xe1s segura y c\xf3moda."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["Use frases de contrase\xf1a (4 o m\xe1s palabras al azar): la longitud le gana a la complejidad","Nunca reutilice contrase\xf1as entre cuentas","Use un gestor de contrase\xf1as como Bitwarden (gratis) o 1Password","Active la autenticaci\xf3n multifactor en todas las cuentas que la ofrezcan"]}]},"social-engineering":{title:"Ingenier\xeda social 101",icon:"\uD83C\uDFAD",duration:"12 min",slides:[{type:"title",timer:5,title:"Ingenier\xeda social 101",subtitle:"C\xf3mo los atacantes manipulan a las personas para obtener acceso",objectives:["Reconocer las t\xe1cticas de mani
1pulaci\xf3n","Comprender el pretexting, el baiting y el tailgating","Responder correctamente a los intentos de ingenier\xeda social"]},{type:"concept",timer:20,title:"\xbfQu\xe9 es la ingenier\xeda social?",content:"La ingenier\xeda social es el arte de manipular a las personas para que revelen informaci\xf3n confidencial o realicen acciones que comprometen la seguridad. A diferencia de quienes hackean computadoras, los ingenieros sociales hackean a las personas: se aprovechan de la confianza, la autoridad y las ganas de ayudar.",stats:[{value:"98%",label:"de los ciberataques implican ingenier\xeda social"},{value:"$130K",label:"p\xe9rdida promedio por estafa de compromiso de correo electr\xf3nico"},{value:"85%",label:"de las brechas de seguridad implican un factor humano"}],callout:{icon:"\uD83E\uDDE0",title:"Por qu\xe9 funciona",text:"Estamos programados para confiar en las figuras de autoridad, ayudar a quienes lo necesitan y reaccionar ante la urgencia. Los atacantes se aprovechan de estos instintos naturales. La mejor defensa es estar alerta: conocer las t\xe1cticas hace que sea mucho m\xe1s dif\xedcil enga\xf1arlo."}},{type:"keypoints",timer:25,title:"Tipos de ataque comunes",points:[{icon:"\uD83C\uDFAD",label:"Pretexting",desc:"Crear un escenario falso para ganarse la confianza. \xabHola, soy del departamento de TI y necesito verificar sus credenciales para una actualizaci\xf3n del sistema.\xbb",color:"#ef4444"},{icon:"\uD83C\uDFA3",label:"Phishing",desc:"Correos electr\xf3nicos fraudulentos que suplantan a entidades de confianza. El ataque de ingenier\xeda social m\xe1s com\xfan.",color:"#f97316"},{icon:"\uD83D\uDCF1",label:"Vishing",desc:"Phishing por voz: llamadas telef\xf3nicas de \xabSoporte de Microsoft\xbb, \xabel IRS\xbb o \xabsu banco\xbb que exigen una acci\xf3n inmediata.",color:"#eab308"},{icon:"\uD83C\uDF6C",label:"Baiting",desc:"Dejar memorias USB infectadas en estacionamientos u ofrecer descargas gratuitas que contienen malware.",color:"#22c55e"},{icon:"\uD83D\uDEAA",label:"Tailgating",desc:"Seguir a una persona autorizada a trav\xe9s de una puerta segura. \xabAy, olvid\xe9 mi credencial, \xbfme sostiene la puerta?\xbb",color:"#3b82f6"},{icon:"\uD83D\uDC8E",label:"Quid Pro Quo",desc:"\xabLe arreglo la computadora si me da sus credenciales de inicio de sesi\xf3n.\xbb Ofrecer algo a cambio de acceso.",color:"#8b5cf6"}]},{type:"scenario",timer:0,title:"\xbfPuede identificar al ingeniero social?",steps:[{text:"Est\xe1 en la recepci\xf3n cuando alguien con uniforme de reparaciones le dice: \xabHola, vengo de la empresa de fotocopiadoras a hacer mantenimiento. El director nos llam\xf3. \xbfMe puede dejar entrar a la sala de servidores? La fotocopiadora se conecta por ah\xed.\xbb",choices:[{label:"Dejarlo entrar: tiene uniforme",next:1},{label:"Pedirle que muestre su identificaci\xf3n de la empresa",next:2},{label:"Llamar al director para verificar la cita",next:3},{label:"Decir que no y pedirle que espere mientras usted verifica",next:3}]},{text:"Lo dej\xf3 entrar. Conect\xf3 un peque\xf1o dispositivo al conmutador de red y ahora est\xe1 capturando todo el tr\xe1fico de la red, incluidas las contrase\xf1as. El \xabt\xe9cnico de reparaciones\xbb era un ingeniero social. El uniforme se compr\xf3 por internet por $30.",outcome:"bad",lesson:"Los uniformes, los portapapeles y la seguridad al hablar son f\xe1ciles de fingir. Verifique siempre antes de dar acceso a \xe1reas sensibles.",choices:[{label:"Intente de nuevo",next:0}]},{text:"Pidi\xf3 una identificaci\xf3n. Le mostr\xf3 una credencial que dice \xabCopyTech Solutions\xbb con su foto. Se ve profesional. Pero las identificaciones falsas son sumamente f\xe1ciles de crear. Una identificaci\xf3n de la empresa por s\xed sola no confirma que la cita sea leg\xedtima.",choices:[{label:"Dejarlo entrar: la identificaci\xf3n se ve real",next:1},{label:"Llamar al director para verificar",next:3}]},{text:"Llam\xf3 al director, quien confirm\xf3 que no hab\xeda ninguna cita de fotocopiadora programada. El \xabt\xe9cnico de reparaciones\xbb se fue r\xe1pidamente al darse cuenta de que usted estaba verificando. \xa1Evit\xf3 el acceso no autorizado a la red de su escuela!",outcome:"best",lesson:"Verifique siempre a trav\xe9s de sus propios canales. Una llamada r\xe1pida para confirmar una cita toma 30 segundos y puede evitar una brecha grave.",choices:[{label:"Continuar",next:-1}]}]},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:"Alguien llama diciendo ser de TI y le pide su contrase\xf1a para \xabarreglar un problema\xbb. \xbfQu\xe9 hace?",options:["Darle la contrase\xf1a: TI la necesita","Colgar y llamar directamente al departamento de TI","Pedirle que demuestre que es real","Enviarle la contrase\xf1a por correo electr\xf3nico en su lugar"],
1correct:1,explanation:"El personal de TI leg\xedtimo nunca pide su contrase\xf1a. Cuelgue y comun\xedquese con TI a trav\xe9s de un n\xfamero conocido."},{q:"\xbfQu\xe9 es el \xabpretexting\xbb?",options:["Escribir c\xf3digo para irrumpir en los sistemas","Crear un escenario falso para ganarse la confianza","Probar la seguridad f\xedsica con credenciales falsas","Enviar correos electr\xf3nicos de spam masivos"],correct:1,explanation:"El pretexting consiste en crear un escenario inventado âuna identidad falsa, una emergencia ficticiaâ para manipularlo y hacer que conf\xede en el atacante."},{q:"\xbfCu\xe1l es un ejemplo de \xabbaiting\xbb?",options:["Un correo de phishing de su banco","Una memoria USB etiquetada \xabSalarios del personal\xbb dejada en el estacionamiento","Una llamada telef\xf3nica del Soporte de Microsoft","Seguir a alguien a trav\xe9s de una puerta con llave"],correct:1,explanation:"El baiting se aprovecha de la curiosidad. Esa memoria USB \xabperdida\xbb est\xe1 dise\xf1ada para que la encuentren y la conecten, instalando malware autom\xe1ticamente."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["Nunca comparta contrase\xf1as: el personal de TI leg\xedtimo nunca se las pedir\xe1","Verifique las identidades a trav\xe9s de sus propios canales, no los de ellos","Desconf\xede cuando se aprovechen de la urgencia, la autoridad y las ganas de ayudar","Reporte de inmediato a visitantes, llamadas o correos sospechosos"]}]},"links-attachments":{title:"Enlaces y archivos adjuntos seguros",icon:"\uD83D\uDD17",duration:"10 min",slides:[{type:"title",timer:5,title:"Enlaces y archivos adjuntos sospechosos",subtitle:"C\xf3mo manejar de forma segura los enlaces y archivos en los correos electr\xf3nicos",objectives:["Identificar URLs maliciosas antes de hacer clic","Reconocer tipos de archivo peligrosos","Saber cu\xe1ndo y c\xf3mo abrir archivos adjuntos de forma segura"]},{type:"concept",timer:20,title:"Los enlaces: el peligro oculto",content:'Un enlace en un correo electr\xf3nico puede decir cualquier cosa â"Haga clic aqu\xed para ver su factura"â pero llevarlo a un lugar completamente distinto. Los enlaces maliciosos pueden instalar malware, robar credenciales o descargar ransomware con un solo clic.',stats:[{value:"86%",label:"de las organizaciones tuvieron a un usuario que hizo clic en un enlace de phishing"},{value:"< 60s",label:"tiempo promedio desde el clic hasta el compromiso de la seguridad"},{value:"$1.4M",label:"costo promedio de un ataque de ransomware a las escuelas"}],callout:{icon:"\uD83D\uDD17",title:"Pase el cursor antes de hacer clic",text:"En una computadora, pase el cursor del mouse sobre cualquier enlace para ver a d\xf3nde lleva realmente. El texto que se muestra y la URL real suelen ser completamente distintos. En el celular, mantenga presionado el enlace para ver una vista previa de la URL."}},{type:"keypoints",timer:20,title:"Se\xf1ales de alerta de enlaces peligrosos",points:[{icon:"\uD83D\uDD24",label:"Dominios mal escritos",desc:"googIe.com (una I may\xfascula en lugar de una L min\xfascula), paypa1.com, amaz0n.com âlos cambios diminutos ocultan sitios falsos.",color:"#ef4444"},{icon:"\uD83D\uDCCF",label:"URLs excesivamente largas",desc:"Los sitios leg\xedtimos tienen URLs limpias. Los enlaces de phishing suelen ser muy largos y con caracteres aleatorios para ocultar el destino real.",color:"#f97316"},{icon:"\uD83D\uDD13",label:"HTTP (no HTTPS)",desc:"Las p\xe1ginas de inicio de sesi\xf3n leg\xedtimas siempre usan HTTPS (el \xedcono del candado). HTTP significa que la conexi\xf3n no est\xe1 cifrada: nunca ingrese contrase\xf1as.",color:"#eab308"},{icon:"\uD83C\uDFAF",label:"Acortadores de URL",desc:"Los enlaces de bit.ly y tinyurl.com ocultan el destino real. En correos de remitentes desconocidos, trate los enlaces acortados como sospechosos.",color:"#3b82f6"},{icon:"\uD83D\uDCCB",label:"Texto visible que no coincide",desc:'El enlace dice "Iniciar sesi\xf3n en Office 365", pero en realidad apunta a hacker-site.ru/o365login: siempre pase el cursor para verificar.',color:"#8b5cf6"}]},{type:"keypoints",timer:15,title:"Tipos de archivos adjuntos peligrosos",points:[{icon:"â ï¸",label:".exe, .scr, .bat",desc:"Archivos ejecutables: NUNCA los abra desde un correo electr\xf3nico. Ejecutan programas en su computadora y a menudo son malware.",color:"#ef4444"},{icon:"\uD83D\uDCE6",label:".zip, .rar, .7z",desc:"Los archivos comprimidos pueden ocultar ar
1chivos maliciosos en su interior. \xc1bralos solo si esperaba el archivo de un remitente conocido.",color:"#f97316"},{icon:"\uD83D\uDCC4",label:".docm, .xlsm",desc:'La "m" significa macros: estas pueden ejecutar c\xf3digo al abrir el archivo. Los archivos normales .docx y .xlsx son m\xe1s seguros.',color:"#eab308"},{icon:"â
",label:".pdf, .docx, .xlsx",desc:"Generalmente seguros, pero aun as\xed verifique al remitente. Incluso estos pueden contener enlaces incrustados o aprovechar vulnerabilidades.",color:"#22c55e"}]},{type:"email_exercise",timer:0,title:"\xbfHar\xeda clic en este enlace?",instruction:"Examine este correo electr\xf3nico y decida si es seguro.",email:{from:{name:"School Supplies Direct",address:"[email protected]"},to:"[email protected]",time:"Hoy, 11:30 a. m.",subject:"Su pedido #88291 ha sido enviado â Rastr\xe9elo ahora",body:"Hola:\n\n\xa1Buenas noticias! Su pedido #88291 ha sido enviado y est\xe1 en camino.\n\nRastree su paquete: https://school-supp1ies-direct.com/track/88291\n\nEntrega prevista: ma\xf1ana antes de las 5 p. m.\n\nSi tiene preguntas, cont\xe1ctenos en [email protected]\n\nEl equipo de School Supplies Direct",isPhishing:!0,redFlags:[{highlight:"school-supp1ies-direct.com",explanation:'El n\xfamero "1" reemplaza la letra "l" en "supplies": este es un dominio falso.'},{highlight:"Pedido #88291",explanation:"\xbfRealmente hizo este pedido? Las notificaciones de env\xedo inesperadas de pedidos que usted no hizo son una t\xe1ctica com\xfan de phishing."},{highlight:"Rastree su paquete",explanation:"Este enlace lleva al mismo dominio falso. Hacer clic en \xe9l probablemente lo llevar\xeda a una p\xe1gina de robo de credenciales o a la descarga de malware."}]}},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:"Antes de hacer clic en un enlace de un correo electr\xf3nico, usted debe:",options:["Hacer clic para ver a d\xf3nde lleva","Pasar el cursor sobre \xe9l para verificar la URL real",'Hacer clic derecho y seleccionar "Abrir"',"Reenviar el correo electr\xf3nico a un amigo para que lo revise"],correct:1,explanation:"Pasar el cursor revela la URL de destino real. Esto toma 2 segundos y puede evitar un compromiso de seguridad."},{q:"\xbfCu\xe1l archivo adjunto es el M\xc1S peligroso?",options:["report.pdf","budget.xlsx","update.exe","photo.jpg"],correct:2,explanation:"Los archivos .exe son programas ejecutables. Abrir uno desde un correo electr\xf3nico podr\xeda instalar malware, ransomware o spyware."},{q:'Una URL contiene "paypa1.com": \xbfes leg\xedtima?',options:["S\xed, es PayPal",'No, la "l" est\xe1 reemplazada por un "1"',"No se puede saber sin hacer clic","S\xed, si tiene HTTPS"],correct:1,explanation:"La sustituci\xf3n de caracteres (1 por l, 0 por o) es un truco com\xfan para crear dominios falsos convincentes."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["Siempre pase el cursor sobre los enlaces antes de hacer clic para ver la URL real","Nunca abra archivos adjuntos .exe, .bat o .scr de un correo electr\xf3nico","Desconf\xede de pedidos, facturas o notificaciones de env\xedo inesperados","Ante la duda, vaya directamente al sitio web escribiendo usted mismo la URL"]}]},"safe-browsing":{title:"H\xe1bitos de navegaci\xf3n segura",icon:"\uD83C\uDF10",duration:"10 min",slides:[{type:"title",timer:5,title:"H\xe1bitos de navegaci\xf3n segura",subtitle:"Prot\xe9jase en l\xednea con una navegaci\xf3n inteligente",objectives:["Identificar sitios web inseguros","Proteger la informaci\xf3n personal en l\xednea","Evitar las amenazas web m\xe1s comunes"]},{type:"concept",timer:20,title:"La web es un campo de batalla",content:"Cada vez que navega por la web, se mueve por un terreno lleno de sitios leg\xedtimos y de imitaciones muy convincentes. Los sitios web maliciosos pueden instalar malware, robar credenciales y comprometer su dispositivo, a menudo sin que usted se d\xe9 cuenta de que algo ocurri\xf3.",stats:[{value:"560K",label:"nuevos programas de malware detectados cada d\xeda"},{value:"1 de cada 13",label:"solicitudes web conducen a malware"},{value:"$10B+",label:"perdidos por delitos inform\xe1ticos cada a\xf1o"}],callout:{icon:"\uD83C\uDF10",title:"Descargas autom\xe1ticas (drive-by)",text:'Algunos sitios maliciosos pueden infectar su computadora con solo visitarlos, sin necesidad de hacer clic. Esto se conoce como "descarga autom\xe1tica" (drive-by download). Mantener actualizados su navegador y su sistema operativo es una protecci\xf3n fundamental.'}},{type:"keypoints",timer:20,title:"Reglas de navegaci\xf3n segura",points:[{icon:"\uD83D\uDD12",label:"Verifique que use HTTPS",desc:'Busque el \xedcono del candado y "https://" en la barra de direcciones. Nunca ingrese contrase\xf1as ni informaci\xf3n personal en sitios HTTP.',color:"#22c55e"},{icon:"\uD83D\uDD04",label:"Mantenga todo actualizado",desc:"Navegador, sistema operativo, complementos: las actualizaciones corrigen vulnerabilidades de seguridad que los atacantes aprovechan.",color:"#3b82f6"},{icon:"\uD83D\uDEAB",label:"Evite el WiFi p\xfablico para tareas sensibles",desc:"El WiFi de una cafeter\xeda n
1o es seguro. Nunca acceda a servicios bancarios, correo electr\xf3nico o sistemas escolares en redes p\xfablicas sin una VPN.",color:"#ef4444"},{icon:"\uD83C\uDF6A",label:"Administre las extensiones del navegador",desc:"Instale extensiones \xfanicamente de fuentes confiables. Las extensiones maliciosas pueden leer todo lo que usted escribe, incluidas las contrase\xf1as.",color:"#f97316"},{icon:"\uD83D\uDD0D",label:"Verifique antes de descargar",desc:'Descargue software \xfanicamente de fuentes oficiales. Esa herramienta "gratuita" de un sitio cualquiera probablemente contiene malware.',color:"#8b5cf6"}]},{type:"scenario",timer:0,title:"Escenario de navegaci\xf3n segura",steps:[{text:"Est\xe1 en una cafeter\xeda calificando trabajos en su computadora port\xe1til. Necesita revisar la calificaci\xf3n de un estudiante en el portal escolar. La cafeter\xeda tiene WiFi gratuito.",choices:[{label:"Conectarse al WiFi gratuito e iniciar sesi\xf3n en el portal",next:1},{label:"Usar su tel\xe9fono como punto de acceso m\xf3vil (hotspot) en su lugar",next:2},{label:"Esperar hasta regresar a la escuela",next:3}]},{text:'Inici\xf3 sesi\xf3n a trav\xe9s del WiFi p\xfablico. Un atacante conectado a la misma red intercept\xf3 sus credenciales mediante un ataque de "intermediario" (man-in-the-middle). Ahora tiene acceso al portal escolar con su inicio de sesi\xf3n.',outcome:"bad",lesson:"El WiFi p\xfablico es inseguro por naturaleza. Cualquier persona en la misma red puede interceptar sus datos.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"\xa1Buena decisi\xf3n! El punto de acceso m\xf3vil de su tel\xe9fono crea una conexi\xf3n privada y cifrada. Puede acceder de forma segura al portal escolar sin exponer sus credenciales a otros usuarios de la red.",outcome:"best",lesson:"Los puntos de acceso m\xf3viles son mucho m\xe1s seguros que el WiFi p\xfablico para acceder a sistemas sensibles.",choices:[{label:"Continuar",next:-1}]},{text:"Esperar es una opci\xf3n segura, aunque no siempre pr\xe1ctica. Si necesita trabajar de forma remota, un punto de acceso m\xf3vil o una VPN son buenas alternativas al WiFi p\xfablico.",outcome:"good",lesson:"Cuando el WiFi p\xfablico sea la \xfanica opci\xf3n, use una VPN para cifrar su conexi\xf3n.",choices:[{label:"Continuar",next:-1}]}]},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:"Necesita descargar un convertidor de PDF. \xbfDe d\xf3nde deber\xeda obtenerlo?",options:["El primer resultado en Google","El sitio web oficial del desarrollador",'Un sitio de torrents con una insignia de "verificado"',"Un enlace que alguien comparti\xf3 en Facebook"],correct:1,explanation:"Descargue siempre de fuentes oficiales. Los resultados de b\xfasqueda, los enlaces en redes sociales y los sitios de torrents distribuyen malware con frecuencia."},{q:"\xbfCu\xe1l es la opci\xf3n m\xe1s segura para acceder a los sistemas escolares de forma remota?",options:["El WiFi de una cafeter\xeda","El WiFi de un hotel","El punto de acceso m\xf3vil de su tel\xe9fono","El WiFi abierto de su vecino"],correct:2,explanation:"El punto de acceso de su tel\xe9fono crea una conexi\xf3n privada y cifrada que solo usted usa. Todas las dem\xe1s opciones comparten la red con desconocidos."},{q:'Un sitio web le pide que "desactive su antivirus para descargar". \xbfQu\xe9 deber\xeda hacer?',options:["Desactivarlo: el sitio sabe lo que hace","Descargar de todos modos con el antivirus activado","Abandonar el sitio de inmediato","Comprobar si es un sitio conocido"],correct:2,explanation:"Ning\xfan software leg\xedtimo le pide que desactive la seguridad. Esta es una se\xf1al de alerta enorme de que la descarga contiene malware."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["Verifique siempre que use HTTPS antes de ingresar cualquier credencial","Nunca use WiFi p\xfablico para inicios de sesi\xf3n sensibles: use un punto de acceso o una VPN","Mantenga su navegador y su sistema operativo actualizados en todo momento","Descargue software \xfanicamente de fuentes oficiales y confiables"]}]},quishing:{title:"Estafas con c\xf3digos QR (quishing)",icon:"\uD83D\uDD33",duration:"9 min",slides:[{type:"title",timer:5,title:"Estafas con c\xf3digos QR (quishing)",subtitle:"Por qu\xe9 ese peque\xf1o cuadrado puede ser m\xe1s peligroso que un enlace",objectives:['Comprenda c\xf3mo funciona el phishing con c\xf3digos QR ("quishing")',"Identifique los c\xf3digos QR que nunca debe escanear","Revele de forma segura a d\xf3nde lleva realmente un c\xf3digo QR"]},{type:"concept",timer:20,title:"\xbfQu\xe9 es el quishing?",content:"El quishing es phishing que oculta el enlace malicioso dentro de un c\xf3digo QR en lugar de una URL en la que se pueda hacer clic. Usted apunta la c\xe1mara de su tel\xe9fono al cuadrado, se abre un sitio web, pero nunca vio la direcci\xf3n antes de llegar. Como el enlace es una imagen, la mayor\xeda de los filtros de correo no pueden leerlo, as\xed que el quishing se cuela por las defensas que atrapar\xedan a un enlace de phishing normal.",stats:[{value:"587%",label:"de aumento en los ataques de quishing en un solo a\xf1o"},{value:"~25%",label:"del phishing por correo ahora usa c\xf3digos QR"},{value:"0",label:"herramientas de seguridad en la mayor\xeda de los tel\xe9fonos que revisen el enlace primero"}],callout:{icon:"\uD83D\uDCF1",title:"Por qu\xe9 su tel\xe9fono es el punto d\xe9bil",text:"Los c\xf3digos QR casi siempre se escanean en un tel\xe9fono personal, que por lo general no tiene ninguna de las protecciones que s\xed tiene su computadora de trabajo. El atacante lo traslada de un dispositivo supervisado a uno sin supervisi\xf3n con un solo escaneo."}},{type:"keypoints",timer:25,title:"D\xf3nde aparecen los c\xf3digos QR falsos",points:[{icon:"\uD83D\uDCE7",label:"En correos electr\xf3nicos",desc:'"Escanee este c\xf3digo QR para volver a verificar su cuenta de Microsoft 365" o para "ver su documento seguro". La imagen esquiva los filtros de enlaces.',color:"#ef4444"}
1,{icon:"\uD83D\uDCC4",label:"En archivos PDF adjuntos",desc:'Una "factura" o un "mensaje de voz" en PDF con un c\xf3digo QR dentro: doblemente oculto, porque el enlace es una imagen dentro de un archivo.',color:"#f97316"},{icon:"\uD83C\uDD7Fï¸",label:"En calcoman\xedas en el mundo real",desc:"Calcoman\xedas de QR falsas pegadas sobre las reales en parqu\xedmetros, cargadores de autos el\xe9ctricos y mesas de restaurantes redirigen su pago.",color:"#eab308"},{icon:"\uD83D\uDCEC",label:"En cartas y volantes impresos",desc:'"No se pudo entregar su paquete: escanee para reprogramar". Las estafas f\xedsicas enviadas por correo postal parecen m\xe1s leg\xedtimas que las de correo electr\xf3nico.',color:"#3b82f6"},{icon:"\uD83D\uDCB3",label:"C\xf3digos de pago o donaci\xf3n falsos",desc:'Un QR pegado en una caja de recaudaci\xf3n o enviado para un "pago r\xe1pido" env\xeda su dinero al atacante, no a la escuela.',color:"#8b5cf6"}]},{type:"email_exercise",timer:0,title:"\xbfEscanear\xeda esto?",instruction:"Lea el correo y decida: \xbfes un c\xf3digo QR seguro o un intento de quishing?",email:{from:{name:"Seguridad de Microsoft 365",address:"[email protected]"},to:"[email protected]",time:"Hoy, 8:05 a. m.",subject:"Acci\xf3n requerida: vuelva a verificar su cuenta en un plazo de 24 horas",body:"Su organizaci\xf3n ha habilitado nuevas configuraciones de seguridad. Para conservar el acceso a su correo de St. Mary's, debe volver a verificar su cuenta con su dispositivo m\xf3vil.\n\n[ ⢠C\xd3DIGO QR ]\n\nEscanee el c\xf3digo QR de arriba con la c\xe1mara de su tel\xe9fono para confirmar su identidad. Si no realiza la verificaci\xf3n en un plazo de 24 horas, su acceso ser\xe1 suspendido.\n\nEquipo de Seguridad de Microsoft 365",isPhishing:!0,redFlags:[{highlight:"m365-secure-verify.com",explanation:"Microsoft no env\xeda correos de seguridad desde dominios de terceros al azar. Esta no es una direcci\xf3n de Microsoft."},{highlight:"Escanee el c\xf3digo QR",explanation:"Empujarlo a escanear en su TEL\xc9FONO lo traslada a un dispositivo sin herramientas de seguridad: ese es todo el objetivo del quishing."},{highlight:"en un plazo de 24 horas",explanation:"Urgencia artificial para impedir que verifique por los canales normales."},{highlight:"volver a verificar su cuenta",explanation:"La configuraci\xf3n real de MFA se hace dentro de la configuraci\xf3n de su cuenta, nunca escaneando un c\xf3digo que le llega por correo de la nada."}]}}
1,{type:"scenario",timer:0,title:"\xbfQu\xe9 har\xeda usted?",steps:[{text:'Recibe un correo en el trabajo: "La transcripci\xf3n de su mensaje de voz est\xe1 lista: escanee el c\xf3digo QR para escucharlo". Usted no esperaba ning\xfan mensaje de voz. \xbfQu\xe9 hace?',choices:[{label:"Escanearlo con mi tel\xe9fono para escuchar el mensaje de voz",next:1},{label:"Reenviarlo a un compa\xf1ero de trabajo para que lo escanee",next:2},{label:"Reportarlo: un c\xf3digo QR para un mensaje de voz es extra\xf1o",next:3}]},{text:"Lo escane\xf3. La p\xe1gina parec\xeda un inicio de sesi\xf3n de Microsoft y usted ingres\xf3 su contrase\xf1a. Era falsa: los atacantes ahora tienen sus credenciales de la escuela, capturadas en su tel\xe9fono, donde nada marc\xf3 el sitio como sospechoso.",outcome:"bad",lesson:"Nunca escanee un c\xf3digo QR en un correo inesperado. El cuadrado oculta el destino hasta que ya est\xe1 ah\xed.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"Reenviarlo solo traslada la trampa a otra persona, y si esa persona lo escanea, la escuela sigue estando comprometida. Lo correcto es reportarlo, no pasarlo de mano en mano.",choices:[{label:"Reportarlo en su lugar",next:3},{label:"Escanearlo de todos modos",next:1}]},{text:"Lo report\xf3. TI confirm\xf3 una oleada de quishing que afectaba a varios empleados y bloque\xf3 al remitente. El mensaje de voz de su compa\xf1\xeda telef\xf3nica nunca llega como un c\xf3digo QR por correo: verificar a trav\xe9s del sistema real habr\xeda mostrado que no hab\xeda nada esper\xe1ndolo.",outcome:"best",lesson:"Cuando un c\xf3digo QR llega de forma inesperada, tr\xe1telo exactamente como un enlace sospechoso: no lo escanee, rep\xf3rtelo.",choices:[{label:"Continuar",next:-1}]}]},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:"\xbfPor qu\xe9 el quishing es tan eficaz para pasar las defensas?",options:["Los c\xf3digos QR est\xe1n cifrados","El enlace es una imagen, as\xed que los filtros de correo no pueden leerlo","Los tel\xe9fonos son m\xe1s seguros que las computadoras","Los c\xf3digos QR no pueden contener enlaces"],correct:1,explanation:"Como la URL est\xe1 oculta dentro de una imagen, los filtros que analizan enlaces nunca la ven, y usted escanea en un tel\xe9fono con menos protecciones."},{q:'Recibe una carta impresa que dice "escanee para reprogramar su entrega fallida". \xbfQu\xe9 es lo m\xe1s seguro?',options:["Escanearlo: el correo impreso es confiable","Ir directamente al sitio web o la aplicaci\xf3n oficial de la empresa de mensajer\xeda","Escanearlo pero no ingresar una contrase\xf1a","Responder a la carta"],correct:1,explanation:"El correo f\xedsico tambi\xe9n se puede falsificar. Vaya usted mismo a la empresa de mensajer\xeda real en lugar de escanear un c\xf3digo no solicitado."},{q:"Una calcoman\xeda de QR en un parqu\xedmetro lo lleva a una p\xe1gina de pago. \xbfQu\xe9 deber\xeda sospechar?",options:["Nada: est\xe1 en un equipo oficial","Podr\xeda ser una calcoman\xeda falsa colocada sobre la real","Los c\xf3digos QR no se pueden manipular","Solo es riesgoso si pide una contrase\xf1a"],correct:1,explanation:"Las calcoman\xedas de QR falsas colocadas sobre las reales son una estafa com\xfan en el mundo real. Pague a trav\xe9s de la aplicaci\xf3n oficial o de una URL conocida."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["Un c\xf3digo QR es solo un enlace oculto: trate los inesperados como enlaces sospechosos","El quishing se cuela por los filtros de correo porque el enlace es una imagen","Tenga especial cuidado con los c\xf3digos que lo empujan a escanear en su tel\xe9fono","Acceda directamente a los sitios de pago, inicio de sesi\xf3n y entrega: no escanee para llegar ah\xed"]}]},"smishing-vishing":{title:"Estafas por mensaje de texto y llamada (smishing y vishing)",icon:"âï¸",duration:"10 min",slides:[{type:"title",timer:5,title:"Estafas por mensaje de texto y llamada",subtitle:"El phishing no solo llega por correo electr\xf3nico",objectives:["Reconozca las estafas de smishing (mensaje de texto) y vishing (voz)","Defi\xe9ndase de la fatiga de MFA y del phishing de devoluci\xf3n de llamada","Conozca la \xfanica regla que derrota a casi todas"]},{type:"concept",timer:20,title:"Smishing y vishing",content:"El smishing es phishing por mensaje de texto SMS; el vishing es phishing por llamada de voz. Los atacantes los usan porque confiamos en nuestros tel\xe9fonos y respondemos r\xe1pido. Un mensaje de texto se siente personal, y una voz en vivo puede presionarlo en tiempo real de maneras que un correo electr\xf3nico nunca podr\xeda.",stats:[{value:"$1.2B+",label:"perdidos por estafas de texto y llamada en un solo a\xf1o"},{value:"68%",label:"de las personas abren cada mensaje de texto que reciben"},{value:"3 seg",label:"es lo que tarda un identificador de llamadas falsificado en imitar cualquier n\xfamero"}],callout:{icon:"\uD83D\uDCDE",title:"El identificador de llamadas miente",text:'El nombre y el n\xfamero de una llamada entrante pueden estar completamente falsificados. Que aparezca "TI de St. Mary\'s" o incluso el n\xfamero real de su banco no significa nada: cualquiera puede suplantarlo.'}},{type:"keypoints",timer:25,title:"Estafas comunes por texto y llamada",points:[{icon:"\uD83D\uDCE6",label:"Mensajes de texto de paquetes / entregas",desc:'"Su paquete de USPS est\xe1 retenido: pague una tarifa de $1.99 aqu\xed." Una cantidad peque\xf1a y cre\xedble para capturar los datos de su tarjeta.',color:"#ef4444"},{icon:"\uD83C\uDFE6",label:"Alertas de fraude falsas",desc:'"\xbfGast\xf3 $750? Responda NO." Al responder, inician una conversaci\xf3n en la que lo "ayudan" rob\xe1ndole sus credenciales de inicio de sesi\xf3n.',color:"#f97316"},{icon:"\uD83D\uDEE0ï¸",label:"Llamadas de soporte t\xe9cnico / TI",desc:'"Le habla Microsoft: detectamos un virus." Los proveedores reales nunca lo llaman sin previo aviso por su computadora.',color:"#eab308"},{icon:"\uD83D\uDD14",label:"Fatiga de MFA (bombardeo de notificaciones)",desc:'Tienen su contrase\xf1a y llenan su tel\xe9fono de avisos de aprobaci\xf3n de inicio de sesi\xf3n, con la esperanza de que toque "Aprobar" para que se detengan.',color:"#8b5cf6"},{icon:"â©ï¸",label:"Phishing de devoluci\xf3n de llamada",desc:'Un correo electr\xf3nico o mensaje de texto dice "llame a este n\xfamero por un cargo." El n\xfamero es el atacante, listo para convencerlo de darle acceso.',color:"#3b82f6"}]},{type:"scenario",timer:0,title:"Los avisos de aprobaci\xf3n de las 2 a. m.",steps:[{text:'A las 2 a. m. su tel\xe9fono vibra una y otra vez: notificaciones de "\xbfAprobar inicio de sesi\xf3n?" de su cuenta escolar. Usted no intent\xf3 iniciar sesi\xf3n. \xbfQu\xe9 est\xe1 pasando y qu\xe9 hace?',choices:[{label:"Tocar Aprobar para que las notificaciones se detengan",next:1},{label:"Ignorarlas o rechazarlas y cambiar mi contrase\xf1a ahora mismo",next:2},{label:"Voltear el tel\xe9fono y volver a dormir",next:3}]},{text:'Lo aprob\xf3. Ese era un atacante que ya ten\xeda su contrase\xf1a: el aviso era lo \xfanico que se interpon\xeda entre \xe9l y su cuenta. Ahora ya est\xe1 dentro. Esto es "fatiga de MFA", y tocar Aprobar es exactamente lo que quer\xedan.',outcome:"bad",lesson:"Nunca apruebe un aviso de inicio de sesi\xf3n que usted no inici\xf3. Una avalancha de avisos significa que alguien ya tiene su contrase\xf1a: rech\xe1ce el acceso y c\xe1mbiela de inmediato.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"Exactamente. Los avisos repetidos que usted no activ\xf3 significan que su contrase\xf1a ya est\xe1 comprometida. Rechaz\xf3 cada aviso, cambi\xf3 su contrase\xf1a y avis\xf3 a TI. El atacante qued\xf3 fuera.",outcome:"best",lesson:"Rechace los avisos de MFA inesperados, cambie su contrase\xf1a y rep\xf3rtelo. Los avisos se detienen porque se corta el acceso, no porque usted aprobara.",choices:[{label:"Continuar",next:-1}]},{text:"Ignorar los avisos al menos no los dej\xf3 entrar, pero el atacante todav\xeda tiene su contrase\xf1a y seguir\xe1 intent\xe1ndolo. Debe cambiar su contrase\xf1a y avisar a TI, no solo esperar a que pare.",outcome:"good",lesson:"Rechazar est\xe1 bien, pero complete el proceso: cambie la contrase\xf1a comprometida y rep\xf3rtelo para que TI pueda proteger la cuenta.",choices:[{label:"Continuar",next:-1}]}]},{type:"concept",timer:15,title:"La \xfanica regla que las vence a todas",content:"Casi toda estafa por texto y llamada muere en el momento en que usted verifica a trav\xe9s de un canal que usted eligi\xf3. Cuelgue y llame al banco usando el n\xfamero que aparece en su tarjeta. Visite usted mismo el sitio web real de la empresa de entregas.
1Camine por el pasillo para preguntarle al director. El atacante controla el canal por el que lo contact\xf3, as\xed que use uno distinto en el que usted conf\xede.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Cuelgue y devuelva la llamada",text:'Ninguna organizaci\xf3n leg\xedtima se opondr\xe1 a que usted cuelgue y llame a su n\xfamero oficial para confirmar. Cualquiera que lo presione para que "se quede en la l\xednea" le est\xe1 diciendo que es una estafa.'}},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:"Su tel\xe9fono muestra el n\xfamero real de su banco llamando por un fraude. \xbfPuede confiar en \xe9l?",options:["S\xed, el n\xfamero demuestra que son ellos","No, el identificador de llamadas puede falsificarse; cuelgue y llame al n\xfamero que aparece en su tarjeta","S\xed, si saben su nombre","Solo si llaman dos veces"],correct:1,explanation:"El identificador de llamadas se falsifica con suma facilidad. Cuelgue y devuelva la llamada al n\xfamero oficial que usted mismo busque."},{q:'Recibe avisos repetidos de MFA de "\xbfaprobar inicio de sesi\xf3n?" que usted no solicit\xf3. \xbfQu\xe9 significa?',options:["Una falla t\xe9cnica: solo apruebe uno","Alguien ya tiene su contrase\xf1a: rech\xe1ce y c\xe1mbiela","Su tel\xe9fono necesita una actualizaci\xf3n","Nada importante"],correct:1,explanation:"Las solicitudes de MFA no solicitadas significan que su contrase\xf1a est\xe1 comprometida. Rech\xe1ce, cambie la contrase\xf1a y rep\xf3rtelo."},{q:'Un mensaje de texto dice "llame a este n\xfamero por un cargo sospechoso." \xbfQu\xe9 es esto probablemente?',options:["Servicio al cliente \xfatil","Phishing de devoluci\xf3n de llamada: el n\xfamero es el atacante","Un n\xfamero equivocado","Una alerta bancaria leg\xedtima"],correct:1,explanation:"El phishing de devoluci\xf3n de llamada lo induce a marcar el n\xfamero del atacante. En su lugar, use el n\xfamero que aparece en su tarjeta."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["El smishing (texto) y el vishing (voz) explotan lo mucho que confiamos en nuestros tel\xe9fonos","El identificador de llamadas y los n\xfameros de remitente pueden falsificarse: no prueban nada","Nunca apruebe un aviso de MFA que usted no inici\xf3: rech\xe1ce y cambie su contrase\xf1a","Verifique siempre colgando y usando un n\xfamero o sitio web que usted eligi\xf3"]}]},"bec-payment-fraud":{title:"Compromiso del correo de la organizaci\xf3n y fraude de pagos",icon:"\uD83D\uDCB8",duration:"11 min",slides:[{type:"title",timer:5,title:"Compromiso del correo de la organizaci\xf3n y fraude de pagos",subtitle:"La estafa silenciosa que vac\xeda las cuentas bancarias de las escuelas",objectives:["Comprenda c\xf3mo el OEC y el fraude de pagos atacan a las escuelas","Reconozca las estafas de cambio de transferencias, facturas y tarjetas de regalo","Aplique la regla del doble canal antes de mover cualquier dinero"]},{type:"concept",timer:20,title:"\xbfQu\xe9 es el OEC?",content:"El compromiso del correo de la organizaci\xf3n (OEC) ocurre cuando un atacante se hace pasar por alguien en quien usted conf\xeda âel director, un proveedor, la di\xf3cesisâ para enga\xf1arlo y lograr que env\xede dinero o cambie datos de pago. A menudo no hay malware ni enlaces maliciosos, solo un mensaje convincente. Por eso evade los filtros y les cuesta a las organizaciones m\xe1s que cualquier otro delito cibern\xe9tico.",stats:[{value:"$2.9B+",label:"perdidos por OEC en un solo a\xf1o (FBI IC3)"},{value:"#1",label:"el tipo de delito cibern\xe9tico m\xe1s costoso"},{value:"$50K+",label:"p\xe9rdida t\xedpica en un solo incidente escolar"}],callout:{icon:"\uD83D\uDCB8",title:"Por qu\xe9 las escuelas son un blanco",text:"Las escuelas mueven dinero real (colegiaturas, n\xf3mina, proveedores), a menudo con equipos de finanzas peque\xf1os y culturas basadas en la confianza. Los atacantes investigan a su personal en el sitio web y en las redes sociales, y luego atacan en el momento justo."}},{type:"keypoints",timer:25,title:"Las t\xe1cticas principales",points:[{icon:"\uD83C\uDFE6",label:"Cambio de cuenta bancaria de un proveedor",desc:"\xabActualice nuestros datos bancarios para el pago de este mes\xbb. La siguiente factura real termina pag\xe1ndose al atacante.",color:"#ef4444"}
1,{icon:"\uD83E\uDDFE",label:"Facturas falsas o alteradas",desc:"Una factura de aspecto leg\xedtimo de un proveedor de nombre cre\xedble por servicios que no recuerda bien haber solicitado.",color:"#f97316"},{icon:"\uD83C\uDF81",label:"Solicitudes de tarjetas de regalo",desc:"\xabEstoy en una reuni\xf3n: compre $500 en tarjetas de regalo y env\xedeme los c\xf3digos, yo le reembolso\xbb. Siempre es una estafa.",color:"#eab308"},{icon:"\uD83D\uDCB5",label:"Redirecci\xf3n de transferencias / ACH",desc:"Solicitudes urgentes y \xabconfidenciales\xbb para transferir fondos por un acuerdo, un dep\xf3sito o una colegiatura, a una cuenta nueva.",color:"#8b5cf6"},{icon:"\uD83E\uDDD1â\uD83D\uDCBC",label:"Desv\xedo de n\xf3mina",desc:"\xabActualice mi dep\xf3sito directo antes del pago del viernes\xbb. Los sueldos del personal se redirigen al atacante.",color:"#3b82f6"}]},{type:"email_exercise",timer:0,title:"\xbfAprobar este cambio de pago?",instruction:"Usted maneja los pagos a proveedores. \xbfEs seguro actuar seg\xfan esta solicitud?",email:{from:{name:"Riverside Catering",address:"[email protected]"},to:"[email protected]",time:"Hoy, 3:48 p. m.",subject:"Datos bancarios actualizados para el pr\xf3ximo pago",body:"Hola:\n\nGracias por su continua preferencia con St. Mary's. Le informamos que hemos cambiado de banco. Le pedimos amablemente que actualice nuestros registros para que su pr\xf3ximo pago llegue a la cuenta correcta:\n\nNueva cuenta: 8841720094\nRuta (routing): 021000021\n\nConfirme una vez actualizado, ya que nuestra cuenta anterior est\xe1 cerrada. Disculpe las molestias.\n\nCuentas por Cobrar\nRiverside Catering",isPhishing:!0,redFlags:[{highlight:"riverside-catering-accounts.com",explanation:"Un dominio parecido con \xab-accounts\xbb agregado: no es la direcci\xf3n real del proveedor. Comp\xe1relo con correos anteriores que sabe que son leg\xedtimos."},{highlight:"cambiado de banco",explanation:"Una solicitud de cambio de cuenta bancaria es la t\xe1ctica de OEC m\xe1s com\xfan de todas. Verif\xedquela siempre por tel\xe9fono antes de cambiar nada."},{highlight:"cuenta anterior est\xe1 cerrada",explanation:"Presi\xf3n para cambiar r\xe1pido, antes de que pueda confirmar, para que el pr\xf3ximo pago llegue al atacante."},{highlight:"Confirme una vez actualizado",explanation:"Quieren que act\xfae y responda en lugar de levantar el tel\xe9fono y llamar a un n\xfamero conocido."}]}},{type:"scenario",timer:0,title:"La solicitud urgente de transferencia",steps:[{text:"Recibe un correo del director: \xabHoy cerramos la compra del nuevo equipo para el parque infantil. Transfiera ahora el dep\xf3sito de $18,500 al proveedor; adjunto los datos. Mantenga esto confidencial hasta que yo lo anuncie\xbb. \xbfQu\xe9 hace?",choices:[{label:"Transferir el dinero: el director lo pidi\xf3 y es urgente",next:1},{label:"Responder el correo para confirmar los datos",next:2},{label:"Llamar al director a un n\xfamero conocido o ir a hablar con \xe9l en persona",next:3}]},{text:"Envi\xf3 la transferencia. Era un atacante de OEC haci\xe9ndose pasar por el director, quien nunca envi\xf3 ese correo. Los fondos transferidos son casi imposibles de recuperar: los $18,500 se perdieron.",outcome:"bad",lesson:"Urgencia + confidencialidad + una transferencia de dinero es la receta cl\xe1sica del OEC. Nunca mueva fondos bas\xe1ndose solo en un correo.",choices:[{label:"Int\xe9ntelo de nuevo",next:0}]},{text:"Respondi\xf3 para confirmar. El atacante controla ese buz\xf3n (o uno parecido), as\xed que responde con gusto: \xabS\xed, adelante; por favor, ap\xfarese\xbb. Responder solo llega al atacante.",choices:[{label:"Transferir el dinero ahora",next:1},{label:"Llamar al director a un n\xfamero conocido",next:3}]},{text:"Llam\xf3 al director directamente. No ten\xeda idea de lo que le hablaba: no exist\xeda ninguna compra para el parque infantil. Detuvo en seco una p\xe9rdida de $18,500.",outcome:"best",lesson:"Verifique todo cambio de pago o bancario a trav\xe9s de un segundo canal confiable: un n\xfamero de tel\xe9fono conocido o en persona. Convi\xe9rtalo en pol\xedtica, no en una decisi\xf3n al criterio de cada quien.",choices:[{label:"Continuar",next:-1}]}]},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:"Un proveedor le env\xeda por correo nuevos datos bancarios para su pr\xf3ximo pago. \xbfCu\xe1l es el primer paso correcto?",options:["Actualizarlos de inmediato para evitar retrasos","Llamar al proveedor a un n\xfamero conocido para verificar","Responder preguntando si est\xe1n seguros","Reenviarlo a un compa\xf1ero para que se encargue"],correct:1,explanation:"Las solicitudes de cambio bancario son la t\xe1ctica principal del OEC. Confirme siempre por tel\xe9fono usando un n\xfamero que ya tenga."},{q:"\xbfQu\xe9 combinaci\xf3n es la se\xf1al de alerta cl\xe1sica del OEC?",options:["Un tono amable y una firma","Urgencia, confidencialidad y un movimiento de dinero","Un PDF adju
1nto","Un hilo de correo largo"],correct:1,explanation:"La presi\xf3n para actuar r\xe1pido, mantenerlo en secreto y mover dinero es el sello del compromiso del correo de la organizaci\xf3n."},{q:"\xbfPor qu\xe9 los fondos transferidos son especialmente peligrosos en estas estafas?",options:["Se les cobra impuestos dos veces","Son casi imposibles de recuperar una vez enviados","Siempre son cantidades peque\xf1as","Los bancos las revierten autom\xe1ticamente"],correct:1,explanation:"Las transferencias se liquidan r\xe1pido y son muy dif\xedciles de recuperar, que es precisamente por lo que los atacantes las prefieren."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["El OEC se hace pasar por personas en quienes usted conf\xeda, a menudo sin enlaces ni malware que detectar","Las solicitudes de cambio bancario, facturas, tarjetas de regalo, transferencias y n\xf3mina son las t\xe1cticas comunes","Urgencia + confidencialidad + dinero = verifique antes de actuar","Confirme todo cambio de pago o bancario a trav\xe9s de un segundo canal conocido"]}]},"ai-deepfakes":{title:"Amenazas de IA y deepfakes",icon:"\uD83E\uDD16",duration:"10 min",slides:[{type:"title",timer:5,title:"Amenazas de IA y deepfakes",subtitle:"Cuando el correo, la voz y el rostro pueden falsificarse por completo",objectives:["Comprenda c\xf3mo la IA potencia el phishing y la suplantaci\xf3n de identidad","Reconozca clones de voz y videos deepfake",'Conf\xede en la verificaci\xf3n, no en "sonaba como esa persona"']},{type:"concept",timer:20,title:"La IA cambi\xf3 las reglas del juego",content:'Durante a\xf1os, la mala gram\xe1tica y las frases torpes delataban el phishing. La IA borr\xf3 esa se\xf1al. Ahora los atacantes generan correos impecables y personalizados en cualquier idioma en segundos, y pueden clonar una voz a partir de unos pocos segundos de audio o falsificar un rostro en una videollamada. El viejo consejo de "busque errores de ortograf\xeda" ya no es suficiente.',stats:[{value:"~3 seg",label:"de audio necesarios para clonar una voz"},{value:"$25M",label:"robados en una sola estafa por videollamada deepfake"},{value:"1,265%",label:"de aumento del phishing desde que las herramientas de IA se masificaron"}],callout:{icon:"\uD83E\uDD16",title:"La nueva mentalidad",text:"D\xe9 por hecho que un correo convincente, una voz familiar o incluso un rostro en video en vivo pueden ser fabricados. La autenticidad ahora proviene de la verificaci\xf3n, no de lo real que algo parezca o suene."}},{type:"keypoints",timer:25,title:"C\xf3mo se ven los ataques con IA",points:[{icon:"âï¸",label:"Correos de phishing impecables",desc:"Sin errores de ortograf\xeda, con un tono perfecto y personalizados usando datos extra\xeddos del sitio web de su escuela y de las redes sociales.",color:"#ef4444"},{icon:"\uD83C\uDF99ï¸",label:"Clonaci\xf3n de voz (vishing 2.0)",desc:"Una llamada con la voz exacta del director o directora pidi\xe9ndole que act\xfae con urgencia, creada a partir de un clip suyo hablando en l\xednea.",color:"#f97316"},{icon:"\uD83C\uDFA5",label:"Videollamadas deepfake",desc:'Una reuni\xf3n por video en vivo donde el "ejecutivo" que aparece en pantalla es un rostro generado por IA que aprueba una transferencia.',color:"#eab308"},{icon:"\uD83C\uDF10",label:"Sitios y chatbots falsos",desc:'La IA crea p\xe1ginas de inicio de sesi\xf3n falsas muy convincentes y chatbots de "soporte" que recopilan lo que usted escribe.',color:"#8b5cf6"},{icon:"\uD83E\uDDE9",label:"Se\xf1uelos hiperpersonalizados",desc:"La IA rastrea informaci\xf3n p\xfablica para mencionar a sus compa\xf1eros de trabajo, proyectos y horarios reales, logrando que el se\xf1uelo encaje a la perfecci\xf3n.",color:"#3b82f6"}]},{type:"keypoints",timer:20,title:"Si recibe una llamada o video urgente: c\xf3mo responder",points:[{icon:"â¸ï¸",label:"Det\xe9ngase: la urgencia es el arma",desc:'Las estafas con IA lo presionan para que act\xfae antes de pensar. "Ahora mismo", "no le diga a nadie" y "no puedo hablar mucho" son se\xf1ales de alerta, no razones para apresurarse.',color:"#ef4444"},{icon:"\uD83D\uDCDE",label:"Cuelgue y devuelva la llamada",desc:"Termine la llamada y marque a la persona a un n\xfamero que usted ya tenga, nunca a uno que le den durante la llamada. Quien llama de verdad no tendr\xe1 problema con una verificaci\xf3n de 60 segundos.",color:"#f97316"},{icon:"\uD83D\uDD11",label:"Use una palabra clave",desc:"Acuerde una palabra privada con su familia y el personal clave. P\xeddala ante cualquier solicitud urgente de dinero o datos: un clon de voz no la conocer\xe1.",color:"#eab308"},{icon:"\uD83D\uDEAB",label:"Nunca mueva dinero ni datos estando solo en una llamada",desc:"Ninguna transferencia, tarjeta de regalo, c
1ontrase\xf1a ni lista de estudiantes por la sola fuerza de una voz o un rostro. Confirme primero en persona o por un canal conocido.",color:"#8b5cf6"},{icon:"\uD83C\uDFA5",label:"Un rostro en video tampoco es prueba",desc:"Las videollamadas deepfake son reales. P\xeddale a la persona que haga algo espec\xedfico en vivo y, aun as\xed, verifique por separado antes de actuar.",color:"#3b82f6"}]},{type:"scenario",timer:0,title:"La voz al tel\xe9fono",steps:[{text:'Recibe una llamada. Suena exactamente como el director: "Estoy atrapado en una reuni\xf3n de la junta y necesito que env\xede la lista actualizada del personal y que apruebe un pago de $2,000 a un proveedor ahora mismo. No puedo hablar mucho". La voz es inconfundible. \xbfQu\xe9 hace?',choices:[{label:"Hacerlo: claramente es la voz del director",next:1},{label:"Quedarse en la l\xednea y hacer preguntas personales",next:2},{label:"Colgar y devolverle la llamada al director a su n\xfamero conocido",next:3}]},{text:"Actu\xf3 solo con base en la voz. Era un clon de IA creado a partir de un video publicado por el director. La lista y los $2,000 desaparecieron. Una voz familiar ya no es prueba de qui\xe9n llama.",outcome:"bad",lesson:"Una voz puede clonarse a partir de segundos de audio. Nunca act\xfae solo con base en una voz cuando se trate de dinero o datos sensibles.",choices:[{label:"Intente de nuevo",next:0}]},{text:"Buen instinto al indagar, pero un atacante bien preparado puede haber investigado las respuestas, y quedarse en su l\xednea lo mantiene bajo su control. Lo confiable es terminar la llamada y comunicarse usted mismo con la persona.",choices:[{label:"Cuelgue y devuelva la llamada",next:3},{label:"Simplemente hacer lo que pidieron",next:1}]},{text:"Colg\xf3 y llam\xf3 al n\xfamero conocido del director. Nunca estuvo al tel\xe9fono con usted. Frustr\xf3 una estafa de voz deepfake al verificar por un canal que usted eligi\xf3.",outcome:"best",lesson:"Devuelva la llamada a un n\xfamero de confianza. Acuerde una palabra clave verbal sencilla para las solicitudes urgentes, para que su equipo pueda confirmar la identidad al instante.",choices:[{label:"Continuar",next:-1}]}]},{type:"quiz",timer:0,title:"Prueba de conocimientos",questions:[{q:'\xbfPor qu\xe9 el consejo de "busque errores de ortograf\xeda" es m\xe1s d\xe9bil ahora?',options:["La gente escribe mejor","La IA escribe phishing impecable y personalizado en segundos","Los filtros corrigen los errores de ortograf\xeda","La ortograf\xeda nunca import\xf3"],correct:1,explanation:"La IA elimina las se\xf1ales gramaticales que sol\xeda tener el phishing, as\xed que una redacci\xf3n pulida ya no significa que sea seguro."},{q:"Una llamada con la voz exacta de su director le pide transferir dinero con urgencia. \xbfCu\xe1l es la respuesta m\xe1s segura?",options:["Obedecer: la voz demuestra que es esa persona","Colgar y devolver la llamada a un n\xfamero conocido","Pedirle que le escriba un mensaje de texto en su lugar","Transferir una cantidad menor por seguridad"],correct:1,explanation:"Las voces pueden clonarse a partir de clips cortos. Verifique devolviendo la llamada a un n\xfamero de confianza antes de hacer cualquier cosa."},{q:"\xbfCu\xe1l es una defensa s\xf3lida en equipo contra la suplantaci\xf3n de voz o video con IA?",options:["Una palabra clave verbal secreta y compartida para las solicitudes urgentes","Confiar en las videollamadas porque puede ver un rostro","Usar solo el correo electr\xf3nico","Responder m\xe1s r\xe1pido"],correct:0,explanation:"Una palabra clave acordada de antemano le permite confirmar la identidad al instante, incluso cuando la voz o el rostro parecen reales."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["La IA hace que el phishing sea impecable y personal: los errores de ortograf\xeda ya no son la se\xf1al","Las voces e incluso los rostros en video en vivo pueden falsificarse de forma muy convincente","Nunca act\xfae solo con base en una voz o un video cuando se trate de dinero o datos sensibles","Verifique por un canal que usted elija; acuerde una palabra clave para las solicitudes urgentes"]}]},"student-data-privacy":{title:"Protecci\xf3n de los datos de los estudiantes (FERPA y privacidad)",
1icon:"\uD83D\uDEE1ï¸",duration:"10 min",slides:[{type:"title",timer:5,title:"Protecci\xf3n de los datos de los estudiantes",subtitle:"La privacidad, FERPA y su papel como guardi\xe1n de la informaci\xf3n de los estudiantes",objectives:["Comprenda qu\xe9 se considera informaci\xf3n protegida de los estudiantes","Aplique los principios b\xe1sicos de FERPA en las tareas diarias","Evite los errores cotidianos que exponen los registros de los estudiantes"]},{type:"concept",timer:20,title:"Por qu\xe9 importan los datos de los estudiantes",content:"Las escuelas almacenan algunos de los datos m\xe1s delicados que existen: calificaciones, notas m\xe9dicas, direcciones, situaciones familiares y registros de conducta. FERPA (la Ley de Derechos Educativos y Privacidad de la Familia) es la ley federal que protege los registros educativos de los estudiantes. M\xe1s all\xe1 de la ley, proteger estos datos es una cuesti\xf3n de confianza: las familias conf\xedan en que la escuela mantendr\xe1 segura la informaci\xf3n de sus hijos.",stats:[{value:"FERPA",label:"la ley federal que rige los registros de los estudiantes"},{value:"#1",label:"causa de las filtraciones: errores humanos comunes"},{value:"K-12",label:"entre los sectores m\xe1s atacados para el robo de datos"}],callout:{icon:"\uD83D\uDEE1ï¸",title:"Usted es un custodio",text:"Si su funci\xf3n le da acceso a la informaci\xf3n de los estudiantes, usted es su custodio. Comp\xe1rtala \xfanicamente con personas que tengan una necesidad educativa leg\xedtima y solo a trav\xe9s de canales aprobados y seguros."}},{type:"keypoints",timer:25,title:"Reglas cotidianas que protegen a los estudiantes",points:[{icon:"\uD83C\uDFAF",label:"Comparta solo con quien tenga necesidad de saber",desc:"Solo las personas con una raz\xf3n educativa leg\xedtima deben ver los registros de un estudiante, no toda la lista del personal ni un amigo que ense\xf1a en otro lugar.",color:"#22c55e"},{icon:"âï¸",label:"Verifique el destinatario dos veces",desc:"El correo enviado a la persona equivocada es una de las principales causas de filtraciones. Confirme la direcci\xf3n antes de enviar cualquier cosa con nombres, calificaciones o IEP de los estudiantes.",color:"#ef4444"},{icon:"\uD83D\uDD10",label:"Use herramientas aprobadas y seguras",desc:"Mantenga los registros en los sistemas autorizados por la escuela. No traslade las listas a correos personales, unidades personales ni aplicaciones cualesquiera.",color:"#3b82f6"},{icon:"\uD83D\uDDA5ï¸",label:"Bloquee su pantalla",desc:"Si se aleja, bloqu\xe9ela. Los pasillos, las oficinas compartidas y las pantallas proyectadas exponen los datos a cualquiera que pase.",color:"#f97316"},{icon:"\uD83D\uDDD1ï¸",label:"Recopile lo m\xednimo y deseche con cuidado",desc:"No recopile ni conserve m\xe1s de lo necesario. Triture los registros impresos; no los tire al reciclaje.",color:"#8b5cf6"}]},{type:"email_exercise",timer:0,title:"\xbfEs seguro enviar esto?",instruction:"Un padre de familia env\xeda un correo pidiendo informaci\xf3n. Decida c\xf3mo manejarlo.",email:{from:{name:"Jordan Avery",address:"[email protected]"},to:"[email protected]",time:"Hoy, 12:20 p. m.",subject:"Una pregunta r\xe1pida sobre la clase",body:"\xa1Hola! Mi hija me coment\xf3 que su amiga Mia ha tenido dificultades. Como representante de padres de la clase, me encantar\xeda ayudar. \xbfPodr\xeda enviarme la lista de contactos y las calificaciones de los ni\xf1os de la clase para poder organizar un grupo de estudio? \xa1Muchas gracias!\n\nJordan",isPhishing:!1,redFlags:[],legitimateReasons:"Esto no es malware, pero s\xed es una trampa de privacidad. Un padre de familia no tiene derecho a las calificaciones ni a la informaci\xf3n de contacto de otros estudiantes, aunque tenga buenas intenciones. La respuesta correcta es un no cort\xe9s: usted no puede compartir los registros de otros estudiantes, pero s\xed puede transmitir la informaci\xf3n del grupo de estudio a trav\xe9s de canales aprobados. Compartir la lista ser\xeda una violaci\xf3n de FERPA."}},{type:"scenario",timer:0,title:"La solicitud de la lista",steps:[{text:"Un colega de otra escuela le escribe un mensaje de texto: \xabEstamos haciendo un proyecto similar. \xbfPodr\xedas enviarme por correo tu lista completa de estudiantes con las direcciones y las marcas de IEP para adelantar el trabajo?\xbb. \xbfQu\xe9 hace usted?",choices:[{label:"Enviarla: es un colega educador",next:1},{label:"Enviar por correo solo los nombres, eso es inofensivo",next:2},{label:"Negarse y remitirlo a los datos de su propia escuela",next:3}]},{text:"La envi\xf3. Un docente de otra escuela no tiene un inter\xe9s educativo leg\xedtimo en los registros de sus estudiantes: esto es una violaci\xf3n de FERPA, y las direcciones y las marcas de IEP est\xe1n ahora fuera del control de la escuela.",outcome:"bad",lesson:"Ser educador en otro lugar no otorga acceso a los registros de SUS estudiantes. La necesidad de saber es por estudiante, no por profesi\xf3n.",choices:[{label:"Int\xe9ntelo de nuevo",next:0}]},{text:"Incluso \xabsolo los nombres\xbb pueden estar protegidos cuando se vinculan a su clase (revela la inscripci\xf3n), y normaliza el compartir listas por canales no autorizados. La respuesta segura es no enviar ning\xfan dato de los estudiantes a otra escuela.",choices:[{label:"Mejor negarse",next:3},{label:"Enviar la lista completa",next:1}]},{text:"Se neg\xf3 y le sugiri\xf3 que usara los datos y sistemas de su propia escuela. Protegi\xf3 los registros de sus estudiantes y mantuvo a la escuela en cumplimiento de FERPA, sin dejar de ser servicial con el proyecto en s\xed.",outcome:"best",lesson:"Comparta los datos de los estudiantes \xfanicamente con quienes tengan una necesidad educativa leg\xedtima en su escuela, a trav\xe9s de sistemas aprobados. Cuando tenga dudas, consulte a su administrador.",choices:[{label:"Continuar",next:-1}]}]},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:"Un padre representante de la clase pide las calificaciones de otros estudiantes para organizar un grupo de estudio. \xbfQu\xe9 debe hacer?",options:["Enviarlas: es por una buena causa","Negarse cort\xe9smente; no tiene derecho a los registros de otros","Enviar solo las calificaciones, no los nombres","Preguntar primero a los estudiantes"],correct:1,explanation:"Los registros de otros estudiantes est\xe1n protegidos por FERPA. Las buenas intenciones no crean un derecho de acceso a ellos."},{q:"\xbfCu\xe1l es la causa m\xe1s com\xfan de las filtraciones de datos de los estudiantes?",options:["Hackers sofisticados","Errores comunes como el correo enviado a la persona equivocada","Cortes de energ\xeda","Computadoras viejas"],correct:1,explanation:"El error humano cotidiano âdestinatario equivocado, compartir de m\xe1s, pantallas desbloqueadasâ causa la mayor\xeda de las filtraciones. Ir m\xe1s despacio las previene."},{q:"\xbfD\xf3nde deben residir los registros de los estudiantes?",options:["Donde sea conveniente, como el correo personal","\xdanicamente en sistemas escolares aprobados y seguros","En una memoria USB compartida","En una carpeta p\xfablica para acceso f\xe1cil"],correct:1,explanation:"Mantenga los registros en sistemas seguros autorizados por la escuela, nunca en correos personales, unidades ni aplicaciones no aprobadas."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["FERPA protege los registros educativos de los estudiantes, y usted tambi\xe9n deber\xeda hacerlo","Comparta los datos de los estudiantes s
1olo con quien tenga una necesidad leg\xedtima de saber","Verifique dos veces los destinatarios; el correo enviado a la persona equivocada es una de las principales causas de filtraciones","Use sistemas seguros aprobados, bloquee su pantalla y conserve solo lo que necesite"]}]},"beyond-the-inbox":{title:"Estafas m\xe1s all\xe1 de la bandeja de entrada",icon:"\uD83D\uDCE8",duration:"10 min",slides:[{type:"title",timer:5,title:"Estafas m\xe1s all\xe1 de la bandeja de entrada",subtitle:"Las invitaciones de calendario, los archivos compartidos y las solicitudes de firma electr\xf3nica tambi\xe9n pueden ser phishing",objectives:["Reconozca los ataques que llegan como invitaciones de calendario, archivos compartidos y solicitudes de firma electr\xf3nica",'Comprenda por qu\xe9 estos burlan su instinto de "\xbfeste correo es sospechoso?"',"Aplique una regla sencilla a cada notificaci\xf3n, no solo a los correos"]},{type:"concept",timer:15,title:"El phishing sali\xf3 de la bandeja de entrada",content:'Usted ha aprendido a examinar con cuidado los correos. Por eso los atacantes se pasaron a las notificaciones en las que conf\xeda sin pensar: una invitaci\xf3n de calendario que se agrega sola, una alerta de "documento compartido con usted", una solicitud de firma de DocuSign. Estas llegan desde plataformas reales (Google, Microsoft, DocuSign), a menudo esquivan su filtro de spam y persiguen el mismo objetivo: un enlace malicioso o una acci\xf3n apresurada. La confianza que usted deposita en la plataforma es justo lo que el atacante est\xe1 tomando prestado.',stats:[{value:"Reales",label:"plataformas remitentes (Google, DocuSignâ¦)"},{value:"Pasan",label:"la mayor\xeda de los filtros de spam de correo"},{value:"Mismo",label:"objetivo: enlace malicioso o acci\xf3n apresurada"}],callout:{icon:"\uD83C\uDFAD",title:"No es el correo, es la notificaci\xf3n",text:"Una notificaci\xf3n de calendario, de archivo compartido o de firma se siente como parte de la infraestructura, no como un correo. Precisamente por eso funciona. Trate el enlace que contiene exactamente igual que un enlace en un correo sospechoso."}},{type:"keypoints",timer:20,title:"Los vectores a los que estar atento",points:[{icon:"\uD83D\uDCC5",label:"Spam de invitaciones de calendario",desc:'Una invitaci\xf3n a una reuni\xf3n inesperada se agrega sola a su calendario con un enlace para "unirse", "reprogramar" o "revisar la agenda". El enlace lleva a un inicio de sesi\xf3n falso. Rech\xe1cela y elim\xednela; nunca haga clic en enlaces dentro de una invitaci\xf3n que no esperaba.',color:"#ef4444"},{icon:"\uD83D\uDCC2",label:"Invitaciones para compartir archivos y documentos",desc:'"Alguien comparti\xf3 un documento con usted" desde Google Drive, OneDrive o Dropbox, pero usted no conoce a esa persona, o el archivo es una imagen de "Haga clic para ver" que lleva a un sitio externo. Verifique a la persona y vaya directamente a la plataforma, no a trav\xe9s del bot\xf3n del correo.',color:"#f97316"},{icon:"âï¸",label:"Spam de firma electr\xf3nica (DocuSign)",desc:'Una solicitud de "Tiene un documento para firmar" que genera urgencia sobre una factura, un contrato o un formulario de recursos humanos. Los correos leg\xedtimos de firma electr\xf3nica nunca necesitan que usted inicie sesi\xf3n a trav\xe9s de su enlace: abra la plataforma usted mismo o confirme primero con el supuesto remitente.',color:"#eab308"},{icon:"\uD83D\uDD14",label:'Correos falsos de "notificaci\xf3n"',desc:"Alertas de mensajes de voz, fax, documentos escaneados y fotos compartidas que imitan a un servicio para lograr un solo clic. Si no lo esperaba, no haga clic en la vista previa ni en la descarga.",color:"#3b82f6"},{icon:"\uD83D\uDCAC",label:"Invitaciones a herramientas de colaboraci\xf3n",desc:'Invitaciones de Teams, Slack, Zoom o de un "espacio de trabajo para invitados" provenientes de fuera de su organizaci\xf3n. Las invitaciones externas pueden contener enlaces maliciosos o suplantar a compa\xf1eros de trabajo: confirme a trav\xe9s de un canal en el que ya conf\xeda.',color:"#22c55e"}]},{type:"concept",timer:15,title:"La \xfanica regla para cada notificaci\xf3n",content:"Sea cual sea el envoltorio (calendario, archivo compartido, firma electr\xf3nica, mensaje de voz, invitaci\xf3n de chat), la acci\xf3n segura es id\xe9ntica: no act\xfae a trav\xe9s de la notificaci\xf3n. Si una invitaci\xf3n de calendario, un archivo compartido o una solicitud de firma es importante, abra usted mismo la a
1plicaci\xf3n real (calendar.google.com, su cuenta de DocuSign, el Drive verdadero) y revise ah\xed. Inesperado + un enlace o un inicio de sesi\xf3n = det\xe9ngase y verifique a trav\xe9s de un canal que usted controle. Y cuando algo le parezca extra\xf1o, use Reportar como sospechoso: estos merecen figurar en sus reportes igual que los correos de phishing.",stats:[{value:"Abra",label:"usted mismo la aplicaci\xf3n real"},{value:"Nunca",label:"inicie sesi\xf3n a trav\xe9s del enlace de la notificaci\xf3n"},{value:"Reporte",label:"cualquier cosa inesperada"}],callout:{icon:"\uD83D\uDEE1ï¸",title:"El mismo instinto, nuevos envoltorios",text:"Usted ya sabe que no debe hacer clic en el enlace de un correo sospechoso. Extienda ese mismo instinto a cada invitaci\xf3n, archivo compartido y solicitud de firma. El envoltorio cambi\xf3; la regla no."}},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:'Una invitaci\xf3n de calendario que usted no esperaba se agrega sola, con un enlace para "revisar la agenda". \xbfQu\xe9 hace?',options:["Hacer clic en el enlace para ver de qu\xe9 es la reuni\xf3n","Rechazarla o eliminarla y no hacer clic en el enlace","Aceptarla por cortes\xeda","Reenviarla a su equipo"],correct:1,explanation:"Las invitaciones de calendario inesperadas con enlaces son un vector de phishing conocido. Rech\xe1cela, elim\xednela y nunca haga clic en el enlace incrustado."},{q:'Recibe un correo de "DocuSign â documento listo para firmar" que genera urgencia sobre una factura. \xbfCu\xe1l es la acci\xf3n m\xe1s segura?',options:['Hacer clic en "Revisar documento" e iniciar sesi\xf3n',"Abrir directamente su cuenta de DocuSign, o confirmar primero con el remitente","Responder con su contrase\xf1a","Ignorar todo DocuSign para siempre"],correct:1,explanation:"Nunca inicie sesi\xf3n a trav\xe9s del enlace de la notificaci\xf3n. Vaya usted mismo a la plataforma real o verifique con el supuesto remitente a trav\xe9s de un canal conocido."},{q:"\xbfPor qu\xe9 las estafas de calendario, archivos compartidos y firma electr\xf3nica burlan a personas que son cuidadosas con el correo?",options:["Est\xe1n cifradas",'Llegan como notificaciones confiables de plataformas reales, no como "correos" evidentes',"Siempre est\xe1n en la carpeta de spam","Nunca contienen enlaces"],correct:1,explanation:'Toman prestada la confianza que usted deposita en Google, DocuSign y plataformas similares: la notificaci\xf3n se siente como parte de la infraestructura, as\xed que la guardia habitual de "\xbfeste correo es sospechoso?" nunca se activa.'},{q:"\xbfCu\xe1l es la \xfanica regla que cubre por igual las invitaciones de calendario, los archivos compartidos, las solicitudes de firma electr\xf3nica y las invitaciones de chat?",options:["Abrirlas solo en su tel\xe9fono","No actuar a trav\xe9s de la notificaci\xf3n: abrir usted mismo la aplicaci\xf3n real y verificar","Aceptar siempre las invitaciones de su dominio","Eliminar cada notificaci\xf3n autom\xe1ticamente"],correct:1,explanation:"Sea cual sea el envoltorio, no act\xfae a trav\xe9s del enlace de la notificaci\xf3n. Abra usted mismo la aplicaci\xf3n real y verifique; reporte cualquier cosa inesperada."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["El phishing llega como invitaciones de calendario, archivos compartidos, solicitudes de firma electr\xf3nica e invitaciones de chat, no solo como correos","Estos toman prestada la confianza que usted da a plataformas reales (Google, DocuSign) y a menudo esquivan los filtros de spam","Nunca inicie sesi\xf3n ni act\xfae a trav\xe9s del enlace de la notificaci\xf3n: abra usted mismo la aplicaci\xf3n real y verifique","Reporte las invitaciones inesperadas y las solicitudes de compartir o firmar igual que reporta los correos sospechosos"]}]},"trusted-reporter":{title:"Reportero de confianza",icon:"\uD83D\uDCE2",duration:"8 min",slides:[{type:"title",timer:5,title:"Reportero de confianza",subtitle:"Domine los botones de reporte y convi\xe9rtase en una voz de confianza que ayuda a proteger a toda su organizaci\xf3n",objectives:["Sepa exactamente qu\xe9 bot\xf3n de reporte usar, y cu\xe1ndo","Comprenda c\xf3mo se genera una Alerta comunitaria: por el consenso de reporteros de confianza como usted","Sepa qui\xe9n puede generar una alerta instant\xe1nea (sus administradores y los Reporteros de la organizaci\xf3n que ellos elijan)"]},{type:"concept",timer:15,title:"Su barra de herramientas de reporte",content:'Cuando ThouShaltNotClick revisa un correo, muestra una peque\xf1a insignia con botones de acci\xf3n r\xe1pida. Para los usuarios comunes solo hay dos acciones de reporte, y hacen cosas muy distintas, as\xed que conviene saber cu\xe1ndo usar cada una. (El bot\xf3n \uD83E\uDD16 solo abre un an\xe1lisis de IA m\xe1s detallado; no es un reporte. El bot\xf3n \uD83D\uDCE2 de Alerta comunitaria instant\xe1nea aparece \xfanicamente para los administradores de su organizaci\xf3n, adem\xe1s del personal de confianza que ellos hayan elegido espec\xedficamente como "Reporteros de la organizaci\xf3n"; m\xe1s sobre esto en un momento.)',stats:[{value:"\uD83E\uDDD0",label:"Reportar como sospechoso"},{value:"â",label:"Marcar como seguro"},{value:"\uD83E\uDD16",label:"An\xe1lisis de IA"}],image:"/training/tsnc-badge.png",imageAlt:"La insignia de confianza de ThouShaltNotClick sobre un correo en la bandeja de entrada, con los botones Reportar como sospechoso, Marcar como seguro y An\xe1lisis de IA",imageCaption:"As\xed se ve la insignia sobre un mensaje en tu bandeja de entrada: los botones \uD83E\uDDD0 Reportar como sospechoso, â Marcar como seguro y \uD83E\uDD16 An\xe1lisis de IA aparecen justo en el correo."},{type:"keypoints",timer:20,title:"Qu\xe9 bot\xf3n y cu\xe1ndo",points:[{icon:"\uD83E\uDDD0",label:"Reportar como sospechoso: su herramienta de todos los d\xedas",desc:"Cualquier cosa que le parezca extra\xf1a: un enlace raro, un archivo adjunto inesperado, una oferta demasiado buena para ser verdad, una suplantaci\xf3n. Marca al remitente de forma privada para su revisi\xf3n. No hay ning\xfan problema con reportar de m\xe1s; ante la duda, reporte.",color:"#c0392b"},{icon:"â",label:"Marcar como seguro: para remitentes en los que conf\xeda",desc:"Para remitentes que sabe que son reales (su director, un proveedor real, un padre o madre de familia). Reduce las falsas alarmas para todos y fortalece la reputaci\xf3n de confianza del remitente.",color:"#228a4a"},{icon:"\uD83D\uDCE2",label:"Alerta comunitaria: se genera autom\xe1ticamente",desc:'Para la mayor\xeda de los usuarios no existe un bot\xf3n de "avisar a todos". En cambio, cuando suficientes Reporteros de confianza marcan al MISMO remitente (su escuela define el n\xfamero, por lo general dos), TSNC alerta autom\xe1ticamente a toda su organizaci\xf3n. Sus administradores de la organizaci\xf3n o de TI, y cualquier miembro del personal de confianza que hayan elegido como "Reporteros de la organizaci\xf3n", tambi\xe9n pueden generar una al instante. As\xed que lo m\xe1s poderoso que puede hacer es reportar con precisi\xf3n.',color:"#000000"}]},{type:"reporting_demo",timer:0,title:"Pru\xe9belo: \xbfqu\xe9 acci\xf3n corresponde?",instruction:'Esto es exactamente lo que ve en su bandeja de entrada. Haga clic en la insignia de confianza para ampliarla y luego haga clic en cada una de las tres acciones para conocer qu\xe9 hacen. Cambie entre los tres correos reales para ver qu\xe9 acci\xf3n corresponde a cada uno. (Observe que no hay un bot\xf3n manual de "avisar a todos"; eso ocurre autom\xe1ticamente.)',order:["report","safe","ai"],examples:[{label:"\uD83C\uDF81 Estafa de tarjetas de regalo",from:{name:"Director Dawson",address:"[email protected]"},time:"8:42 AM",subject:"Un favor r\xe1pido: necesito que se encargue de esto con discreci\xf3n",body:"Hola,\n\n\xbfEst\xe1 en su escritorio? Estoy en reuniones una tras otra y no puedo hablar. Necesito que compre 5 tarjetas de regalo de Apple ($100 cada una) para una sorpresa de agradecimiento al personal. Por ahora, que quede entre nosotros.\n\nEnv\xedeme los c\xf3digos por mensaje de texto en cuanto los tenga. Le reembolsar\xe9 esta tarde.\n\nGracias,\nDirector Dawson",trustScore:8,band:"danger",rating:"Peligroso",findings:['El dominio del remitente "gmaii-secure.net" suplanta a su director; no es el dominio real de su distrito',"Patr\xf3n cl\xe1sico de estafa: tarjetas de regalo + secreto + urgencia","La direcci\xf3n de respuesta no coincide con el nombre que se muestra"],recommended:"report"},{label:"\uD83E\uDDFE Factura dudosa",from:{name:"Brightline Supplies",address:"[email protected]"},time:"Yesterday, 3:17 PM",subject:"Factura #INV-20418: pago vencido",body:"Hola,\n\nSeg\xfan nuestros registros, la factura #INV-20418 por materiales para el aula ($1,240.00) tiene ahora 14 d\xedas de atraso. Por favor, realice el pago usando los datos bancarios actualizados en el PDF adju
1nto para evitar un cargo por mora.\n\nSi cree que se trata de un error, responda a este correo.\n\nSaludos,\nCuentas por cobrar\nBrightline Supplies",trustScore:47,band:"caution",rating:"Tenga precauci\xf3n",findings:["El nombre del proveedor es plausible, pero usted no reconoce esta factura en particular",'Los "datos bancarios actualizados" en un archivo adjunto son una t\xe1ctica com\xfan para redirigir el pago',"Un archivo adjunto o enlace malicioso hace que esto valga la pena reportar; ante la duda, rep\xf3rtelo"],recommended:"report"},{label:"â
Colega leg\xedtima",from:{name:"Maria Santos (Recepci\xf3n)",address:"[email protected]"},time:"9:05 AM",subject:"Permisos para la excursi\xf3n: se entregan el viernes",body:"Hola equipo,\n\nSolo un recordatorio de que los permisos firmados para la excursi\xf3n al museo de la pr\xf3xima semana deben entregarse en recepci\xf3n antes del viernes a las 3 p. m. Adjunt\xe9 la lista principal para que pueda marcar a sus estudiantes.\n\n\xa1Av\xedseme si necesita copias adicionales!\n\nGracias,\nMaria",trustScore:94,band:"safe",rating:"Parece seguro",findings:["El remitente est\xe1 en el dominio real de su distrito (yourdistrict.org)","Solicitud interna normal, sin urgencia, secreto ni pedido de pago","Usted reconoce a esta persona y el contexto"],recommended:"safe"}],actions:{report:{icon:"\uD83E\uDDD0",name:"Reportar como sospechoso",desc:"Marca a este remitente de forma privada para su revisi\xf3n. NO avisa de inmediato a sus compa\xf1eros, pero cuenta: una vez que suficientes Reporteros de confianza marcan al mismo remitente (su escuela define el n\xfamero, por lo general dos), TSNC alerta autom\xe1ticamente a toda su organizaci\xf3n. \xdaselo siempre que algo le parezca extra\xf1o; no hay ning\xfan problema con reportar de m\xe1s."},safe:{icon:"â",name:"Marcar como seguro",desc:"Le indica a TSNC que este remitente es leg\xedtimo. Reduce las falsas alarmas para todos y fortalece la reputaci\xf3n de confianza del remitente en toda su organizaci\xf3n. \xdaselo solo para remitentes que realmente reconoce."},ai:{icon:"\uD83E\uDD16",name:"An\xe1lisis de IA",desc:"Abre un desglose m\xe1s detallado y en lenguaje sencillo de por qu\xe9 este correo obtuvo su puntuaci\xf3n: los enlaces, el historial del remitente y las se\xf1ales de alerta. Esto es solo informaci\xf3n; no reporta ni cambia nada."}}},{type:"concept",timer:20,title:"C\xf3mo se genera una Alerta comunitaria",content:'Como Reportero de confianza, NO obtiene un bot\xf3n para avisar a todos por su cuenta; las alertas se generan por acuerdo, no por una sola persona. As\xed funciona: (1) Usted y otros Reporteros de confianza reportan como sospechosos a los remitentes que encuentran. (2) Una vez que suficientes Reporteros de confianza marcan al MISMO remitente (su escuela define el n\xfamero, y comienza en dos), TSNC genera autom\xe1ticamente una Alerta comunitaria: el remitente queda marcado como peligroso en toda la organizaci\xf3n, su puntuaci\xf3n de confianza baja en todas las pantallas y se notifica a sus administradores. (3) Dos grupos S\xcd pueden alertar al instante, con un solo clic: sus administradores de la organizaci\xf3n o de TI, y unos pocos miembros del personal de confianza que c
1ada escuela puede elegir como "Reporteros de la organizaci\xf3n". Este modelo de consenso significa que ning\xfan reportero com\xfan puede avisar por s\xed solo a toda la organizaci\xf3n, y son los reporteros precisos los que lo hacen funcionar.',stats:[{value:"2+",label:"reporteros de confianza (definido por su escuela)"},{value:"1 clic",label:"administradores y Reporteros de la organizaci\xf3n"},{value:"100%",label:"registrado para revisi\xf3n"}],callout:{icon:"\uD83D\uDD12",title:"Su estatus, su responsabilidad",text:'Completar este curso lo convierte en Reportero de confianza: sus reportes cuentan para el consenso que genera una alerta. No le otorga un bot\xf3n individual de "avisar a todos" (eso es solo para los administradores y los Reporteros de la organizaci\xf3n que ellos elijan). Reporte con honestidad; cada reporte se registra y se revisa, y el uso indebido puede costarle su estatus.'}},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:"Un correo le parece un poco extra\xf1o, pero no est\xe1 seguro de que sea phishing. \xbfQu\xe9 bot\xf3n usa?",options:["\uD83E\uDDD0 Reportar como sospechoso","â Marcar como seguro","No hacer nada","Reenviarlo a un compa\xf1ero"],correct:0,explanation:"Ante la duda, use Reportar como sospechoso: es privado y se revisa. No hay ning\xfan problema con reportar de m\xe1s."},{q:"\xbfC\xf3mo se convierte un remitente en una Alerta comunitaria para toda su organizaci\xf3n?",options:["Cualquier usuario hace clic en un bot\xf3n de alerta","Cuando suficientes Reporteros de confianza (su escuela define el n\xfamero, por lo general dos) marcan al mismo remitente, o cuando un administrador o Reportero de la organizaci\xf3n genera una al instante","TSNC elimina el correo autom\xe1ticamente","Nunca ocurre autom\xe1ticamente"],correct:1,explanation:"Una Alerta comunitaria se genera por consenso: su escuela define cu\xe1ntos Reporteros de confianza se necesitan (comienza en dos). Los administradores y los Reporteros de la organizaci\xf3n designados tambi\xe9n pueden generar una al instante."},{q:"Como Reportero de confianza, \xbfpuede enviar una Alerta comunitaria instant\xe1nea usted solo?",options:["S\xed: completar esta capacitaci\xf3n me da ese bot\xf3n","No: mis reportes cuentan para el consenso; solo los administradores y los Reporteros de la organizaci\xf3n elegidos por ellos alertan al instante","S\xed, hasta 5 veces al d\xeda","Solo los fines de semana"],correct:1,explanation:"Ser Reportero de confianza significa que sus reportes tienen peso para el consenso; NO le otorga un bot\xf3n de alerta individual. Las alertas instant\xe1neas est\xe1n reservadas para los administradores y los Reporteros de la organizaci\xf3n que ellos designen."},{q:"Un estafador que suplanta a su director env\xeda correos a varios miembros del personal pidiendo tarjetas de regalo. Como Reportero de confianza, \xbfqu\xe9 hace?",options:["Nada: espero a un administrador","Reportar como sospechoso, y una vez que suficientes Reporteros de confianza tambi\xe9n lo hacen, se alerta autom\xe1ticamente a la organizaci\xf3n","Marcar como seguro","Responder para hacer preguntas"],correct:1,explanation:"Rep\xf3rtelo. Los remitentes peligrosos suelen ser detectados por m\xe1s de un reportero, y una vez que el umbral de Reporteros de confianza de su escuela marca al mismo remitente, se avisa a todos autom\xe1ticamente."},{q:"\xbfQu\xe9 significa ser Reportero de confianza?",options:["Puede avisar a toda la organizaci\xf3n con un solo clic","Sus reportes cuentan para el consenso de alerta autom\xe1tica, y cada reporte se registra y se revisa","Puede marcar a cualquier remitente como seguro de forma permanente","No cambia nada"],correct:1,explanation:"Los reportes de los Reporteros de confianza tienen un peso adicional: suficientes reporteros de acuerdo alertan autom\xe1ticamente a la organizaci\xf3n. Los reportes se registran; el uso indebido puede costarle su estatus."}]},{type:"complete",timer:5,title:"\xa1Ahora es un Reportero de confianza!",takeaways:["Reportar como sospechoso = su herramienta de todos los d\xedas para cualquier cosa que le parezca extra\xf1a","Marcar como seguro = decirnos que un remitente es leg\xedtimo","Que suficie
1ntes Reporteros de confianza marquen al mismo remitente (su escuela define el n\xfamero, por lo general dos) alerta autom\xe1ticamente a toda su organizaci\xf3n","NO obtiene un bot\xf3n de alerta individual; los administradores y los Reporteros de la organizaci\xf3n que ellos elijan son los \xfanicos que alertan al instante"]}]},"permission-to-push-back":{title:"Est\xe1 bien preguntar",icon:"â",duration:"10 min",isPublic:!0,curriculum:!0,slides:[{type:"title",timer:5,title:"Est\xe1 bien preguntar",subtitle:"Por qu\xe9 la solicitud le lleg\xf3 a usted, y qu\xe9 hacer al respecto",objectives:["Interprete por qu\xe9 una solicitud fue dirigida espec\xedficamente a usted","Nombre las tres cosas ante las cuales debe detenerse, aunque cada una parezca normal","Sepa qu\xe9 hacer cuando no puede verificar y el plazo es real"]},{type:"concept",timer:20,title:"La 1:47 de un jueves",content:"Es la 1:47 de un jueves. Debe volver con su clase en ocho minutos y hay un padre de familia esperando en el pasillo. Llega un correo de su directora: la oficina del distrito necesita hoy la lista de octavo grado ânombres, grados y correos de los padresâ. Env\xedela de una vez y no la pase por la oficina, la lista todav\xeda no es definitiva.\n\nEn ese mensaje nadie le pide un pago. No trae ning\xfan archivo adjunto. No hay ning\xfan enlace en qu\xe9 hacer clic. Fue escrito para la versi\xf3n cansada de usted, en pleno pasillo, que no quiere ser el motivo por el que la oficina del distrito se queda esperando.",callout:{icon:"\uD83E\uDDED",title:"Una pregunta distinta",text:"La mayor\xeda de las capacitaciones le ense\xf1an qu\xe9 detectar. Esta le pregunta otra cosa: \xbfpor qu\xe9 le lleg\xf3 esto a usted? Esa pregunta sigue funcionando con un ataque que nadie ha catalogado todav\xeda."},variantKey:"opening"},{type:"concept",timer:20,title:"Por qu\xe9 le lleg\xf3 a usted",content:"Los atacantes leen el sitio web de su escuela como si fuera un directorio de personal. Su nombre, su cargo, el bolet\xedn que menciona que usted coordina el consejo estudiantil, el pie de foto que nombra a su directora. Diez minutos de lectura le dicen a alguien a qui\xe9n suplantar, a qui\xe9n escribirle y qu\xe9 plazo va a sonar real.\n\nA los l\xedderes los suplantan. Al personal le llega la solicitud. Y una solicitud que parece venir de su directora llega con un costo por cuestionarla: preguntar \xab\xbfde verdad es usted?\xbb puede sentirse como una insubordinaci\xf3n.\n\nEse es un problema de permiso, no de conocimiento.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Los filtros ayudan. No terminan el trabajo.",text:"Un filtro puede atrapar un dominio parecido o marcar a un remitente externo. Lo que no puede saber es si a usted siquiera debieron pedirle esa lista. Ese criterio es suyo."},variantKey:"whyYou"},{type:"keypoints",timer:25,title:"Interrogue la solicitud, no al remitente",points:[{icon:"\uD83C\uDFAF",label:"\xbfPor qu\xe9 yo?",desc:"\xbfEsta solicitud es parte de mi trabajo? Si no lo es, esa es la se\xf1al m\xe1s fuerte que existe.",color:"#ef4444"},{icon:"â±",label:"\xbfPor qu\xe9 ahora?",desc:"\xbfQui\xe9n puso este plazo? La urgencia que usted no eligi\xf3 es la herramienta de otra persona.",color:"#f97316"},{icon:"\uD83E\uDD10",label:"\xbfPor qu\xe9 en silencio?",desc:"La confidencialidad es normal en una escuela. Confidencial y urgente y valioso, las tres cosas a la vez, no.",color:"#eab308"},{icon:"\uD83D\uDD00",label:"\xbfPor qu\xe9 aqu\xed?",desc:"\xbfEsta persona normalmente me escribir\xeda por correo para esto? Las solicitudes reales llegan por donde siempre han llegado.",color:"#22c55e"},{icon:"\uD83D\uDEAA",label:"\xbfQu\xe9 entrego si digo que s\xed?",desc:"Dinero, una contrase\xf1a, el c\xf3digo de una puerta o una lista de ni\xf1os y sus padres. Algunas de esas cosas no se pueden recuperar.",color:"#3b82f6"}]},{type:"scenario",timer:0,title:"La lista se entrega hoy",steps:[{text:"Volvamos a la 1:47. La lista de octavo grado se entrega hoy a la oficina del distrito y su directora se la pidi\xf3 directamente. \xbfQu\xe9 hace?",choices:[{label:"Enviarla: ella la pidi\xf3",next:1},{label:"Responder el correo para confirmar",next:2},{label:"Llamarla al n\xfamero que usted ya tiene",next:3},{label:"Ir a la oficina y preguntar",next:4}]},{text:"Enviada. La direcci\xf3n de respuesta era un dominio falso, casi id\xe9ntico al real. Los nombres y los datos de contacto de esas fam
1ilias ya est\xe1n en un lugar al que usted no puede llegar, y una lista de alumnos ya enviada no se recupera.",outcome:"bad",lesson:"Un plazo real nunca vuelve seguro un env\xedo sin verificar. La lista era el objetivo desde el principio.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"La respuesta llega en segundos: \xabEstoy en una reuni\xf3n, solo env\xedela\xbb. Lo cual no prueba nada. Una respuesta solo llega a quien envi\xf3 el correo.",choices:[{label:"Enviarla",next:1},{label:"Llamarla al n\xfamero que usted ya tiene",next:3}]},{text:"Buz\xf3n de voz. Est\xe1 fuera de la escuela hasta ma\xf1ana. El plazo sigue siendo hoy, y ahora usted no tiene salida.",choices:[{label:"Enviarla y resolverlo ma\xf1ana",next:1},{label:"Preguntarle a alguien m\xe1s que est\xe9 al tanto",next:4}]},{text:"En la oficina no hay ninguna solicitud de ese tipo, y nadie pidi\xf3 jam\xe1s esa lista. Nadie envi\xf3 ese correo.\n\n\xbfY si hubiera sido aut\xe9ntico? La lista habr\xeda salido una hora m\xe1s tarde de lo que pudo haber salido. Ese es todo el costo de verificar.",outcome:"best",lesson:"\xbfNo logra comunicarse con quien se lo pidi\xf3? Preg\xfantele a otra persona que est\xe9 al tanto. Una lista que llega tarde tiene arreglo. Una lista ya enviada, no.",choices:[{label:"Continuar",next:-1}]}],variantKey:"scenario"},{type:"concept",timer:20,title:"Tiene derecho a preguntar",content:"Esto es lo que la capacitaci\xf3n en seguridad suele omitir: verificar tiene un costo social. Puede que usted d\xe9 la impresi\xf3n de ir demasiado despacio. Puede que d\xe9 la impresi\xf3n de no confiar en su directora. Ese costo es real, y fingir lo contrario ser\xeda insultante.\n\nTambi\xe9n es peque\xf1o y superable. Una directora levemente molesta un jueves es un problema de jueves. Una lista de ni\xf1os que ya sali\xf3 del edificio, no.\n\nAs\xed que tenga la frase lista antes de necesitarla.",callout:{icon:"\uD83D\uDCAC",title:"Cuando no logra comunicarse",text:"Preg\xfantele a una segunda persona que est\xe9 al tanto: la oficina, el administrador de la escuela, quien sea que maneje el proceso. Y responda esto: \xabCon gusto se la env\xedo. Solo necesito confirmar primero por tel\xe9fono o con la oficina; si es urgente, \xbfqui\xe9n m\xe1s puede autorizarlo?\xbb. Eso le da tiempo sin negarle nada a nadie."}},{type:"quiz",timer:0,title:"Verificaci\xf3n de conocimientos",questions:[{q:"Un mensaje le pide algo que est\xe1 fuera de su trabajo, para hoy, y le pide que no involucre a la oficina. \xbfQu\xe9 parte importa m\xe1s?",options:["La ortograf\xeda y la gram\xe1tica","Que las tres cosas llegaron juntas, aunque cada una por separado sea algo com\xfan","La hora del d\xeda en que se envi\xf3","Si trae un archivo adjunto"],correct:1,explanation:"Cada una de esas cosas es normal en una escuela por s\xed sola. Fuera de su cargo, urgente y en silencio: las tres juntas son la combinaci\xf3n por la que vale la pena detenerse."},{q:"Usted responde el correo para comprobar que de verdad es esa persona, y le contestan \xabs\xed, soy yo\xbb. \xbfQu\xe9 confirm\xf3?",options:["Que la solicitud es aut\xe9ntica","Nada: una respuesta solo llega a quien envi\xf3 el correo","Que esa persona est\xe1 en su escritorio","Que la direcci\xf3n es v\xe1lida"],correct:1,explanation:"Al responder, usted se queda dentro del canal que controla el remitente. Confirme por un medio que esa persona no eligi\xf3: un n\xfamero conocido o en persona."},{q:"No puede localizar a quien lo envi\xf3 y el plazo de verdad es hoy. \xbfCu\xe1l es la mejor decisi\xf3n?",options:["Enviarla y resolverlo ma\xf1ana","Negarse hasta que regrese","Confirmar por otra v\xeda que usted elija âotra persona que est\xe9 al tanto, o el n\xfamero de la organizaci\xf3n que usted misma busqueâ y avisarle a quien lo pidi\xf3 que est\xe1 verificando","Reenviarlo a otras personas para preguntar si se ve bien"],correct:2,explanation:"Confirmar por una v\xeda que usted eligi\xf3 responde la pregunta sin tener que decirle que no a nadie, y sirve igual si tiene toda una oficina alrededor o si est\xe1 completamente sola. Aplazar con cortes\xeda cuesta una hora; enviar cuesta todo lo que hay en la lista."}]},{type:"complete",timer:5,title:"\xa1Lecci\xf3n completada!",takeaways:["Preg\xfantese por qu\xe9 una solicitud le lleg\xf3 a usted: esa pregunta funciona con ataques que nadie ha catalogado todav\xeda","Confidencial, urgente y valioso: las tres cosas juntas son el patr\xf3n ante el que debe detenerse","Una respuesta solo llega a quien envi\xf3 el correo: confirme por un canal que usted eligi\xf3","\xbfNo logra comunicarse? Preg\xfantele a otra persona que est\xe9 al tanto, y use Reportar como sospechoso si aun as\xed algo no le cuadra"]}],variants:{"just-me":{whyYou:{content:"Ning\xfan empleador publica una p\xe1gina sobre usted, as\xed que leen lo que ya es p\xfablico. Un correo antiguo aparecido en una filtraci\xf3n, un perfil que menciona su ciudad, una respuesta p\xfablica a la cuenta de soporte de su banco. Nada de eso requiere una investigaci\xf3n. Le dice a alguien a qu\xe9 instituci\xf3n suplantar, a qu\xe9 buz\xf3n escribirle y qu\xe9 amenaza va a sonar real.\n\nA las instituciones las suplantan. A usted le llega la solicitud. Y una advertencia que parece venir de su banco llega con un costo por cuestionarla: preguntar \xab\xbfde verdad son ustedes?\xbb puede sentirse como ponerse dif\xedcil con la instituci\xf3n que tiene su dinero.\n\nEse es un problema de permiso, no de conocimiento.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Los filtros ayudan. No terminan el trabajo.",text:"Un filtro puede atrapar un dominio parecido o marcar un mensaje como sospechoso. Lo que no puede saber es si a usted siquiera debieron pedirle sus preguntas de seguridad. Ese criterio es suyo."}},opening:{title:"Las 7:40 de un martes",content:"Son las 7:40 de la noche de un martes. Las compras siguen sobre la mesa de la cocina y el d\xeda por fin termin\xf3. Llega un correo del equipo antifraude de su banco: alguien intent\xf3 iniciar sesi\xf3n en su cuenta desde un dispositivo nuevo y, si no confirma sus datos esta noche, la cuenta quedar\xe1 bloqueada. Es la cuenta de la que sale todo. Responda con su fe
1cha de nacimiento, su n\xfamero de cuenta y las respuestas a sus preguntas de seguridad; y no use la aplicaci\xf3n, no mostrar\xe1 la alerta hasta que termine la revisi\xf3n.\n\nEn ese mensaje nadie le pide un pago. No trae ning\xfan archivo adjunto. No hay ning\xfan enlace en qu\xe9 hacer clic. Fue escrito para la versi\xf3n cansada de usted, al final de un d\xeda largo, que no quiere despertar sin acceso a su propio dinero."},scenario:{title:"La cuenta se bloquea esta noche",steps:[{text:"Volvamos a las 7:40. La cuenta se bloquea durante la noche si usted no confirma, y el mensaje ven\xeda del banco. \xbfQu\xe9 hace?",choices:[{label:"Responder con los datos",next:1},{label:"Responder y preguntar si es aut\xe9ntico",next:2},{label:"Llamar al n\xfamero que aparece en su tarjeta",next:3},{label:"Abrir la aplicaci\xf3n del propio banco y revisar",next:4}]},{text:"Enviado. La direcci\xf3n de respuesta era un dominio falso, casi id\xe9ntico al real. Su fecha de nacimiento y sus respuestas de seguridad ya est\xe1n en un lugar al que usted no puede llegar y, a diferencia de una contrase\xf1a, su fecha de nacimiento no se puede cambiar.",outcome:"bad",lesson:"Un plazo real nunca vuelve segura una respuesta sin verificar.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"La respuesta llega en segundos: \xabS\xed, somos nosotros, por favor termine de verificar\xbb. Lo cual no prueba nada. Una respuesta solo llega a quien envi\xf3 el correo.",choices:[{label:"Responder con los datos",next:1},{label:"Llamar al n\xfamero que aparece en su tarjeta",next:3}]},{text:"M\xfasica de espera. La fila es larga y la cuenta se bloquea esta noche. Ahora usted no tiene salida.",choices:[{label:"Responder ahora y resolverlo ma\xf1ana",next:1},{label:"Abrir la aplicaci\xf3n del propio banco y revisar",next:4}]},{text:"La aplicaci\xf3n abre como siempre. No hay alerta, no hay dispositivo nuevo, no hay bloqueo. El banco nunca envi\xf3 ese mensaje.\n\n\xbfY si la advertencia hubiera sido real? La aplicaci\xf3n tambi\xe9n la habr\xeda mostrado, y usted lo habr\xeda sabido en lo que tarda en desbloquear su tel\xe9fono. Ese es todo el costo de verificar.",outcome:"best",lesson:"\xbfNo hay nadie m\xe1s a quien preguntarle? Vuelva a buscarlos por una puerta que ellos no le se\xf1alaron. Una cuenta bloqueada tiene arreglo. Un desconocido dentro de ella, no.",choices:[{label:"Continuar",next:-1}]}]}},"school-teacher":{whyYou:{content:"Los atacantes leen el sitio web de su escuela como si fuera un directorio de personal. Su nombre, su cargo, el bolet\xedn que menciona que usted coordina el consejo estudiantil, el pie de foto que nombra a su directora. Diez minutos de lectura le dicen a alguien a qui\xe9n suplantar, a qui\xe9n escribirle y qu\xe9 plazo va a sonar real.\n\nA los l\xedderes los suplantan. Al personal le llega la solicitud. Y una solicitud que parece venir de su directora llega con un costo por cuestionarla: preguntar \xab\xbfde verdad es usted?\xbb puede sentirse como una insubordinaci\xf3n.\n\nEse es un problema de permiso, no de conocimiento.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Los filtros ayudan. No terminan el trabajo.",text:"Un filtro puede atrapar un dominio parecido o marcar a un remitente externo. Lo que no puede saber es si a usted siquiera debieron pedirle esa lista. Ese criterio es suyo."}},opening:{title:"La 1:47 de un jueves",content:"Es la 1:47 de un jueves. Debe volver con su clase en ocho minutos y hay un padre de familia esperando en el pasillo. Llega un correo de su directora: la oficina del distrito necesita hoy la lista de octavo grado ânombres, grados y correos de los padresâ. Env\xedela de una vez y no la pase por la oficina, la lista todav\xeda no es definitiva.\n\nEn ese mensaje nadie le pide un pago. No trae ning\xfan archivo adjunto. No hay ning\xfan enlace en qu\xe9 hacer clic. Fue escrito para la versi\xf3n cansada de usted, en pleno pasillo, que no quiere ser el motivo por el que la oficina del distrito se queda esperando."},scenario:{title:"La lista se entrega hoy",steps:[{text:"Volvamos a la 1:47. La lista de octavo grado se entrega hoy a la oficina del distrito y su directora se la pidi\xf3 directamente. \xbfQu\xe9 hace?",choices:[{label:"Enviarla: ella la pidi\xf3",next:1},{label:"Responder el correo para confirmar",next:2},{label:"Llamarla al n\xfamero que usted ya tiene",next:3},{label:"Ir a la oficina y preguntar",next:4}]},{text:"Enviada. La direcci\xf3n de respuesta era un dominio falso, casi id\xe9ntico al real. Los nombres y los datos de contacto de esas fam
1ilias ya est\xe1n en un lugar al que usted no puede llegar, y una lista de alumnos ya enviada no se recupera.",outcome:"bad",lesson:"Un plazo real nunca vuelve seguro un env\xedo sin verificar. La lista era el objetivo desde el principio.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"La respuesta llega en segundos: \xabEstoy en una reuni\xf3n, solo env\xedela\xbb. Lo cual no prueba nada. Una respuesta solo llega a quien envi\xf3 el correo.",choices:[{label:"Enviarla",next:1},{label:"Llamarla al n\xfamero que usted ya tiene",next:3}]},{text:"Buz\xf3n de voz. Est\xe1 fuera de la escuela hasta ma\xf1ana. El plazo sigue siendo hoy, y ahora usted no tiene salida.",choices:[{label:"Enviarla y resolverlo ma\xf1ana",next:1},{label:"Preguntarle a alguien m\xe1s que est\xe9 al tanto",next:4}]},{text:"En la oficina no hay ninguna solicitud de ese tipo, y nadie pidi\xf3 jam\xe1s esa lista. Nadie envi\xf3 ese correo.\n\n\xbfY si hubiera sido aut\xe9ntico? La lista habr\xeda salido una hora m\xe1s tarde de lo que pudo haber salido. Ese es todo el costo de verificar.",outcome:"best",lesson:"\xbfNo logra comunicarse con quien se lo pidi\xf3? Preg\xfantele a otra persona que est\xe9 al tanto. Una lista que llega tarde tiene arreglo. Una lista ya enviada, no.",choices:[{label:"Continuar",next:-1}]}]}},"school-office":{whyYou:{content:"Los atacantes no tienen que buscarla mucho. La p\xe1gina de contacto pone a la oficina primero, con su nombre y un n\xfamero que llega directo a usted, y les dice a las familias que llamen a la oficina por cualquier asunto de sus expedientes. El mismo sitio nombra a su directora. Diez minutos de lectura le dicen a alguien a qui\xe9n suplantar, a qui\xe9n escribirle y cu\xe1l es la lista que usted precisamente tiene en sus manos.\n\nA los l\xedderes los suplantan. A la oficina le llega la solicitud. Y una solicitud que parece venir de su directora llega con un costo por cuestionarla: todo su trabajo consiste en ser la persona que hace que las cosas avancen, y preguntar \xab\xbfde verdad es usted?\xbb puede sentirse como estorbar.\n\nEse es un problema de permiso, no de conocimiento.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Los filtros ayudan. No terminan el trabajo.",text:"Un filtro puede atrapar un dominio parecido o marcar a un remitente externo. Lo que no puede saber es si a usted siquiera debieron pedirle ese directorio. Ese criterio es suyo."}},opening:{title:"Las 10:20 de un martes",content:"Son las 10:20 de un martes. Hay un pap\xe1 en el mostrador, dos llamadas en espera y un alumno esperando un pase por llegar tarde. Llega un correo de su directora: el nuevo directorio de familias tiene que estar hoy en la imprenta âel nombre, el domicilio, el tel\xe9fono y el correo de cada familia, la versi\xf3n que usted mantieneâ. Env\xedelo de una vez y no lo revise con la encargada de registros, hay datos que todav\xeda no est\xe1n confirmados.\n\nEn ese mensaje nadie le pide un pago. No trae ning\xfan archivo adjunto. No hay ning\xfan enlace en qu\xe9 hacer clic. Fue escrito para la versi\xf3n ocupada de usted, en pleno mostrador, que arma listas como esta con la frecuencia suficiente para que esta no le pida nada fuera de lo com\xfan."},scenario:{title:"La imprenta lo necesita hoy",steps:[{text:"Volvamos a las 10:20. El directorio se entrega hoy en la imprenta y su directora se lo pidi\xf3 directamente. \xbfQu\xe9 hace?",choices:[{label:"Adjuntarlo y envi
1arlo",next:1},{label:"Responder el correo para confirmar",next:2},{label:"Llamar a su celular: usted tiene el n\xfamero",next:3},{label:"Preguntarle a la encargada de registros",next:4}]},{text:"Enviado. La direcci\xf3n de respuesta era un dominio falso, casi id\xe9ntico al real. Cada familia de la escuela âdomicilios, n\xfameros de tel\xe9fonoâ ya est\xe1 en un lugar al que usted no puede llegar, y un directorio ya enviado no se recupera.",outcome:"bad",lesson:"Un plazo real nunca vuelve seguro un env\xedo sin verificar.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"La respuesta llega en segundos: \xabEstoy en una reuni\xf3n, solo env\xedelo\xbb. Lo cual no prueba nada. Una respuesta solo llega a quien envi\xf3 el correo.",choices:[{label:"Adjuntarlo y enviarlo",next:1},{label:"Llamar a su celular: usted tiene el n\xfamero",next:3}]},{text:"Buz\xf3n de voz. Usted ya sab\xeda que estar\xeda todo el d\xeda en la oficina del distrito: lo anot\xf3 en el calendario. El plazo de la imprenta sigue siendo hoy, y ahora usted no tiene salida.",choices:[{label:"Enviarlo y resolverlo ma\xf1ana",next:1},{label:"Preguntarle a alguien m\xe1s que est\xe9 al tanto",next:4}]},{text:"La encargada de registros no sabe de ninguna entrega a la imprenta, y nadie ha encargado un directorio este a\xf1o. Nadie envi\xf3 ese correo.\n\n\xbfY si hubiera sido aut\xe9ntico? El archivo habr\xeda salido veinte minutos despu\xe9s. Ese es todo el costo de verificar.",outcome:"best",lesson:"\xbfNo logra comunicarse con quien se lo pidi\xf3? Preg\xfantele a otra persona que est\xe9 al tanto. Un archivo que sale tarde tiene arreglo. Uno ya enviado, no.",choices:[{label:"Continuar",next:-1}]}]}},parish:{whyYou:{content:"Los atacantes leen el bolet\xedn de su parroquia como usted leer\xeda un directorio de personal. Su nombre, su cargo, el horario de oficina, el nombre del p\xe1rroco en la portada. Los boletines se publican en l\xednea y ah\xed se quedan, as\xed que no es una semana: son meses. Diez minutos de lectura le dicen a alguien a qui\xe9n suplantar, a qui\xe9n escribirle y qu\xe9 plazo va a sonar real.\n\nA los p\xe1rrocos los suplantan. Al personal de la parroquia le llega la solicitud. Y una solicitud que parece venir de su p\xe1rroco llega con un costo por cuestionarla: preguntar \xab\xbfde verdad es usted?\xbb puede sentirse como dudar de \xe9l. Y muchas veces no hay nadie m\xe1s en la oficina a quien consultar.\n\nEse es un problema de permiso, no de conocimiento.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Los filtros ayudan. No terminan el trabajo.",text:"Un filtro puede atrapar un dominio parecido o marcar a un remitente externo. Lo que no puede saber es si a usted siquiera debieron pedirle la lista de contactos de la parroquia. Ese criterio es suyo."}},opening:{title:"Las 4:15 de un martes",content:"Son las 4:15 de un martes. La oficina cierra pronto, el tel\xe9fono no ha parado de sonar desde el mediod\xeda y alguien sigue esperando en el mostrador. Llega un correo de su p\xe1rroco: necesita hoy la lista de contactos de la parroquia âtodas las familias registradas, con domicilios y tel\xe9fonosâ. Env\xedela de una vez y, por ahora, que quede entre ustedes dos.\n\nEn ese mensaje nadie le pide un pago. No trae ning\xfan archivo adjunto. No hay ning\xfan enlace en qu\xe9 hacer clic. Fue escrito para la versi\xf3n cansada de usted, al final de una tarde larga, que no quiere ser el motivo por el que el p\xe1rroco tenga que pedir las cosas dos veces."},scenario:{title:"Antes de que cierre la oficina",steps:[{text:"Volvamos a las 4:15. El p\xe1rroco necesita hoy la lista de contactos de la parroquia y se la pidi\xf3 directamente. \xbfQu\xe9 hace?",choices:[{label:"Enviarla: \xe9l la pidi\xf3",next:1},{label:"Responder el correo para confirmar",next:2},{label:"Llamarlo al n\xfamero que usted ya tiene",next:3},{label:"Ir a buscarlo y preguntarle en persona",next:4}]},{text:"Enviada. La direcci\xf3n de respuesta era un dominio falso, casi id\xe9ntico al real. Cada familia de la parroquia âdomicilios, n\xfameros de tel\xe9fonoâ ya est\xe1 en un lugar al que usted no puede llegar, y una lista ya enviada no se recupera.",outcome:"bad",lesson:"Un plazo real nunca vuelve seguro un env\xedo sin verificar.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"La respuesta llega en segundos: \xabS\xed, soy yo, por favor env\xedela\xbb. Lo cual no prueba nada. Una respuesta solo llega a quien envi\xf3 el correo.",choices:[{label:"Enviarla",next:1},{label:"Llamarlo al n\xfamero que usted ya tiene",next:3}]}
1,{text:"Timbra y nadie contesta. Anda en visitas y la oficina cierra en cuarenta minutos. Ahora usted no tiene salida.",choices:[{label:"Enviarla y coment\xe1rselo ma\xf1ana",next:1},{label:"Esperar hasta poder comunicarse con \xe9l",next:4}]},{text:"Usted la deja en la carpeta de borradores y lo alcanza en la ma\xf1ana. \xc9l nunca envi\xf3 ese correo, y se alegra de que usted haya esperado.\n\n\xbfY si hubiera sido aut\xe9ntico? Habr\xeda tenido la lista antes de las nueve. Ese es todo el costo de verificar.",outcome:"best",lesson:"\xbfNo hay nadie m\xe1s a quien preguntarle? Entonces la lista espera hasta que usted pueda comunicarse por otra v\xeda. Una lista enviada tarde tiene arreglo. Una lista enviada a un desconocido, no.",choices:[{label:"Continuar",next:-1}]}]}},nonprofit:{whyYou:{content:"Los atacantes leen su sitio web como si fuera un directorio de personal. Su nombre y su cargo en la p\xe1gina del equipo, el informe anual que nombra a su director ejecutivo y agradece a los donantes por nivel de aportaci\xf3n. Las organizaciones peque\xf1as publican m\xe1s sobre s\xed mismas de lo que creen, porque los financiadores esperan verlo. Diez minutos de lectura le dicen a alguien a qui\xe9n suplantar, a qui\xe9n escribirle y qu\xe9 plazo va a sonar real.\n\nA los l\xedderes los suplantan. Al personal le llega la solicitud. Y una solicitud que parece venir de su director ejecutivo llega con un costo por cuestionarla: en un equipo tan peque\xf1o, preguntar \xab\xbfde verdad es usted?\xbb puede sentirse como una acusaci\xf3n.\n\nEse es un problema de permiso, no de conocimiento.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Los filtros ayudan. No terminan el trabajo.",text:"Un filtro puede atrapar un dominio parecido o marcar a un remitente externo. Lo que no puede saber es si a usted siquiera debieron pedirle la lista de donantes. Ese criterio es suyo."}},opening:{title:"Las 4:40 de un martes",content:"Son las 4:40 de un martes. Una voluntaria lleva veinte minutos esperando una respuesta que solo usted puede dar, y el env\xedo de ma\xf1ana todav\xeda no est\xe1 listo. Llega un correo de su directora ejecutiva: la junta directiva necesita hoy la lista de donantes ânombres, historial de donaciones y datos de contactoâ. Env\xedela de una vez y no copie a nadie m\xe1s, las cifras todav\xeda no son definitivas.\n\nEn ese mensaje nadie le pide un pago. No trae ning\xfan archivo adjunto. No hay ning\xfan enlace en qu\xe9 hacer clic. Fue escrito para la versi\xf3n cansada de usted, al final de un d\xeda largo haciendo el trabajo de tres personas, que no quiere ser el motivo por el que la junta se queda esperando."},scenario:{title:"La junta la quiere hoy",steps:[{text:"Volvamos a las 4:40. La lista de donantes se entrega hoy a la junta directiva y su directora ejecutiva se la pidi\xf3 directamente. \xbfQu\xe9 hace?",choices:[{label:"Enviarla: ella la pidi\xf3",next:1},{label:"Responder el correo para confirmar",next:2},{label:"Llamarla al n\xfamero que usted ya tiene",next:3},{label:"Preguntarle a la colega que se encarga de los env\xedos",next:4}]},{text:"Enviada. La direcci\xf3n de respuesta era un dominio falso, casi id\xe9ntico al real. El nombre, el historial de donaciones y los datos de contacto de cada donante ya est\xe1n en un lugar al que usted no puede llegar, y una lista de donantes ya enviada no se recupera.",outcome:"bad",lesson:"Un plazo real nunca vuelve seguro un env\xedo sin verificar.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"La respuesta llega en segundos: \xabEstoy en una llamada, solo env\xedela\xbb. Lo cual no prueba nada. Una respuesta solo llega a quien envi\xf3 el correo.",choices:[{label:"Enviarla",next:1},{label:"Llamarla al n\xfamero que usted ya tiene",next:3}]},{text:"Buz\xf3n de voz. Est\xe1 con un donante institucional hasta ma\xf1ana. La junta se re\xfane esta noche, y ahora usted no tiene salida.",choices:[{label:"Enviarla y avisarle ma\xf1ana",next:1},{label:"Preguntarle a alguien m\xe1s que est\xe9 al tanto",next:4}]},{text:"No hay ninguna reuni\xf3n de la junta esta noche, y nadie ha pedido los registros de donantes. Nadie envi\xf3 ese correo.\n\n\xbfY si hubiera sido aut\xe9ntico? La lista habr\xeda salido veinte minutos despu\xe9s. Ese es todo el costo de verificar.",outcome:"best",lesson:"\xbfNo logra comunicarse con quien se lo pidi\xf3? Preg\xfantele a otra persona que est\xe9 al tanto. Una lista que llega tarde tiene arreglo. Una lista ya enviada, no.",choices:[{label:"Continuar",next:-1}]}]}},workplace:{whyYou:{content:"Los atacantes empiezan con lo que su empresa publica en l\xednea. El nombre del due\xf1o en el sitio y en LinkedIn, una rese\xf1a de un cliente que le agradece por su nombre de pila, y un formato de direcci\xf3n de correo que cualquiera puede adivinar en cuanto tiene ese nombre. Diez minutos de lectura le dicen a alguien a qui\xe9n suplantar, a qui\xe9n escribirle y qu\xe9 plazo va a sonar real.\n\nA los due\xf1os los suplantan. Al personal le llega la solicitud. Y una solicitud que parece venir del due\xf1o llega con un costo por cuestionarla: anda afuera en un trabajo, lo necesita ya, y preguntar \xab\xbfde verdad es usted?\xbb puede sentirse como si usted no confiara en \xe9l.\n\nEse es un problema de permiso, no de conocimiento.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Los filtros ayudan. No terminan el trabajo.",text:"Un filtro puede atrapar un dominio parecido o marcar a un remitente externo. Lo que no puede saber es si a usted siquiera debieron pedirle esta lista de personal. Ese criterio es suyo."}},opening:{title:"Las 4:52 de un jueves",content:"Son las 4:52 de un jueves. Est\xe1 a diez minutos de irse a casa y tiene a un cliente en espera. Llega un correo del due\xf1o: el contador externo necesita hoy la lista del personal ânombres, puestos y domiciliosâ. Env\xedela de una vez y no involucre a la encargada de la contabilidad interna, no le toca a ella decidirlo.\n\nEn ese mensaje nadie le pide un pago. No trae ning\xfan archivo adjunto. No hay ning\xfan enlace en qu\xe9 hacer clic. Fue escrito para la versi\xf3n cansada de usted, con un pie fuera de la oficina, que no quiere ser el motivo por el que el contador externo se queda esperando."},scenario:{title:"El due\xf1o la necesita hoy",steps:[{text:"Volvamos a las 4:52. El contador externo necesita hoy la lista del personal y el due\xf1o se la pidi\xf3 directamente. \xbfQu\xe9 hace?",choices:[{label:"Enviarla: \xe9l la pidi\xf3",next:1},{label:"Responder el correo para confirmar",next:2},{label:"Llamarlo al n\xfamero que usted ya tiene",next:3},{label:"Preguntarle a la encargada de la contabilidad interna",next:4}]},{text:"Enviada. La direcci\xf3n de respuesta era un dominio falso, casi id\xe9ntico al real. Los nombres y los domicilios de sus compa\xf1eros ya est\xe1n en un lugar al que usted no puede llegar, y una lista del personal ya envi
1ada no se recupera.",outcome:"bad",lesson:"Un plazo real nunca vuelve seguro un env\xedo sin verificar.",choices:[{label:"Intentar de nuevo",next:0}]},{text:"La respuesta llega en segundos: \xabEstoy con un cliente, solo env\xedela\xbb. Lo cual no prueba nada. Una respuesta solo llega a quien envi\xf3 el correo.",choices:[{label:"Enviarla",next:1},{label:"Llamarlo al n\xfamero que usted ya tiene",next:3}]},{text:"Directo al buz\xf3n de voz. Viene manejando de regreso de una visita y no llegar\xe1 hasta ma\xf1ana. El contador externo todav\xeda la necesita hoy, y ahora usted no tiene salida.",choices:[{label:"Enviarla y dec\xedrselo ma\xf1ana",next:1},{label:"Preguntarle a alguien m\xe1s que est\xe9 al tanto",next:4}]},{text:"La encargada de la contabilidad interna no tiene ninguna solicitud del contador externo, y nadie pidi\xf3 jam\xe1s una lista del personal. Nadie envi\xf3 ese correo.\n\n\xbfY si hubiera sido aut\xe9ntico? La lista habr\xeda salido diez minutos despu\xe9s. Ese es todo el costo de verificar.",outcome:"best",lesson:"\xbfNo logra comunicarse con quien se lo pidi\xf3? Preg\xfantele a otra persona que est\xe9 al tanto. Una lista que llega tarde tiene arreglo. Una lista ya enviada, no.",choices:[{label:"Continuar",next:-1}]}]}}},upsellSlide:{type:"concept",timer:15,title:"Si quiere m\xe1s que una lecci\xf3n",content:"Este m\xf3dulo es gratis y va a seguir siendo gratis. Si le result\xf3 \xfatil, hay m\xe1s.\n\nUna suscripci\xf3n individual agrega la extensi\xf3n del navegador âuna puntuaci\xf3n de confianza en cada correo antes de que usted lo abraâ adem\xe1s del resto de esta biblioteca y ataques de pr\xe1ctica que le enviamos cada mes.\n\nSi su escuela se suscribe, todo el personal recibe eso mismo, y los administradores pueden ver qui\xe9n se ha capacitado, qui\xe9n report\xf3 qu\xe9 y d\xf3nde est\xe1n los puntos d\xe9biles.",callout:{icon:"\uD83C\uDF93",title:"Su certificado",text:"Escriba su correo y le enviaremos un certificado por haber completado este m\xf3dulo, junto con un enlace para retomar donde se qued\xf3. Solo lo usamos para eso."}}}},n={"ms-fake-messages":{title:"Spotting Fake Messages",icon:"\uD83C\uDFA3",duration:"8 min",level:"Middle School \xb7 Grades 6-8",slides:[{type:"title",timer:5,title:"Spotting Fake Messages",subtitle:"How to tell when a message is trying to trick you",objectives:['Know what a fake ("phishing") message is',"Spot the warning signs","Learn the one move that keeps you safe"]},{type:"concept",timer:12,title:"What is a Fake Message?",content:'A fake message is one where a scammer pretends to be someone you trust â a game like Roblox or Fortnite, a company like YouTube, or even a friend â to trick you into giving up your password, your money, or your personal info. These are called "phishing" messages, and they can arrive by email, text, DM, or right inside a game chat.',callout:{icon:"\uD83C\uDFA3",title:'Why "phishing"?',text:'It sounds like "fishing" â the scammer throws out bait (a prize, a scary warning, a link) and hopes you bite. If you know the tricks, you just do not bite.'}},{type:"keypoints",timer:22,title:"Warning Signs of a Fake Message",points:[{icon:"â°",label:"It rushes you",desc:'"Do this in the next 10 minutes or your account is deleted!" Real companies do not threaten you like that. Rushing is a trick to stop you from thinking.',color:"#ef4444"},{icon:"\uD83C\uDF81",label:"It promises free stuff",desc:'"You won 10,000 Robux! Click to claim!" Free money, skins, or gift cards you never entered to win are almost always a scam.',color:"#f97316"},{icon:"\uD83D\uDD17",label:"Weird links or spelling",desc:'The link looks almost right but is off, like "roblox-free-login.com". Bad spelling and strange web addresses are big red flags.',color:"#eab308"},{icon:"\uD83D\uDD11",label:"It asks for your password",desc:"No real game or app will ever message you asking for your password or login code. If a message asks, it is fake.",color:"#22c55e"},{icon:"\uD83D\uDE42",label:'A "friend" acting strange',desc:'If a friend suddenly messages "click this" or "send me a code," their account may be hacked. Check with them another way first.',color:"#8b5cf6"}]},{type:"email_exercise",timer:0,title:"Real or Fake?",instruction:"Read this message and decide: is it real, or a phishing trick?",email:{from:{name:"Roblox Support",address:"[email protected]"},to:"[email protected]",time:"Today, 4:12 PM",subject:"â ï¸ Your account will be DELETED in 24 hours",body:"Dear Player,\n\nWe found a problem with your account. If you do not verify your password RIGHT NOW, your account and all your items will be permanently deleted in 24 hours.\n\nVerify here: https://roblox-secure-login.com/verify\n\nEnter your username and password to keep your account safe.\n\n- Roblox Support Team",isPhishing:!0,redFlags:[{highlight:"roblox-secure-login.com",explanation:"The real site is roblox.com. This made-up web address is a fake pretending to be Roblox."},{highlight:"DELETED in 24 hours",explanation:"Scary countdowns are meant to make you panic and act fast. Real companies do not do this."},{highlight:"Enter your username and password",explanation:"Roblox will never email you asking for your password. This is how scammers steal accounts."}]}}
1,{type:"email_exercise",timer:0,title:"Real or Fake?",instruction:"Here is another one. Real, or a trick?",email:{from:{name:"Roblox",address:"[email protected]"},to:"[email protected]",time:"Yesterday, 7:30 PM",subject:"New sign-in to your Roblox account",body:"Hi,\n\nWe noticed a new sign-in to your account from a new device.\n\nIf this was you, you can ignore this message. If it was not you, go to Roblox and change your password in your account settings.\n\nWe will never ask for your password by email.\n\n- The Roblox Team",isPhishing:!1,redFlags:[],legitimateReasons:"This one is safe. It comes from the real roblox.com, it does not rush you or threaten to delete anything, it tells you to go to the app yourself instead of clicking a link, and it says it will never ask for your password. That is exactly what a real safety message looks like."}},{type:"scenario",timer:0,title:"What Would You Do?",steps:[{text:'You get a DM in a game: "OMG you were picked for a FREE Nitro giveaway! Just log in here with your account to claim it: discord-nitro-free.com". What do you do?',choices:[{label:"Click it and log in â free Nitro!",next:1},{label:"Ignore it and do not click",next:2},{label:"Send it to my friends so they can win too",next:3}]},{text:"You clicked and typed in your login. That was a fake page built to steal it. Minutes later you are locked out and the scammer is DMing your friends the same trick from your account.",outcome:"bad",lesson:'A site that asks you to "log in to claim a prize" is stealing your login. Free-giveaway links are one of the most common scams.',choices:[{label:"Try again",next:0}]},{text:"You ignored it and did not click. Nothing bad happened. If you were not sure, you could also tell a parent or check the real app â real prizes never need your password on a random website.",outcome:"best",lesson:"Not clicking is a superpower. Real giveaways never ask you to log in on a link someone DMed you.",choices:[{label:"Continue",next:-1}]},{text:"You forwarded it to friends. Now the scam spreads, and if any of them click, THEY get their account stolen too. Sharing a scam link makes it worse for everyone.",outcome:"bad",lesson:'Never pass along a "free prize" link. If it were real, it would not need you to spread it or log in on a strange site.',choices:[{label:"Try again",next:0}]}]},{type:"quiz",timer:0,title:"Quick Check",questions:[{q:'A message says "verify your password in 10 minutes or lose your account." What is going on?',options:["A helpful reminder â do it fast","A scam using a scary countdown to rush you","A normal thing games do every week","A message from a friend"],correct:1,explanation:"Countdowns and threats are meant to make you panic. Slow down â real companies do not do this."},{q:"Which web address is the FAKE one pretending to be Roblox?",options:["roblox.com","roblox-secure-login.com","www.roblox.com","None of them"],correct:1,explanation:'Extra words like "secure-login" tacked onto the name are a classic trick. The real site is just roblox.com.'},{q:"A game emails you asking for your password. What should you do?",options:["Send it â they need it","Never send it; real games never ask","Send a fake password","Ask a friend for advice first"],correct:1,explanation:"No real game or app ever asks for your password by message. If it asks, it is a scam."}]},{type:"complete",timer:5,title:"Nice Work!",takeaways:["Fake messages pretend to be someone you trust to steal your password, money, or info",'Watch for rushing, "free" prizes, weird links, and any request for your password',"Real companies never ask for your password in a message","When unsure, do not click â check the real app yourself or ask a trusted adult"]}]},"ms-strong-passwords":{title:"Strong Passwords & Locking Your Accounts",icon:"\uD83D\uDD11",duration:"8 min",level:"Middle School \xb7 Grades 6-8",slides:[{type:"title",timer:5,title:"Strong Passwords & Locking Your Accounts",subtitle:"Keep your games, chats, and accounts yours",objectives:["Make a password that is actually hard to guess","Understand why sharing or reusing passwords is risky","Turn on an extra lock (2-step verification)"]},{type:"concept",timer:12,title:"Why Passwords Matter",content:"Your password is the key to your account. If someone gets it, they can log in as you â mess with your game, spend your money or V-Bucks, read your messages, and message your friends pretending to be you. A strong password that only you know keeps all of that locked up tight.",callout:{icon:"\uD83D\uDD12",title:"Think of it like your locker",text:"You would not tape your locker combo to the door. Your password is the same â it only works if you keep it secret."}},{type:"keypoints",timer:22,title:"How to Build a Strong Password",points:[{icon:"\uD83D\uDCCF",label:"Make it long",desc:'Longer is stronger. A passphrase like "purple-tiger-skateboard-42" is way harder to crack than a short word â and easier to remember.',color:"#3b82f6"},{icon:"\uD83C\uDFB2",label:"Do not make it guessable",desc:'Skip your name, birthday, pet, favorite team, or "password123". Anyone who knows you (or can look you up) could guess those.',color:"#ef4444"},{icon:"â»ï¸",label:"Do not reuse it",desc:"Use a different password for different accounts. If one gets leaked, the others stay safe.",color:"#f97316"},{icon:"\uD83E\uDD10",label:"Never share it",desc:'Not with a best friend, not to "trade" or "get a free skin." Once someone knows it, it is not secret anymore.',color:"#8b5cf6"},{icon:"\uD83D\uDCF1",label:"Turn on 2-step",desc:"2-step verification (also called 2FA) adds a second lock â usually a code on your phone â so even if someone learns your password, they still cannot get in.",color:"#22c55e"}]},{type:"scenario",timer:0,title:"What Would You Do?",steps:[{text:'A kid you play with online says: "Give me your account password and I will log in and get you a rare skin for free. I do this for everyone!" What do you do?',choices:[{label:"Give them my password â free skin!",next:1},{label:"Say no and never share my password",next:2},{label:"Give them a made-up wrong password",next:3}]},{text:"You handed over your password. Instead of a skin, they changed your password and locked you out of your own account. There was never a free skin â that was the whole trick.",outcome:"bad",lesson:'Anyone who asks for your password is trying to take your account. "I will get you something free" is the bait.',choices:[{label:"Try again",next:0}]},{text:"You said no. Your account stayed yours. Real free items come from the game itself, never from handing your password to a stranger.",outcome:"best",lesson:"The rule is simple: your password is never part of a trade or a favor. Keep it secret, always.",choices:[{label:"Continue",next:-1}]},{text:"You gave a fake password, so they could not get in â good instinct! But the safest move is to just say no and never treat your password like something to hand out at all.",outcome:"good",lesson:'Not sharing worked out, but do not even open the door. "No" is a complete answer.',choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Quick Check",questions:[{q:"Which of these is the STRONGEST password?",options:["jayden2012","password1","brave-otter-lamp-moon","ilovepizza"],correct:2,explanation:"A long passphrase of random words is very hard to crack and still easy to remember. Names, birthdays, and common words are weak."},{q:'A friend asks for your password to "help you out." What is the best answer?',options:["Share it â they are a friend","Say no; never share your password","Share it but change it after","Trade passwords with them"],correct:1,explanation:"Never share your password, even with a friend. Once it is out, it is not a secret, and their account could be hacked next."},{q:"What does 2-step verification (2FA) do?",options:["Makes your password longer","Adds a second lock, like a code on your phone","Shares your account with a friend","Nothing useful"],correct:1,explanation:"2FA adds a second step so even someone who knows your password still cannot get in without your co
1de."}]},{type:"complete",timer:5,title:"Locked Down!",takeaways:["Long passphrases beat short, guessable passwords","Use different passwords for different accounts",'Never share your password â no trade or "free" gift is worth your account',"Turn on 2-step verification wherever you can for an extra lock"]}]},"ms-privacy-basics":{title:"Your Privacy: What to Keep to Yourself",icon:"\uD83D\uDD12",duration:"8 min",level:"Middle School \xb7 Grades 6-8",slides:[{type:"title",timer:5,title:"Your Privacy: What to Keep to Yourself",subtitle:"What is safe to share online â and what is not",objectives:["Know which info to keep private","Understand that posts can last forever","Use privacy settings and think before you post"]},{type:"concept",timer:12,title:"Your Info is Valuable",content:"Little pieces of information about you â your full name, your school, where you live, your phone number, where you are right now â can be put together by strangers or scammers to find you or trick you. Sharing online feels quick and private, but a post or photo can be saved and shared by anyone, forever.",callout:{icon:"\uD83D\uDCF8",title:"Screenshots are forever",text:'Even a photo or message you "delete" or that "disappears" can already be screenshotted. Post only what you would be okay with anyone seeing.'}},{type:"keypoints",timer:22,title:"Keep These Private",points:[{icon:"\uD83C\uDFE0",label:"Where you live",desc:"Your home address, and your full name plus your school together â that combo makes it possible for a stranger to figure out where to find you.",color:"#ef4444"},{icon:"\uD83D\uDCDE",label:"Phone number",desc:"Do not post your number publicly or give it to people you only know online. It leads to spam, scams, and unwanted contact.",color:"#f97316"},{icon:"\uD83D\uDCCD",label:"Your live location",desc:'Turn off location tags on posts, and do not announce "home alone" or exactly where you are right now.',color:"#eab308"},{icon:"\uD83D\uDD11",label:"Passwords & codes",desc:'Never share login info or the 2-step code that gets texted to you â not even if someone says they are "support."',color:"#22c55e"},{icon:"âï¸",label:"Use privacy settings",desc:"Set your accounts to private/friends-only, and think before you post. Ask a friend before you post a photo of them, too.",color:"#8b5cf6"}]},{type:"scenario",timer:0,title:"What Would You Do?",steps:[{text:"You are about to post a photo from outside school. You are in your school jacket, the school sign is in the background, and your app wants to tag your exact location. What do you do?",choices:[{label:"Post it with the location tag on",next:1},{label:"Turn off the location and crop out the school sign",next:2},{label:"Post it publicly so more people see it",next:3}]},{text:"You posted it with your location and school showing, set to public. Now a stranger scrolling could know your school, your face, and where you were at a certain time. That is a lot of pieces for someone you do not know.",outcome:"bad",lesson:"A location tag plus your school plus your face is exactly the info that lets a stranger figure out where to find you.",choices:[{label:"Try again",next:0}]},{text:"You turned off the location and cropped out the sign. You can still share the fun photo with friends â just without the map to your school. Smart move.",outcome:"best",lesson:"You can still post and have fun. Just leave OUT the pieces that reveal where you are and where to find you.",choices:[{label:"Continue",next:-1}]},{text:"You made it public so it would get more views. But now anyone at all â not just friends â can see your school, your face, and where you were. More views is not worth giving strangers that much about you.",outcome:"bad",lesson:"Public means everyone, including people you would never want knowing where you go to school. Keep it friends-only.",choices:[{label:"Try again",next:0}]}]},{type:"quiz",timer:0,title:"Quick Check",questions:[{q:"Which of these is safest to keep PRIVATE?",options:["Your favorite color","Your home address and school together","The name of a game you like","Your favorite song"],correct:1,explanation:"Your address, and
1your full name plus school, can help a stranger find you. Favorites are harmless."},{q:"You post a photo and then delete it an hour later. Is it fully gone?",options:["Yes, deleting removes it everywhere","No â someone could have already screenshotted it","Only if you delete the app","Yes, after 24 hours"],correct:1,explanation:"Once something is posted, others can save or screenshot it. Deleting your copy does not erase theirs."},{q:"What is a smart privacy setting for your accounts?",options:["Public, so everyone sees","Private / friends-only","No password","Share your location always"],correct:1,explanation:"Friends-only keeps your posts to people you actually know, not strangers."}]},{type:"complete",timer:5,title:"Privacy Pro!",takeaways:["Keep your address, phone, school + name combo, and live location private","Anything you post can be screenshotted and last forever","Set accounts to friends-only and turn off location tags","Ask before posting photos of other people, too"]}]},"ms-scams-and-downloads":{title:"Free-Stuff Scams & Sketchy Downloads",icon:"\uD83C\uDFAE",duration:"8 min",level:"Middle School \xb7 Grades 6-8",slides:[{type:"title",timer:5,title:"Free-Stuff Scams & Sketchy Downloads",subtitle:'When "free Robux" and "free mods" are really traps',objectives:['Spot "free money/skins" scams',"Know why cheat and mod downloads are risky","Check a link before you trust it"]},{type:"concept",timer:12,title:'If It Is "Free," Be Careful',content:'Scammers know exactly what you want: free Robux, V-Bucks, skins, followers, or a cheat that makes you unbeatable. So they build fake "generators," giveaways, and downloads. What you actually get is a stolen account, a virus, or a bill â never the free stuff. The rule: real game money and items come from the game itself, never from a random website or a "generator."',callout:{icon:"\uD83D\uDEAB",title:"Generators are always fake",text:'A "free Robux/V-Bucks generator" is a scam 100% of the time. Games do not give away their own money through outside websites.'}},{type:"keypoints",timer:22,title:"Traps to Watch For",points:[{icon:"\uD83D\uDC8E",label:'"Free" currency generators',desc:'Sites that promise free Robux, V-Bucks, or coins if you "log in" or "verify." They steal your account or make you fill out endless ads.',color:"#ef4444"},{icon:"\uD83D\uDEE0ï¸",label:"Cheats, hacks & mods",desc:"Downloads that promise aimbot, free skins, or unlimited coins often hide viruses that steal your passwords. Only get mods from official, trusted sources.",color:"#f97316"},{icon:"\uD83C\uDF89",label:"Fake giveaways",desc:'"You won! DM us your login to claim." Real giveaways never need your password or a payment to "release" a prize.',color:"#eab308"},{icon:"\uD83D\uDD17",label:"Check the link",desc:'Before clicking, look at the web address. Misspellings and extra words ("free-fortnite-vbucks.net") mean fake. When unsure, do not click.',color:"#22c55e"},{icon:"\uD83D\uDCE5",label:"Download from official stores",desc:"Get apps and games from official stores (App Store, Google Play) and official websites â not from pop-ups, ads, or links a stranger sent.",color:"#8b5cf6"}]},{type:"email_exercise",timer:0,title:"Real or Fake?",instruction:"You get this email. Is it a real offer, or a scam?",email:{from:{name:"Fortnite Rewards",address:"[email protected]"},to:"[email protected]",time:"Today, 5:47 PM",subject:"\uD83C\uDF89 You have been selected for 13,500 FREE V-Bucks!",body:"Congratulations!!! You were randomly selected to receive 13,500 V-Bucks for FREE.\n\nTo claim, click below, log in with your Epic Games account, and complete a quick verification.\n\nCLAIM NOW â https://free-vbucks-now.net/claim\n\nHurry â this offer expires in 1 hour!",isPhishing:!0,redFlags:[{highlight:"free-vbucks-now.net",explanation:"This is not epicgames.com. It is a fake site made to look like a reward page."},{highlight:"log in with your Epic Games account",explanation:"Logging in on this fake page hands your account straight to the scammer."},{highlight:"expires in 1 hour",explanation:"The countdown is there to rush you. Real rewards do not work like this."}]}}
1,{type:"quiz",timer:0,title:"Quick Check",questions:[{q:'A website offers a "free Robux generator" if you log in. What is it?',options:["A real Roblox feature","A scam that steals your account","A safe way to earn Robux","A game update"],correct:1,explanation:"Free currency generators are always scams. Real Robux only comes from Roblox itself."},{q:"You want a mod for your game. Where is it safest to get it?",options:["A random link in a comment","A pop-up ad","An official or well-known trusted source","A strangerâs DM"],correct:2,explanation:"Only download from official stores or trusted sources. Random downloads can hide viruses that steal passwords."},{q:"An email says you won V-Bucks but must log in on their website to claim. What do you do?",options:["Log in fast before it expires","Do not click; real prizes never need your login on a strange site","Send it to friends","Reply with your username"],correct:1,explanation:"Any prize that needs your login on an outside site is a trap. Do not click."}]},{type:"complete",timer:5,title:"Scam-Proof!",takeaways:['Free-currency "generators" and giveaways that need your login are always scams',"Cheats and mods from random sites can hide viruses â use official sources","Check the web address before you click; weird spelling means fake","Real game money and items only come from the game itself"]}]},"ms-online-strangers":{title:"Online Strangers & Staying Safe",icon:"\uD83E\uDDD1â\uD83E\uDD1Dâ\uD83E\uDDD1",duration:"8 min",level:"Middle School \xb7 Grades 6-8",slides:[{type:"title",timer:5,title:"Online Strangers & Staying Safe",subtitle:'When a new online "friend" is not what they seem',objectives:["Recognize when someone online is not safe to trust","Know what never to share with people you only know online","Know that telling a trusted adult is always the right move"]},{type:"concept",timer:12,title:"People Online Are Not Always Who They Say",content:"In games and apps you meet people you do not know in real life. Most are fine â but some adults pretend to be kids to gain trust. A person who is a little TOO friendly, asks a lot of personal questions, wants to keep secrets, or tries to move you to a private chat is showing warning signs. This is not about being scared of everyone â it is about knowing the signs and having a plan.",callout:{icon:"\uD83D\uDEDF",title:"You will not be in trouble",text:"If something online feels weird or uncomfortable, telling a trusted adult is the BEST thing you can do. You are not in trouble â you are being smart and safe."}},{type:"keypoints",timer:24,title:'Warning Signs from an Online "Friend"',points:[{icon:"â",label:"Too many personal questions",desc:"They keep asking your age, where you live, your school, or your phone number. A real gaming buddy does not need any of that.",color:"#ef4444"},{icon:"\uD83E\uDD2B",label:"Wants to keep secrets",desc:'"Do not tell your parents about me." Anyone who wants your friendship to be a secret is a serious red flag.',color:"#f97316"},{icon:"\uD83D\uDCF7",label:"Asks for photos",desc:"Someone you only know online asking for pictures of you is never okay. You never have to send anything.",color:"#eab308"},{icon:"â¡ï¸",label:"Wants to move chats",desc:"They push you to leave the game and talk on a private app, like Snap or DMs, where no one else can see. That is a warning sign.",color:"#8b5cf6"},{icon:"\uD83C\uDF81",label:"Offers gifts to win you over",desc:"Free skins, game money, or gifts in exchange for chatting privately, photos, or personal info is a trick to build trust. Say no.",color:"#22c55e"}]},{type:"scenario",timer:0,title:"What Would You Do?",steps:[{text:'Someone you have played with a few times messages: "You are so cool! How old are you and what school do you go to? Add me on Snap so we can talk just us â do not tell your parents, they would not get it." What do you do?',choices:[{label:"Answer and add them on Snap",next:1},{label:"Do not share anything and tell a trusted adult",next:2},{label:"Just block them and say nothing to anyone",next:3}]},{text:"You shared your age and school and added them privately. Now someone you do not really know has personal info about you and a private line where no one can see what they s
1ay. This is exactly the situation to avoid.",outcome:"bad",lesson:'Personal questions + "keep it a secret" + "move to a private app" together are big warning signs. Do not share, and do not move to a private chat.',choices:[{label:"Try again",next:0}]},{text:"You did not share anything and told a parent or trusted adult what happened. They can help you block and report the person. You did exactly the right thing â that is the smartest, bravest move.",outcome:"best",lesson:"When someone online sends up these warning signs, do not share info, and tell a trusted adult. You will never be in trouble for that.",choices:[{label:"Continue",next:-1}]},{text:"Blocking them was a good start and kept you safe in the moment! But telling a trusted adult is even better â the person might try the same thing on other kids, and an adult can help report them.",outcome:"good",lesson:"Blocking protects you now; telling a trusted adult helps protect you AND others. Do both.",choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Quick Check",questions:[{q:"Someone you only know from a game asks your age, school, and to add them on a private app. What is the best move?",options:["Answer â they seem nice","Do not share, and tell a trusted adult","Give them a fake school name","Add them but do not talk much"],correct:1,explanation:"Personal questions plus moving to a private chat are warning signs. Do not share, and tell a trusted adult."},{q:'An online friend says "do not tell your parents about me." What does that tell you?',options:["They are just shy","It is a serious red flag","It is normal for online friends","They want to surprise you"],correct:1,explanation:"Anyone who wants your friendship kept secret from your parents is a major warning sign. Tell a trusted adult."},{q:"If something online makes you uncomfortable and you tell a trusted adult, what happens?",options:["You get in trouble","You are being smart and safe â not in trouble","You have to delete all your games","Nothing can be done"],correct:1,explanation:"Telling a trusted adult is the best, bravest thing you can do. You will not be in trouble â they are there to help."}]},{type:"complete",timer:5,title:"Safe & Smart!",takeaways:["Some people online pretend to be someone they are not","Warning signs: lots of personal questions, secrets, asking for photos, moving to private chats, gifts","Never share personal info or photos with people you only know online","If something feels wrong, tell a trusted adult â you will never be in trouble for that"]}]}},s={"spotting-phishing":{title:"Spotting Phishing Emails",icon:"\uD83C\uDFA3",duration:"10 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Spotting Phishing Emails",subtitle:"Learn to identify deceptive emails before you click",objectives:["Identify the 6 common phishing red flags","Analyze real vs. fake emails","Practice with realistic scenarios"]},{type:"concept",timer:12,title:"What is Phishing?",content:"Phishing is a cyberattack where criminals send deceptive messages designed to trick you into revealing sensitive information, clicking malicious links, or downloading harmful attachments. It's the #1 way data breaches begin.",stats:[{value:"91%",label:"of breaches start with phishing"},{value:"3.4B",label:"phishing emails sent daily worldwide"},{value:"$4.9M",label:"average cost per data breach"}],callout:{icon:"\uD83D\uDCE7",title:"How it works",text:"Attackers send emails that look like they're from someone you trust â your school district, your principal, a vendor. They want you to click a link, open an attachment, or share credentials. One click is all it takes."}},{type:"keypoints",timer:25,title:"The 6 Red Flags",points:[{icon:"â°",label:"Urgency",desc:'"Act now!" "Your account will be suspended!" Pressure to act fast prevents you from thinking clearly.',color:"#ef4444"},{icon:"\uD83D\uDC64",label:"Spoofed Sender",desc:"The display name looks right, but the email address is slightly off: [email protected]",color:"#f97316"},{icon:"\uD83D\uDD17",label:"Suspicious Links",desc:"Hover before you click. The displayed text says one thing, but the actual URL goes somewhere else entirely.",color:"#eab308"},{icon:"\uD83D\uDCCE",label:"Unexpected Attachments",desc:"Were you expecting this file? .exe, .zip, .docm files from unknown senders are dangerous.",color:"#22c55e"},{icon:"âï¸",label:"Poor Grammar",desc:"Typos, awkward phrasing, and formatting errors often signal auto-generated or foreign-origin content.",color:"#3b82f6"},{icon:"\uD83C\uDF81",label:"Too Good to Be True",desc:'"You\'ve won!" "Free gift card!" If it sounds too good to be true, it almost certainly is.',color:"#8b5cf6"}]},{type:"email_exercise",timer:0,title:"Spot the Phishing Email",instruction:"Read the email carefully and decide: is it real or a phishing attempt?",email:{from:{name:"IT Support",address:"[email protected]"},to:"[email protected]",time:"Today, 9:42 AM",subject:"â ï¸ URGENT: Your Email Password Expires in 2 Hours",body:"Dear Staff Member,\n\nYour email password will expire in 2 hours. To avoid losing access to your account, please verify your credentials immediately by clicking the link below.\n\nVERIFY YOUR PASSWORD NOW â https://diocse-portal.com/verify\n\nIf you do not verify within 2 hours, your account will be permanently locked and all emails will be deleted.\n\nThank you,\nIT Support Team",isPhishing:!0,redFlags:[{highlight:"di0cese-tech.com",explanation:"The sender domain uses a zero instead of 'o' â it's not your real domain."},{highlight:"expires in 2 Hours",explanation:"Artificial urgency is a classic phishing tactic. Real IT departments give you days, not hours."},{highlight:"diocse-portal.com",explanation:"The link domain is misspelled â this goes to a fake site."},{highlight:"permanently locked",explanation:"Threatening permanent deleti
1on creates panic. Real IT would never do this."}]}},{type:"email_exercise",timer:0,title:"Spot the Phishing Email",instruction:"Here's another one. Is this email legitimate or phishing?",email:{from:{name:"Sarah Mitchell",address:"[email protected]"},to:"[email protected]",time:"Today, 2:15 PM",subject:"Staff Meeting Agenda â Thursday 3pm",body:"Hi everyone,\n\nJust a reminder that our weekly staff meeting is Thursday at 3pm in the faculty lounge.\n\nAgenda items:\n⢠Spring fundraiser planning update\n⢠Field trip permission form changes\n⢠New attendance tracking system demo\n\nPlease let me know if you have anything to add to the agenda.\n\nThanks,\nSarah Mitchell\nAssistant Principal",isPhishing:!1,redFlags:[],legitimateReasons:"This email has a legitimate sender domain, no urgency tactics, no suspicious links, and a natural conversational tone. It's safe!"}},{type:"scenario",timer:0,title:"What Would You Do?",steps:[{text:"You receive an email from what appears to be your principal, asking you to urgently purchase $500 in Apple gift cards for a staff appreciation event. The email says to keep it confidential.",choices:[{label:"Buy the gift cards â the principal asked!",next:1},{label:"Reply to the email to ask for more details",next:2},{label:"Walk to the principal's office to confirm in person",next:3},{label:"Report it as suspicious using the Report button",next:4}]},{text:"You bought the gift cards and sent the codes. Unfortunately, this was an Organization Email Compromise (OEC) scam. The email was from an attacker impersonating your principal. The $500 is gone and cannot be recovered.",outcome:"bad",lesson:"Gift card requests via email are almost always scams. No legitimate organization buys gift cards this way.",choices:[{label:"Try again",next:0}]},{text:"You replied asking for details. The attacker responds with more urgency: \"Please hurry, the event is today! I'm in a meeting and can't talk.\" This is a common tactic to prevent you from verifying.",choices:[{label:"Okay, buy them now",next:1},{label:"Call the principal's known phone number",next:3},{label:"Report the email as suspicious",next:4}]},{text:"You walked to the principal's office (or called their known number). The principal has no idea what you're talking about â they never sent that email. You just prevented a $500 loss!",outcome:"good",lesson:"Always verify unusual requests through a separate channel. Never trust the contact info in the suspicious email itself.",choices:[{label:"Continue",next:-1}]},{text:"You reported the email using the Report Suspicious button. The IT admin investigated and confirmed it was an OEC attack targeting multiple staff members. Your quick action protected the entire school!",outcome:"best",lesson:"Reporting suspicious emails helps protect everyone. The sooner threats are identified, the faster they can be blocked.",choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"What should you do if an email creates a sense of extreme urgency?",options:["Act immediately as instructed","Slow down and verify through another channel","Forward it to all staff","Delete it and ignore it"],correct:1,explanation:"Urgency is a manipulation tactic. Always slow down and verify through a separate, trusted channel."},{q:"Which sender address is suspicious?",options:["[email protected]","[email protected]","[email protected]","[email protected]"],correct:1,explanation:'The zero in "amaz0n" is a character substitution trick. Always check addresses carefully.'},{q:"Your principal emails asking you to buy gift cards. Best response?",options:["Buy them â it's the principal!","Reply to the email to confirm","Call the principal using a known phone number","Ask a coworker"],correct:2,explanation:"Always verify through a completely separate channel. Calling a known number is safest."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["Always check the sender's actual email address, not just the display name","Slow down when emails create urgency â that's a red flag","Hover over links before clicking to verify the real URL","When in doubt, verify through a separate channel (phone, in person)"]}]},"password-hygiene":{title:"Password Hygiene & Security",icon:"\uD83D\uDD11",duration:"10 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Password Hygiene & Security",subtitle:"Strong passwords are your first line of defense",objectives:["Create truly strong passwords","Understand why password reuse is dangerous","Set up multi-factor authentication"]},{type:"concept",timer:20,title:"Why Passwords Matter",content:"Your password is the key to your digital life. Weak or reused passwords are the easiest way for attackers to gain access to school systems, student records, and financial accounts.",stats:[{value:"81%",label:"of breaches involve weak or stolen passwords"},{value:"23M",label:'people still use "123456" as their password'},{value:"< 1sec",label:"to crack a 6-character password"}],callout:{icon:"\uD83D\uDC80",title:"The domino effect",text:"When you reuse the same password across sites, one breach exposes everything. If your personal email password is the same as your school login, a data breach at any site you use gives attackers access to your school's systems."}},{type:"keypoints",timer:20,title:"What Makes a Password Strong?",points:[{icon:"\uD83D\uDCCF",label:"Length Over Complexity",desc:'"correcthorsebatterystaple" is stronger than "P@$$w0rd!" â longer passwords take exponentially longer to crack.',color:"#22c55e"},{icon:"\uD83D\uDEAB",label:"Never Reuse",desc:"Every account gets a unique password. Period. One breach shouldn't compromise everything.",color:"#ef4444"},{icon:"\uD83D\uDDDDï¸",label:"Use a Password Manager",desc:"Tools like Bitwarden (free) or 1Password generate and remember strong unique passwords for you.",color:"#3b82f6"},{icon:"\uD83D\uDCF1",label:"Enable MFA Everywhere",desc:"Multi-factor authentication means even if your password is stolen, attackers still can't get in.",color:"#8b5cf6"},{icon:"\uD83D\uDD12",label:"Passphrase Method",desc:'String 4+ random words together: "purple-elephant-drives-tuesday" â easy to remember, nearly impossible to crack.',color:"#f97316"}]},{type:"concept",timer:20,title:"How Fast Can Your Password Be Cracked?",content:"Modern computers can test billions of password combinations per second. The length and complexity of your password determines how long it would take to crack.",stats:[{value:"Instant",label:"6 characters, lowercase only"},{value:"3 hours",label:"8 characters, mixed case + numbers"},{value:"34 years",label:"12 characters, mixed case + numbers + symbols"}],callout:{icon:"\uD83D\uDEE1ï¸",title:"The sweet spot",text:'Use 16+ characters (a passphrase) with a mix of words. "sunflower-piano-rocket-blue42" would take millions of years to crack by brute force â and you can actually remember it.'}},{type:"scenario",timer:0,title:"Password Scenario",steps:[{text:'You need to create a new password for your school email. The old one was "StMarys2024!" â what do you choose?',choices:[{label:"StMarys2025! (just update the year)",next:1},{label:"Use the same password as my personal Gmail",next:2},{label:"Generate one with a password manager",next:3},{label:'Write "purple-walrus-teaches-math" on a sticky note',next:4}]},{text:'Predictable patterns like incrementing the year are the first thing attackers try. "StMarys2025!" would be cracked in minutes using a targeted dictionary attack against your school.',outcome:"bad",lesson:"Never use predictable variations of old passwords. Each password should be completely different.",choices:[{label:"Try again",next:0}]},{text:"Password reuse is the #1 password mistake. If your Gmail is ever breached (and Google has had incidents), attackers will immediately try that password on your school email, bank, and every other account.",outcome:"bad",lesson:"Every account needs a unique password. One breach should never compromise multiple accounts.",choices:[{label:"Try again",next:0}]},{text:"A password manager generates a strong, unique, random password and remembers it for you. You only need to remember one master password. This is the gold standard for password security.",outcome:"best",lesson:"Password managers like Bitwarden (free) or 1Password eliminate the need to remember dozens of passwords.",choices:[{label:"Continue",next:-1}]},{text:'The passphrase "purple-walrus-teaches-math" is actually very strong â but writing it on a sticky note defeats the purpose! Anyone who walks by your desk can see it. Use a password manager instead.',outcome:"good",lesson:"Passphrases are great, but store them securely â in a password manager, not on paper.",choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"Which password is strongest?",options:["P@$$
1w0rd!","correct-horse-battery-staple","12345678","qwerty2024"],correct:1,explanation:"Long passphrases are far stronger than short complex passwords. Length beats complexity every time."},{q:"What is the biggest risk of password reuse?",options:["It's hard to remember","One breach compromises all your accounts","It slows down your computer","Nothing â reuse is fine"],correct:1,explanation:"When one site is breached, attackers try those credentials on every other site. One breach = all accounts compromised."},{q:"What is the best way to manage unique passwords for every account?",options:["Write them in a notebook","Use a password manager","Use the same base with different endings","Let your browser save them"],correct:1,explanation:"Password managers generate, store, and auto-fill strong unique passwords. They're the most secure and convenient option."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["Use passphrases (4+ random words) â length beats complexity","Never reuse passwords across accounts","Use a password manager like Bitwarden (free) or 1Password","Enable multi-factor authentication on every account that offers it"]}]},"social-engineering":{title:"Social Engineering 101",icon:"\uD83C\uDFAD",duration:"12 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Social Engineering 101",subtitle:"How attackers manipulate people to gain access",objectives:["Recognize manipulation tactics","Understand pretexting, baiting, and tailgating","Respond correctly to social engineering attempts"]},{type:"concept",timer:20,title:"What is Social Engineering?",content:"Social engineering is the art of manipulating people into giving up confidential information or performing actions that compromise security. Unlike hacking computers, social engineers hack people â exploiting trust, authority, and helpfulness.",stats:[{value:"98%",label:"of cyber attacks involve social engineering"},{value:"$130K",label:"average loss per email-compromise scam"},{value:"85%",label:"of breaches involve a human element"}],callout:{icon:"\uD83E\uDDE0",title:"Why it works",text:"We're wired to trust authority figures, help people in need, and respond to urgency. Attackers exploit these natural instincts. The best defense is awareness â knowing the tactics makes you much harder to fool."}},{type:"keypoints",timer:25,title:"Common Attack Types",points:[{icon:"\uD83C\uDFAD",label:"Pretexting",desc:'Creating a fake scenario to gain trust. "Hi, I\'m from the IT department and need to verify your credentials for a system update."',color:"#ef4444"},{icon:"\uD83C\uDFA3",label:"Phishing",desc:"Fraudulent emails that impersonate trusted entities. The most common social engineering attack.",color:"#f97316"},{icon:"\uD83D\uDCF1",label:"Vishing",desc:'Voice phishing â phone calls from "Microsoft Support," "the IRS," or "your bank" demanding immediate action.',color:"#eab308"},{icon:"\uD83C\uDF6C",label:"Baiting",desc:"Leaving infected USB drives in parking lots, or offering free downloads that contain malware.",color:"#22c55e"},{icon:"\uD83D\uDEAA",label:"Tailgating",desc:'Following an authorized person through a secured door. "Oh, I forgot my badge â can you hold the door?"',color:"#3b82f6"},{icon:"\uD83D\uDC8E",label:"Quid Pro Quo",desc:'"I\'ll fix your computer if you give me your login credentials." Offering something in exchange for access.',color:"#8b5cf6"}]},{type:"scenario",timer:0,title:"Can You Spot the Social Engineer?",steps:[{text:"You're at the front desk when someone in a repair uniform says: \"Hi, I'm here from the copier company to do maintenance. The principal called us. Can you let me into the server room? The copier connects through there.\"",choices:[{label:"Let them in â they have a uniform",next:1},{label:"Ask to see their company ID",next:2},{label:"Call the principal to verify the appointment",next:3},{label:"Say no and ask them to wait while you verify",next:3}]},{text:'You let them in. They plugged a small device into the network switch â it\'s now capturing all network traffic including passwords. The "repair person" was a social engineer. The uniform was purchased online for $30.',outcome:"bad",lesson:"Uniforms, clipboards, and confidence are easy to fake. Always verify before granting access to sensitive areas.",choices:[{label:"Try again",next:0}]},{text:'You asked for ID. They showed a badge that says "CopyTech Solutions" with their photo. It looks professional. But fake IDs are trivially easy to create. A company ID alone doesn\'t confirm a legitimate appointment.',choices:[{label:"Let them in â the ID looks real",next:1},{label:"Call the principal to verify",next:3}]},{text:'You called the principal, who confirmed no copier appointment was scheduled. The "repair person" quickly left when they realized you were verifying. You prevented unauthorized access to your school\'s network!',outcome:"best",lesson:"Always verify through your own channels. A quick call to confirm an appointment takes 30 seconds and can prevent a serious breach.",choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:'Someone calls claiming to be from IT and asks for your password to "fix an issue." What do you do?',options:["Give them the password â IT needs it","Hang up and call the IT department directly","Ask them to verify they're real","Email them the password instead"],correct:1,explanation:"Legitimate IT staff never ask for your password. Hang up and contact IT through a known number."},{q:'What is "pretexting"?',options:["Writing code to break into systems","Creating a fake scenario to gain trust","Testing physical security with fake badges","Sending mass spam emails"],correct:1,explanation:"Pretexting is creating a fabricated scenario â a false identity, a fake emergency â to manipulate you into trusting the attacker."},{q:'Which is an example of "baiting"?',options:["A phishing email from your bank",'A USB drive labeled "Staff Salaries" left in the parking lot',"A phone call from Microsoft Support","Following someone through a locked door"],correct:1,explanation:'Baiting exploits curiosity. That "lost" USB drive is designed to be found and plugged in â installing malware automatically.'}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["Never share passwords â legitimate IT will never ask","Verify identities through your own channels, not theirs","Be wary of urgency, authority, and helpfulness being exploited","Report suspicious visitors, calls, or emails immediately"]}]},"links-attachments":{title:"Safe Links & Attachments",icon:"\uD83D\uDD17",duration:"10 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Suspicious Links & Attachments",subtitle:"How to safely handle links and files in emails",objectives:["Identify malicious URLs before clicking","Recognize dangerous file types","Know
1when and how to safely open attachments"]},{type:"concept",timer:20,title:"Links: The Hidden Danger",content:'A link in an email can say anything â "Click here to view your invoice" â but take you somewhere completely different. Malicious links can install malware, steal credentials, or download ransomware with a single click.',stats:[{value:"86%",label:"of organizations had a user click a phishing link"},{value:"< 60s",label:"average time from click to compromise"},{value:"$1.4M",label:"average cost of a ransomware attack on schools"}],callout:{icon:"\uD83D\uDD17",title:"Hover before you click",text:"On a computer, hover your mouse over any link to see where it actually goes. The display text and the real URL are often completely different. On mobile, long-press to preview the URL."}},{type:"keypoints",timer:20,title:"Dangerous Link Red Flags",points:[{icon:"\uD83D\uDD24",label:"Misspelled Domains",desc:"googIe.com (capital I instead of lowercase L), paypa1.com, amaz0n.com â tiny changes hide fake sites.",color:"#ef4444"},{icon:"\uD83D\uDCCF",label:"Overly Long URLs",desc:"Legitimate sites have clean URLs. Phishing links are often very long with random characters to hide the real destination.",color:"#f97316"},{icon:"\uD83D\uDD13",label:"HTTP (Not HTTPS)",desc:"Legitimate login pages always use HTTPS (lock icon). HTTP means the connection is not encrypted â never enter passwords.",color:"#eab308"},{icon:"\uD83C\uDFAF",label:"URL Shorteners",desc:"bit.ly, tinyurl.com links hide the real destination. In emails from unknown senders, treat shortened links as suspicious.",color:"#3b82f6"},{icon:"\uD83D\uDCCB",label:"Mismatched Display Text",desc:'The link says "Login to Office 365" but actually points to hacker-site.ru/o365login â always hover to check.',color:"#8b5cf6"}]},{type:"keypoints",timer:15,title:"Dangerous Attachment Types",points:[{icon:"â ï¸",label:".exe, .scr, .bat",desc:"Executable files â NEVER open these from email. They run programs on your computer, often malware.",color:"#ef4444"},{icon:"\uD83D\uDCE6",label:".zip, .rar, .7z",desc:"Compressed archives can hide malicious files inside. Only open if you were expecting the file from a known sender.",color:"#f97316"},{icon:"\uD83D\uDCC4",label:".docm, .xlsm",desc:'The "m" means macros â these can execute code when opened. Regular .docx and .xlsx are safer.',color:"#eab308"},{icon:"â
",label:".pdf, .docx, .xlsx",desc:"Generally safe, but still verify the sender. Even these can contain embedded links or exploit vulnerabilities.",color:"#22c55e"}]},{type:"email_exercise",timer:0,title:"Would You Click This Link?",instruction:"Examine this email and decide if it's safe.",email:{from:{name:"School Supplies Direct",address:"[email protected]"},to:"[email protected]",time:"Today, 11:30 AM",subject:"Your Order #88291 Has Shipped â Track Now",body:"Hello,\n\nGreat news! Your order #88291 has shipped and is on its way.\n\nTrack your package: https://school-supp1ies-direct.com/track/88291\n\nExpected delivery: Tomorrow by 5pm.\n\nIf you have questions, contact us at [email protected]\n\nSchool Supplies Direct Team",isPhishing:!0,redFlags:[{highlight:"school-supp1ies-direct.com",explanation:'The number "1" replaces the letter "l" in "supplies" â this is a fake domain.'},{highlight:"Order #88291",explanation:"Did you actually place this order? Unexpected shipping notifications for orders you didn't make are a common phishing tactic."},{highlight:"Track your package",explanation:"This link goes to the same fake domain. Clicking it would likely lead to a credential harvesting page or malware download."}]}},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"Before clicking a link in an email, you should:",options:["Click it to see where it goes","Hover over it to check the real URL",'Right-click and select "Open"',"Forward the email to a friend to check"],correct:1,explanation:"Hovering reveals the actual destination URL. This takes 2 seconds and can prevent a compromise."},{q:"Which file attachment is MOST dangerous?",options:["report.pdf","budget.xlsx","update.exe","photo.jpg"],correct:2,explanation:".exe files are executable programs. Opening one from an email could install mal
1ware, ransomware, or spyware."},{q:'A URL contains "paypa1.com" â is this legitimate?',options:["Yes â it's PayPal",'No â the "l" is replaced with "1"',"Can't tell without clicking","Yes â if it has HTTPS"],correct:1,explanation:"Character substitution (1 for l, 0 for o) is a common trick to create convincing fake domains."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["Always hover over links before clicking to see the real URL","Never open .exe, .bat, or .scr attachments from email","Be suspicious of unexpected orders, invoices, or shipping notifications","When in doubt, go directly to the website by typing the URL yourself"]}]},"safe-browsing":{title:"Safe Browsing Habits",icon:"\uD83C\uDF10",duration:"10 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Safe Browsing Habits",subtitle:"Protect yourself online with smart browsing",objectives:["Identify unsafe websites","Protect personal information online","Avoid common web-based threats"]},{type:"concept",timer:20,title:"The Web is a Battlefield",content:"Every time you browse the web, you're navigating a landscape filled with legitimate sites and convincing fakes. Malicious websites can install malware, steal credentials, and compromise your device â often without you realizing anything happened.",stats:[{value:"560K",label:"new malware detected every day"},{value:"1 in 13",label:"web requests lead to malware"},{value:"$10B+",label:"lost to internet crime annually"}],callout:{icon:"\uD83C\uDF10",title:"Drive-by downloads",text:'Some malicious sites can infect your computer just by visiting them â no clicks needed. This is called a "drive-by download." Keeping your browser and OS updated is critical protection.'}},{type:"keypoints",timer:20,title:"Safe Browsing Rules",points:[{icon:"\uD83D\uDD12",label:"Check for HTTPS",desc:'Look for the lock icon and "https://" in the address bar. Never enter passwords or personal info on HTTP sites.',color:"#22c55e"},{icon:"\uD83D\uDD04",label:"Keep Everything Updated",desc:"Browser, operating system, plugins â updates patch security vulnerabilities that attackers exploit.",color:"#3b82f6"},{icon:"\uD83D\uDEAB",label:"Avoid Public WiFi for Sensitive Tasks",desc:"Coffee shop WiFi is not secure. Never access banking, email, or school systems on public networks without a VPN.",color:"#ef4444"},{icon:"\uD83C\uDF6A",label:"Manage Browser Extensions",desc:"Only install extensions from trusted sources. Malicious extensions can read everything you type, including passwords.",color:"#f97316"},{icon:"\uD83D\uDD0D",label:"Verify Before You Download",desc:'Only download software from official sources. That "free" tool from a random site likely contains malware.',color:"#8b5cf6"}]},{type:"scenario",timer:0,title:"Safe Browsing Scenario",steps:[{text:"You're at a coffee shop grading papers on your laptop. You need to check a student's grade in the school portal. The coffee shop has free WiFi.",choices:[{label:"Connect to the free WiFi and log in to the portal",next:1},{label:"Use your phone as a mobile hotspot instead",next:2},{label:"Wait until you're back at school",next:3}]},{text:'You logged in over public WiFi. An attacker on the same network intercepted your credentials using a "man-in-the-middle" attack. They now have access to the school portal with your login.',outcome:"bad",lesson:"Public WiFi is inherently insecure. Anyone on the same network can potentially intercept your data.",choices:[{label:"Try again",next:0}]},{text:"Smart choice! Your phone's mobile hotspot creates a private, encrypted connection. You can safely access the school portal without exposing your credentials to other users on the network.",outcome:"best",lesson:"Mobile hotspots are much safer than public WiFi for accessing sensitive systems.",choices:[{label:"Continue",next:-1}]},{text:"Waiting is a safe option, though not always practical. If you need to work remotely, a mobile hotspot or VPN are good alternatives to public WiFi.",outcome:"good",lesson:"When public WiFi is the only option, use a VPN to encrypt your connection.",choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"You need to download a PDF converter. Where should you get it?",options:["First result on Google","The developer's official website",'A torrent site with a "verified" badge',"A link someone shared on Facebook"],correct:1,explanation:"Always download from official sources. Search results, social media links, and torrent sites frequently distribute malware."},{q:"Which is safest for accessing school systems remotely?",options:["Coffee shop WiFi","Hotel WiFi","Your phone's mobile hotspot","Your neighbor's open WiFi"],correct:2,explanation:"Your phone's hotspot creates a private encrypted connection that only you use. All other options share the network with strangers."},{q:'A website asks you to "disable your antivirus to download." What should you do?',options:["Disable it â the site knows best","Download anyway with antivirus on","Leave the site immediately","Check if it's a known site"],correct:2,explanation:"No legitimate software asks you to disable security. This is a massive red flag that the download contains malware."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["Always verify HTTPS before entering any credentials","Never use public WiFi for sensitive logins â use a hotspot or VPN","Keep your browser and OS updated at all times","Only download software from official, trusted sources"]}]},quishing:{title:"QR Code Scams (Quishing)",icon:"\uD83D\uDD33",duration:"9 min",isPublic:!1,slides:[{type:"title",timer:5,title:"QR Code Scams (Quishing)",subtitle:"Why that little square can be more dangerous than a link",objectives:['Understand how QR-code phishing ("quishing") works',"Spot QR codes you should never scan","Safely reveal where a QR code actually leads"]},{type:"concept",timer:20,title:"What is Quishing?",content:"Quishing is phishing that hides the malicious link inside a QR code instead of a clickable URL. You point your phone's camera at the square, it opens a website â but you never saw the address before you arrived. Because the link is an image, most email filters can't read it, so quishing slips past defenses that would catch a normal phishing link.",stats:[{value:"587%",label:"rise in quishing attacks in a single year"},{value:"~25%",label:"of email phishing now uses QR codes"},{value:"0",label:"security tools on most phones checking the link first"}],callout:{icon:"\uD83D\uDCF1",title:"Why your phone is the weak point",text:"QR codes are almost always scanned on a personal phone â which usually has none of the protections your work computer does. The attacker moves you from a monitored device to an unmonitored one in one scan."}},{type:"keypoints",timer:25,title:"Where Fake QR Codes Show Up",points:[{icon:"\uD83D\uDCE7",label:"In emails",desc:'"Scan this QR code to re-verify your Microsoft 365 account" or to "view your secure document." The image dodges link filters.',color:"#ef4444"},{icon:"\uD83D\uDCC4",label:"In PDF attachments",desc:'A PDF "invoice" or "voicemail" with a QR code inside â doubly hidden, since the link is an image inside a file.',color:"#f97316"},{icon:"\uD83C\uDD7Fï¸",label:"On stickers in the real world",desc:"Fake QR stickers slapped over real ones on parking meters, EV chargers, and restaurant tables redirect your payment.",color:"#eab308"},{icon:"\uD83D\uDCEC",label:"On printed letters & flyers",desc:'"Your package couldn\'t be delivered â scan to reschedule." Mailed physical scams feel more legitimate than email.',color:"#3b82f6"},{icon:"\uD83D\uDCB3",label:"Fake payment / donation codes",desc:'A QR taped to a collection box or sent for a "quick payment" sends your money to the attacker, not the school.',color:"#8b5cf6"}]},{type:"email_exercise",timer:0,title:"Would You Scan This?",instruction:"Read the email and decide: is this a
1safe QR code or a quishing attempt?",email:{from:{name:"Microsoft 365 Security",address:"[email protected]"},to:"[email protected]",time:"Today, 8:05 AM",subject:"Action required: re-verify your account within 24 hours",body:"Your organization has enabled new security settings. To keep access to your St. Mary's email, you must re-verify your account using your mobile device.\n\n[ ⢠QR CODE ]\n\nScan the QR code above with your phone camera to confirm your identity. If you do not verify within 24 hours, your access will be suspended.\n\nMicrosoft 365 Security Team",isPhishing:!0,redFlags:[{highlight:"m365-secure-verify.com",explanation:"Microsoft does not send security mail from random third-party domains. This is not a Microsoft address."},{highlight:"Scan the QR code",explanation:"Pushing you to scan on your PHONE moves you to a device with no security tools â the whole point of quishing."},{highlight:"within 24 hours",explanation:"Artificial urgency to stop you from verifying through normal channels."},{highlight:"re-verify your account",explanation:"Real MFA setup happens inside your account settings, never by scanning a code emailed to you out of the blue."}]}},{type:"scenario",timer:0,title:"What Would You Do?",steps:[{text:'You get an email at work: "Your voicemail transcript is ready â scan the QR code to listen." You weren\'t expecting a voicemail. What do you do?',choices:[{label:"Scan it with my phone to hear the voicemail",next:1},{label:"Forward it to a coworker to scan",next:2},{label:"Report it â a QR code for a voicemail is odd",next:3}]},{text:"You scanned it. The page looked like a Microsoft login and you entered your password. It was a fake â attackers now have your school credentials, captured on your phone where nothing flagged the site.",outcome:"bad",lesson:"Never scan a QR code in an unexpected email. The square hides the destination until you're already there.",choices:[{label:"Try again",next:0}]},{text:"Forwarding it just moves the trap to someone else â and if they scan it, the school is still compromised. The right move is to report it, not pass it around.",choices:[{label:"Report it instead",next:3},{label:"Scan it anyway",next:1}]},{text:"You reported it. IT confirmed a quishing wave hitting several staff and blocked the sender. Your phone company's voicemail never arrives as an emailed QR code â verifying through the real system would have shown nothing was waiting.",outcome:"best",lesson:"When a QR code arrives unexpectedly, treat it exactly like a suspicious link: don't scan, report it.",choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"Why is quishing so effective at getting past defenses?",options:["QR codes are encrypted","The link is an image, so email filters can't read it","Phones are more secure than computers","QR codes can't contain links"],correct:1,explanation:"Because the URL is hidden inside an image, link-scanning filters never see it â and you scan on a phone with fewer protections."},{q:'You get a printed letter saying "scan to reschedule your missed delivery." What\'s safest?',options:["Scan it â printed mail is trustworthy","Go to the carrier's official website or app directly","Scan it but don't enter a password","Reply to the letter"],correct:1,explanation:"Physical mail can be faked too. Go to the real carrier yourself instead of scanning an unsolicited code."},{q:"A QR sticker on a parking meter sends you to a payment page. What should you suspect?",options:["Nothing â it's on official equipment","It may be a fake sticker placed over the real one","QR codes can't be tampered with","It's only risky if it asks for a password"],correct:1,explanation:"Fake QR stickers placed over real ones are a common real-world scam. Pay through the official app or a known URL."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["A QR code is just a hidden link â treat unexpected ones like suspicious links","Quishing slips past email filters because the link is an image","Be extra wary of codes that push you to scan on your phone","Reach payment, login, and delivery sites directly â don't scan to get there"]}]},"smishing-vishing":{title:"Text & Phone Scams (Smishing & Vishing)",icon:"âï¸",duration:"10 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Text & Phone Scams",subtitle:"Phishing doesn't only arrive by email",objectives:["Recognize smishing (text) and vishing (voice) scams","Defend against MFA fatigue and callback phishing","Know the one rule that defeats almost all of them"]},{type:"concept",timer:20,title:"Smishing & Vishing",content:"Smishing is phishing by SMS text message; vishing is phishing by voice call. Attackers use them because we trust our phones and answer quickly. A text feels personal, and a live voice can pressure you in real time in
1ways an email never could.",stats:[{value:"$1.2B+",label:"lost to text and call scams in a single year"},{value:"68%",label:"of people open every text they receive"},{value:"3 sec",label:"a spoofed caller ID takes to fake any number"}],callout:{icon:"\uD83D\uDCDE",title:"Caller ID lies",text:"The name and number on an incoming call can be completely faked. \"St. Mary's IT\" or even your bank's real number showing up means nothing â anyone can spoof it."}},{type:"keypoints",timer:25,title:"Common Text & Call Scams",points:[{icon:"\uD83D\uDCE6",label:"Package / delivery texts",desc:'"Your USPS package is held â pay a $1.99 fee here." A tiny, believable amount to capture your card.',color:"#ef4444"},{icon:"\uD83C\uDFE6",label:"Fake fraud alerts",desc:'"Did you spend $750? Reply NO." Replying starts a conversation where they "help" you by stealing your login.',color:"#f97316"},{icon:"\uD83D\uDEE0ï¸",label:"Tech / IT support calls",desc:'"This is Microsoft â we detected a virus." Real vendors never cold-call you about your computer.',color:"#eab308"},{icon:"\uD83D\uDD14",label:"MFA fatigue (push bombing)",desc:'They have your password and spam your phone with login approval prompts, hoping you tap "Approve" to make it stop.',color:"#8b5cf6"},{icon:"â©ï¸",label:"Callback phishing",desc:'An email or text says "call this number about a charge." The number is the attacker, ready to talk you into access.',color:"#3b82f6"}]},{type:"scenario",timer:0,title:"The 2 A.M. Approval Prompts",steps:[{text:"At 2 a.m. your phone buzzes again and again: \"Approve sign-in?\" notifications from your school account. You didn't try to log in. What's happening, and what do you do?",choices:[{label:"Tap Approve so the notifications stop",next:1},{label:"Ignore/deny them and change my password now",next:2},{label:"Turn the phone over and go back to sleep",next:3}]},{text:'You approved it. That was an attacker who already had your password â the prompt was the only thing standing between them and your account. They\'re now in. This is "MFA fatigue," and tapping Approve is exactly what they wanted.',outcome:"bad",lesson:"Never approve a login prompt you didn't start. A flood of prompts means someone already has your password â deny and change it immediately.",choices:[{label:"Try again",next:0}]},{text:"Exactly right. Repeated prompts you didn't trigger mean your password is already compromised. You denied every prompt, changed your password, and told IT. The attacker is locked out.",outcome:"best",lesson:"Deny unexpected MFA prompts, change your password, and report it. The prompts stop because access is cut off â not because you approved.",choices:[{label:"Continue",next:-1}]},{text:"Ignoring the prompts at least didn't let them in â but the attacker still has your password and will keep trying. You need to change your password and tell IT, not just wait it out.",outcome:"good",lesson:"Denying is good, but follow through: change the compromised password and report it so IT can secure the account.",choices:[{label:"Continue",next:-1}]}]},{type:"concept",timer:15,title:"The One Rule That Beats Them All",content:"Almost every text and call scam dies the moment you verify through a channel you chose. Hang up and call the bank using the number on your card. Visit the delivery company's real website yourself. Walk down the hall to ask the principal. The attacker controls the channel they contacted you on â so use a different one you trust.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Hang up and call back",text:'No legitimate organization will object to you hanging up and calling their official number to confirm. Anyone who pressures you to "stay on the line" is telling you it\'s a scam.'}},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"Your phone shows your bank's real number calling about fraud. Can you trust it?",options:["Yes â the number proves it's them","No â caller ID can be spoofed; hang up and call the number on your card","Yes, if they know your name","Only if they call twice"],correct:1,explanation:"Caller ID is trivially faked. Hang up and call back on the official number you look up yourself."},{q:'You get repeated MFA "approve sign-in?" prompts you didn\'t request. What does it mean?',options:["A glitch â just approve one","Someone already has your password â deny and change it","Your phone needs an update","Nothing important"],correct:1,explanation:"Unprompted MFA requests mean your password is compromised. Deny, change the password, and report it."},{q:'A text says "call this number about a suspicious charge." What is this likely to be?',options:["Helpful customer service","Callback phishing â the number is the attacker","A wrong number","A legitimate bank alert"],correct:1,explanation:"Callback phishing lures you into dialing the attacker. Use the number on your card
1instead."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["Smishing (text) and vishing (voice) exploit how much we trust our phones","Caller ID and sender numbers can be faked â they prove nothing","Never approve an MFA prompt you didn't start â deny and change your password","Always verify by hanging up and using a number or website you chose"]}]},"bec-payment-fraud":{title:"Organization Email Compromise & Payment Fraud",icon:"\uD83D\uDCB8",duration:"11 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Organization Email Compromise & Payment Fraud",subtitle:"The quiet scam that drains school bank accounts",objectives:["Understand how OEC and payment fraud target schools","Recognize wire-change, invoice, and gift-card scams","Use the dual-channel rule before any money moves"]},{type:"concept",timer:20,title:"What is OEC?",content:"Organization Email Compromise (OEC) is when an attacker impersonates someone you trust â the principal, a vendor, the diocese â to trick you into sending money or changing payment details. There's often no malware and no bad link, just a convincing message. That's why it slips past filters and costs organizations more than any other cybercrime.",stats:[{value:"$2.9B+",label:"lost to OEC in a single year (FBI IC3)"},{value:"#1",label:"most expensive type of cybercrime"},{value:"$50K+",label:"typical loss in a single school incident"}],callout:{icon:"\uD83D\uDCB8",title:"Why schools are targets",text:"Schools move real money (tuition, payroll, vendors) often with small finance teams and trusting cultures. Attackers research your staff on the website and social media, then strike at the right moment."}},{type:"keypoints",timer:25,title:"The Main Plays",points:[{icon:"\uD83C\uDFE6",label:"Vendor bank-account change",desc:'"Please update our banking details for this month\'s payment." The next real invoice gets paid to the attacker.',color:"#ef4444"},{icon:"\uD83E\uDDFE",label:"Fake or altered invoices",desc:"A real-looking invoice from a real-sounding vendor for services you can't quite remember ordering.",color:"#f97316"},{icon:"\uD83C\uDF81",label:"Gift card requests",desc:"\"I'm in a meeting â grab $500 in gift cards and send the codes, I'll reimburse you.\" Always a scam.",color:"#eab308"},{icon:"\uD83D\uDCB5",label:"Wire / ACH redirection",desc:'Urgent "confidential" requests to wire funds for a deal, a deposit, or tuition â to a new account.',color:"#8b5cf6"},{icon:"\uD83E\uDDD1â\uD83D\uDCBC",label:"Payroll diversion",desc:'"Please update my direct deposit before Friday\'s run." Staff paychecks get rerouted to the attacker.',color:"#3b82f6"}]},{type:"email_exercise",timer:0,title:"Approve This Payment Change?",instruction:"You handle vendor payments. Is this request safe to act on?",email:{from:{name:"Riverside Catering",address:"[email protected]"},to:"[email protected]",time:"Today, 3:48 PM",subject:"Updated banking details for upcoming payment",body:"Hello,\n\nThank you for your continued business with St. Mary's. Please note that we have changed banks. Kindly update our records so your next payment reaches the correct account:\n\nNew Account: 8841720094\nRouting: 021000021\n\nPlease confirm once updated, as our previous account is now closed. Apologies for any inconvenience.\n\nAccounts Receivable\nRiverside Catering",isPhishing:!0,redFlags:[{highlight:"riverside-catering-accounts.com",explanation:'A look-alike domain with "-accounts" tacked on â not the vendor\'s real address. Compare it to past, known-good emails.'},{highlight:"changed banks",explanation:"A bank-account change request is the single most common OEC play. Always verify it by phone before changing anything."},{highlight:"previous account is now closed",explanation:"Pressure to switch fast, before you can confirm, so the next payment lands with the attacker."},{highlight:"Please confirm once updated",explanation:"They want you to act and reply rather than pick up the phone and call a known number."}]}},{type:"scenario",timer:0,title:"The Urgent Wire Request",steps:[{text:'You get an email from the principal: "We\'re closing on the new playground equipment today. Please wire the $18,500 deposit to the vendor now â details attached. Keep this confidential until I announce it." What do you do?',choices:[{label:"Wire it â the principal asked and it's urgent",next:1},{label:"Reply to the email to confirm the details",next:2},{label:"Call or walk to the principal on a known number",next:3}]},{text:"You sent the wire. It was an OEC attacker impersonating the principal, who never sent that email. Wired funds are nearly impossible to re
1cover â the $18,500 is gone.",outcome:"bad",lesson:"Urgency + confidentiality + a money transfer is the classic OEC recipe. Never move funds on an email alone.",choices:[{label:"Try again",next:0}]},{text:'You replied to confirm. The attacker controls that mailbox (or a look-alike), so they happily reply "Yes, go ahead â please hurry." Replying only ever reaches the attacker.',choices:[{label:"Wire it now",next:1},{label:"Call the principal on a known number",next:3}]},{text:"You called the principal directly. They had no idea what you were talking about â there was no playground deal. You stopped an $18,500 loss cold.",outcome:"best",lesson:"Verify every payment or banking change through a second, trusted channel â a known phone number or in person. Make it policy, not a judgment call.",choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"A vendor emails new banking details for their next payment. What's the right first step?",options:["Update it right away to avoid delay","Call the vendor on a known number to verify","Reply asking if they're sure","Forward it to a coworker to handle"],correct:1,explanation:"Bank-change requests are the top OEC tactic. Always confirm by phone using a number you already have."},{q:"What combination is the classic OEC warning sign?",options:["A friendly tone and a signature","Urgency, confidentiality, and a money movement","An attached PDF","A long email thread"],correct:1,explanation:"Pressure to act fast, keep it secret, and move money is the signature of organization email compromise."},{q:"Why are wired funds especially dangerous in these scams?",options:["They're taxed twice","They're nearly impossible to recover once sent","They're always small amounts","Banks reverse them automatically"],correct:1,explanation:"Wires settle fast and are very hard to claw back â which is exactly why attackers prefer them."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["OEC impersonates people you trust â often with no link or malware to catch","Bank-change, invoice, gift-card, wire, and payroll requests are the common plays","Urgency + confidentiality + money = verify before you act","Confirm every payment or banking change through a second, known channel"]}]},"ai-deepfakes":{title:"AI Threats & Deepfakes",icon:"\uD83E\uDD16",duration:"10 min",isPublic:!1,slides:[{type:"title",timer:5,title:"AI Threats & Deepfakes",subtitle:"When the email, the voice, and the face can all be faked",objectives:["Understand how AI supercharges phishing and impersonation","Recognize voice clones and deepfake video",'Rely on verification, not "it sounded like them"']},{type:"concept",timer:20,title:"AI Changed the Game",content:'For years, bad grammar and clumsy wording gave phishing away. AI erased that tell. Attackers now generate flawless, personalized emails in any language in seconds â and they can clone a voice from a few seconds of audio or fake a face on a video call. The old advice "look for typos" is no longer enough.',stats:[{value:"~3 sec",label:"of audio needed to clone a voice"},{value:"$25M",label:"stolen in one deepfake video-call scam"},{value:"1,265%",label:"rise in phishing since AI tools went mainstream"}],callout:{icon:"\uD83E\uDD16",title:"The new mindset",text:"Assume that a convincing email, a familiar voice, or even a live video face can be fabricated. Authenticity now comes from verification, not from how real something looks or sounds."}},{type:"keypoints",timer:25,title:"What AI Attacks Look Like",points:[{icon:"âï¸",label:"Flawless phishing emails",desc:"No typos, perfect tone, and personalized using details scraped from your school website and social media.",color:"#ef4444"},{icon:"\uD83C\uDF99ï¸",label:"Voice cloning (vishing 2.0)",desc:"A call in the principal's exact voice asking you to act urgently â built from a clip of them speaking online.",color:"#f97316"},{icon:"\uD83C\uDFA5",label:"Deepfake video calls",desc:'A live video meeting where the "executive" on screen is an AI-generated face approving a transfer.',color:"#eab308"},{icon:"\uD83C\uDF10",label:"Fake sites & chatbots",desc:'AI spins up convincing look-alike login pages and "support" chatbots that harvest what you type.',color:"#8b5cf6"},{icon:"\uD83E\uDDE9",label:"Hyper-personalized lures",desc:"AI mines public info to reference your real coworkers, projects, and schedule â making the bait fit perfectly.",color:"#3b82f6"}]},{type:"keypoints",timer:20,title:"If You Get an Urgent Call or Video â How to Respond",points:[{icon:"â¸ï¸",label:"Pause â urgency is the weapon",desc:'AI scams push you to act before you think. "Right now," "don\'t tell anyone," and "I can\'t talk long" are red flags, not reasons to hurry.',color:"#ef4444"},{icon:"\uD83D\uDCDE",label:"Hang up and call back",desc:"End the call and dial the person on a number you already have â never one they give you on the call. A real caller won't mind a 60-second verification.",color:"#f97316"},{icon:"\uD83D\uDD11",label:"Use a code word",desc:"Agree on a private word with family and ke
1y staff. Ask for it on any urgent money or data request â a voice clone won't know it.",color:"#eab308"},{icon:"\uD83D\uDEAB",label:"Never move money or data on a call alone",desc:"No wire, gift card, password, or student roster on the strength of a voice or a face. Confirm in person or on a known channel first.",color:"#8b5cf6"},{icon:"\uD83C\uDFA5",label:"A face on video isn't proof either",desc:"Deepfake video calls are real. Ask them to do something live and specific, and still verify separately before acting.",color:"#3b82f6"}]},{type:"scenario",timer:0,title:"The Voice on the Phone",steps:[{text:"You get a call. It sounds exactly like the principal: \"I'm stuck in a board meeting and need you to send the updated staff roster and approve a $2,000 payment to a vendor right now. I can't talk long.\" The voice is unmistakable. What do you do?",choices:[{label:"Do it â that's clearly the principal's voice",next:1},{label:"Stay on the line and ask personal questions",next:2},{label:"Hang up and call the principal back on their known number",next:3}]},{text:"You acted on the voice alone. It was an AI clone built from the principal's posted video. The roster and the $2,000 are gone. A familiar voice is no longer proof of who's calling.",outcome:"bad",lesson:"A voice can be cloned from seconds of audio. Never act on a voice alone for money or sensitive data.",choices:[{label:"Try again",next:0}]},{text:"Good instinct to probe â but a well-prepared attacker may have researched answers, and staying on their line keeps you in their control. The reliable move is to end the call and reach the person yourself.",choices:[{label:"Hang up and call back",next:3},{label:"Just do what they asked",next:1}]},{text:"You hung up and called the principal's known number. They were never on the phone with you. You shut down a deepfake voice scam by verifying on a channel you chose.",outcome:"best",lesson:"Call back on a trusted number. Agree on a simple verbal code word for urgent requests so your team can confirm identity instantly.",choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:'Why is "look for spelling mistakes" weaker advice now?',options:["People spell better","AI writes flawless, personalized phishing in seconds","Filters fix typos","Spelling never mattered"],correct:1,explanation:"AI removes the grammar tells phishing used to have, so polished writing no longer means safe."},{q:"A call in your principal's exact voice asks you to wire money urgently. The safest response?",options:["Comply â the voice proves it's them","Hang up and call back on a known number","Ask them to text instead","Transfer a smaller amount to be safe"],correct:1,explanation:"Voices can be cloned from short clips. Verify by calling back on a trusted number before doing anything."},{q:"What is a strong team defense against AI voice/video impersonation?",options:["A shared, secret verbal code word for urgent requests","Trusting video calls because you can see a face","Only using email","Replying faster"],correct:0,explanation:"A pre-agreed code word lets you instantly confirm identity even when the voice or face looks real."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["AI makes phishing flawless and personal â typos are no longer the tell","Voices and even live video faces can be convincingly faked","Never act on a voice or video alone for money or sensitive data","Verify on a channel you choose; agree on a code word for urgent asks"]}]},"student-data-privacy":{title:"Protecting Student Data (FERPA & Privacy)",icon:"\uD83D\uDEE1ï¸",duration:"10 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Protecting Student Data",subtitle:"Privacy, FERPA, and your role as a guardian of student information",objectives:["Understand what counts as protected student data","Apply FERPA basics in everyday tasks","Avoid the everyday mistakes that expose student records"]},{type:"concept",timer:20,title:"Why Student Data Matters",content:"Schools hold some of the most sensitive data there is: grades, health notes, addresses, family situations, behavioral records. FERPA (the Family Educational Rights and Privacy Act) is the federal law protecting student education records. Beyond the law, protecting this data is a matter of trust â families trust the school to keep their children's information safe.",stats:[{value:"FERPA",label:"the federal law governing student records"},{value:"#1",label:"cause of breaches: ordinary human mistakes"},{value:"K-12",label:"among the most-targeted sectors for data theft"}],callout:{icon:"\uD83D\uDEE1ï¸",title:"You are a steward",text:"If your role gives you access to student information, you're a steward of it. Share it only with people who have a legitimate educational need, and only through approved, secure channels."}},{type:"keypoints",timer:25,title:"Everyday Rules That Protect Students",points:[{icon:"\uD83C\uDFAF",label:"Share on a need-to-know basis",desc:"Only people with a legitimate educational reason should see a student's records â not the whole staff list, not a friend who teaches elsewhere.",color:"#22c55e"},{icon:"âï¸",label:"Check the recipient twice",desc:"Misdirected email is a top cause of leaks. Confirm the address before sending anything with student names, grades, or IEPs.",color:"#ef4444"},{icon:"\uD83D\uDD10",label:"Use approved, secure tools",desc:"Keep records in school-sanctioned
1systems. Don't move rosters to personal email, personal drives, or random apps.",color:"#3b82f6"},{icon:"\uD83D\uDDA5ï¸",label:"Lock your screen",desc:"Step away and lock it. Hallways, shared offices, and projected screens expose data to anyone passing by.",color:"#f97316"},{icon:"\uD83D\uDDD1ï¸",label:"Minimize and dispose carefully",desc:"Don't collect or keep more than you need. Shred printed records; don't toss them in the recycling.",color:"#8b5cf6"}]},{type:"email_exercise",timer:0,title:"Is This Safe to Send?",instruction:"A parent emails asking for information. Decide how to handle it.",email:{from:{name:"Jordan Avery",address:"[email protected]"},to:"[email protected]",time:"Today, 12:20 PM",subject:"Quick question about the class",body:"Hi! My daughter mentioned her friend Mia has been struggling. As a class parent I'd love to help â could you send me the contact list and grades for the kids in the class so I can organize a study group? Thanks so much!\n\nJordan",isPhishing:!1,redFlags:[],legitimateReasons:"This is not malware â but it is a privacy trap. A parent has no right to other students' grades or contact information, even with good intentions. The right response is a polite no: you can't share other students' records, but you can pass along study-group info through approved channels. Sharing the list would be a FERPA violation."}},{type:"scenario",timer:0,title:"The Roster Request",steps:[{text:'A colleague at another school texts: "We\'re doing a similar project â can you email me your full student roster with addresses and IEP flags as a head start?" What do you do?',choices:[{label:"Send it â they're a fellow educator",next:1},{label:"Email just the names, that's harmless",next:2},{label:"Decline and point them to their own school's data",next:3}]},{text:"You sent it. A teacher at another school has no legitimate educational interest in your students' records â this is a FERPA violation, and the addresses and IEP flags are now outside the school's control.",outcome:"bad",lesson:"Being an educator elsewhere does not grant access to YOUR students' records. Need-to-know is per student, not per profession.",choices:[{label:"Try again",next:0}]},{text:'Even "just names" can be protected when tied to your class (it reveals enrollment), and it normalizes sharing rosters off-channel. The safe answer is not to send student data to another school at all.',choices:[{label:"Decline instead",next:3},{label:"Send the whole roster",next:1}]},{text:"You declined and suggested they use their own school's data and systems. You protected your students' records and kept the school FERPA-compliant â without being unhelpful about the project itself.",outcome:"best",lesson:"Share student data only with those who have a legitimate educational need at your school, through approved systems. When unsure, ask your administrator.",choices:[{label:"Continue",next:-1}]}]},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"A class parent asks for other students' grades to organize a study group. What should you do?",options:["Send them â it's for a good cause","Politely decline; they have no right to others' records","Send just the grades, not names","Ask the students first"],correct:1,explanation:"Other students' records are protected under FERPA. Good intentions don't create a right to access them."},{q:"What is the most common cause of student-data leaks?",options:["Sophisticated hackers","Ordinary mistakes like misdirected email","Power outages","Old computers"],correct:1,explanation:"Everyday human error â wrong recipient, oversharing, unlocked screens â causes most leaks. Slowing down prevents them."},{q:"Where should student records live?",options:["Wherever is convenient, like personal email","In approved, secure school systems only","On a shared USB drive","In a public folder for easy access"],correct:1,explanation:"Keep records in school-sanctioned, secure systems â never personal email, drives, or unapproved apps."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["FERPA protects student education records â and so should you","Share student data only on a legitimate need-to-know basis","Double-check recipients; misdirected email is a top cause of leaks","Use approved secure systems, lock your screen, and keep only what you need"]}]},"beyond-the-inbox":{title:"Scams Beyond the Inbox",icon:"\uD83D\uDCE8",duration:"10 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Scams Beyond the Inbox",subtitle:"Calendar invites, shared files, and e-sign requests can be phishing too",objectives:["Recognize attacks that arrive as calendar invites, file shares, and e-signature requests",'Understand why these slip past your "is this email suspicious?" instinct',"Apply one simple rule to every notification, not just emails"]},{type:"concept",timer:15,title:"Phishing Left the Inbox",content:'You have learned to scrutinize emails. So attackers moved to the notifications you trust without thinking: a calendar invite that auto-adds itself, a "document shared with you" alert, a DocuSign request to sign. These arrive from real platforms (Google, Microsoft, DocuSign), often land outside your spam filter, and carry the same goal â a malicious link or a rushed action. The trust you place in the platform is exactly what the attacker is borrowing.',stats:[{value:"Real",label:"sender platforms (Google, DocuSignâ¦)"},{value:"Past",label:"most email spam filters"},{value:"Same",label:"goal: bad link or rushed action"}],callout:{icon:"\uD83C\uDFAD",title:"It is not the email â it is the notification",text:"A calendar, file-share, or signature notification feels like plumbing, not mail. That is precisely why it works. Treat the link inside it exactly like a link in a suspicious email."}}
1,{type:"keypoints",timer:20,title:"The Vectors to Watch",points:[{icon:"\uD83D\uDCC5",label:"Calendar-invite spam",desc:'An unexpected meeting invite auto-adds to your calendar with a link to "join," "reschedule," or "review the agenda." The link goes to a fake login. Decline and delete; never click links inside an invite you were not expecting.',color:"#ef4444"},{icon:"\uD83D\uDCC2",label:"File-share & document invites",desc:'"Someone shared a document with you" from Google Drive, OneDrive, or Dropbox â but you do not know them, or the file is a "Click to view" image leading offsite. Verify the person and go to the platform directly, not via the email button.',color:"#f97316"},{icon:"âï¸",label:"E-signature (DocuSign) spam",desc:'A "You have a document to sign" request creating urgency about an invoice, contract, or HR form. Real e-sign emails never need you to log in through their link â open the platform yourself, or confirm with the supposed sender first.',color:"#eab308"},{icon:"\uD83D\uDD14",label:'Fake "notification" emails',desc:"Voicemail, fax, scanned-document, and shared-photo alerts that mimic a service to get one click. If you were not expecting it, do not click the preview or download.",color:"#3b82f6"},{icon:"\uD83D\uDCAC",label:"Collaboration-tool invites",desc:'Teams, Slack, Zoom, or "guest workspace" invites from outside your organization. External invites can carry malicious links or impersonate coworkers â confirm through a channel you already trust.',color:"#22c55e"}]},{type:"concept",timer:15,title:"The One Rule for Every Notification",content:"Whatever the wrapper â calendar, file share, e-sign, voicemail, chat invite â the safe move is identical: do not act through the notification. If a calendar invite, shared file, or signature request matters, open the real app yourself (calendar.google.com, your DocuSign account, the actual Drive) and check there. Unexpected + a link or a login = stop and verify through a channel you control. And when something feels off, Report Suspicious â these belong in your reports just like phishing emails do.",stats:[{value:"Open",label:"the real app yourself"},{value:"Never",label:"log in via the notification link"},{value:"Report",label:"anything unexpected"}],callout:{icon:"\uD83D\uDEE1ï¸",title:"Same instinct, new wrappers",text:"You already know not to click a suspicious email link. Extend that exact instinct to every invite, share, and signature request. The wrapper changed; the rule did not."}},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:'A calendar invite you did not expect auto-adds itself, with a link to "review the agenda." What do you do?',options:["Click the link to see what the meeting is","Decline/delete it and do not click the link","Accept it to be polite","Forward it to your team"],correct:1,explanation:"Unexpected calendar invites with links are a known phishing vector. Decline, delete, and never click the embedded link."},{q:'You get a "DocuSign â document ready to sign" email creating urgency about an invoice. Safest action?',options:['Click "Review Document" and sign in',"Open your DocuSign account directly, or confirm with the sender first","Reply with your password","Ignore all DocuSign forever"],correct:1,explanation:"Never log in through the notification link. Go to the real platform yourself or verify with the supposed sender through a known channel."},{q:"Why do calendar, file-share, and e-sign scams slip past people who are careful with email?",options:["They are encrypted",'They arrive as trusted notifications from real platforms, not as obvious "emails"',"They are always in the spam folder","They never contain links"],correct:1,explanation:'They borrow the trust you place in Google, DocuSign, and similar platforms â the notification feels like plumbing, so the usual "is this email suspicious?" guard never kicks in.'},{q:"What is the one rule that covers calendar invites, shared files, e-sign requests, and chat invites alike?",options:["Only open them on your phone","Do not act through the notification â open the real app yourself and verify","Always accept invites from your domain","Delete every notification automatically"],correct:1,explanation:"Whatever the wrapper, do not act through the notification link. Open the real app yourself and verify; report anything unexpected."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["Phishing arrives as calendar invites, file shares, e-sign requests, and chat invites â not just emails","These borrow the trust you give real platforms (Google, DocuSign) and often dodge spam filters","Never log in or act through the notification link â open the real app yourself and verify","Report unexpected invites and share/sign requests just like you report suspicious emails"]}]},"trusted-reporter":{title:"Trusted Reporter",icon:"\uD83D\uDCE2",duration:"8 min",isPublic:!1,slides:[{type:"title",timer:5,title:"Trusted Reporter",subtitle:"Master the reporting buttons â and become a trusted voice that helps protect your whole org",objectives:["Know exactly which reporting button to use, and when","Understand how a Community Alert gets raised â by the consensus of trusted reporters like you","Know who can raise an instant alert (your admins, and the Org Reporters they choose)"]},{type:"concept",timer:15,title:"Your Reporting Toolbar",content:'When ThouShaltNotClick checks an email, it shows a small badge with quick-action buttons. For everyday users there are just tw
1o reporting actions â and they do very different things, so it pays to know when to use each. (The \uD83E\uDD16 button only opens a deeper AI analysis â it is not a report. The \uD83D\uDCE2 instant Community Alert button appears only for your organization\'s admins, plus any trusted staff they have specifically chosen as "Org Reporters" â more on that shortly.)',stats:[{value:"\uD83E\uDDD0",label:"Report Suspicious"},{value:"â",label:"Mark Safe"},{value:"\uD83E\uDD16",label:"AI Analysis"}],image:"/training/tsnc-badge.png",imageAlt:"The ThouShaltNotClick trust badge shown on an email in the inbox, with Report Suspicious, Mark Safe, and AI Analysis buttons",imageCaption:"How the badge looks on a message in your inbox â the \uD83E\uDDD0 Report Suspicious, â Mark Safe, and \uD83E\uDD16 AI Analysis buttons sit right on the email."},{type:"keypoints",timer:20,title:"Which Button, When",points:[{icon:"\uD83E\uDDD0",label:"Report Suspicious â your everyday tool",desc:"Anything that feels off â a strange link, an unexpected attachment, a too-good-to-be-true offer, an impersonation. It privately flags the sender for review. There is no harm in over-reporting; when in doubt, report.",color:"#c0392b"},{icon:"â",label:"Mark Safe â for senders you trust",desc:"For senders you know are real (your principal, a real vendor, a parent). It reduces false alarms for everyone and builds the sender's trusted reputation.",color:"#228a4a"},{icon:"\uD83D\uDCE2",label:"Community Alert â raised automatically",desc:'There is no "warn everyone" button for most users. Instead, when enough Trusted Reporters flag the SAME sender (your school sets the number â usually two), TSNC automatically alerts your whole org. Your Org/IT admins â and any trusted staff they have chosen as "Org Reporters" â can also trigger one instantly. So the most powerful thing you can do is report accurately.',color:"#000000"}]},{type:"reporting_demo",timer:0,title:"Try It: Which Action Fits?",instruction:'This is exactly what you see in your inbox. Click the trust badge to expand it, then click each of the three actions to learn what they do. Switch between the three real-world emails to see which action fits each one. (Notice there is no manual "alert everyone" button â that happens automatically.)',order:["report","safe","ai"],examples:[{label:"\uD83C\uDF81 Gift-card scam",from:{name:"Principal Dawson",address:"[email protected]"},time:"8:42 AM",subject:"Quick favor â need you to handle this discreetly",body:"Hi,\n\nAre you at your desk? I'm in back-to-back meetings and can't talk. I need you to pick up 5 Apple gift cards ($100 each) for a staff appreciation surprise. Keep this between us for now.\n\nText me the codes as soon as you have them. I'll reimburse you this afternoon.\n\nThanks,\nPrincipal Dawson",trustScore:8,band:"danger",rating:"Dangerous",findings:['Sender domain "gmaii-secure.net" impersonates your principal â not your real district domain',"Classic gift-card + secrecy + urgency scam pattern","Reply-to address does not match the display name"],recommended:"report"},{label:"\uD83E\uDDFE Unsure invoice",from:{name:"Brightline Supplies",address:"[email protected]"},time:"Yesterday, 3:17 PM",subject:"Invoice #INV-20418 â payment past due",body:"Hello,\n\nOur records show invoice #INV-20418 for classroom supplies ($1,240.00) is now 14 days past due. Please remit payment using the updated banking details in the attached PDF to avoid a late fee.\n\nIf you believe this is an error, reply to this email.\n\nRegards,\nAccounts Receivable\nBrightline Supplies",trustScore:47,band:"caution",rating:"Use Caution",findings:["Vendor name is plausible but you don't recognize this specific invoice",'"Updated banking details" in an attachment is a common redirect-payment tactic',"A malicious attachment or link makes this report-worthy â when in doubt, report it"],recommended:"report"},{label:"â
Legit colleague",from:{name:"Maria Santos (Front Office)",address:"[email protected]"},time:"9:05 AM",subject:"Field trip permission slips â due Friday",body:"Hi team,\n\nJust a reminder that signed permission slips for next week's museum field trip are due to the front office by Friday at 3 PM. I've attached the master list so you can check off your students.\n\nLet me know if you need extra copies!\n\nThanks,\nMaria",trustScore:94,band:"safe",rating:"Looks Safe",findings:["Sender is on your real district domain (yourdistrict.org)","Normal internal request with no urgency, secrecy, or payment ask","You recognize this person and the context"],recommended:"safe"}],actions:{report:{icon:"\uD83E\uDDD0",name:"Report Suspicious",desc:"Privately flags this sender for review. It does NOT immediately warn coworkers â but it counts: once enough Trusted Reporters flag the same sender (your school sets the number, usually two), TSNC automatically alerts your whole org. Use it whenever something feels off; there is no harm in over-reporting."},safe:{icon:"â",name:"Mark Safe",desc:"Tells TSNC this sender is legitimate. It reduces false alarms for everyone and builds the sender's trusted reputation across your org. Use it only for senders you actually recognize."},ai:{icon:"\uD83E\uDD16",name:"AI Analysis",desc:"Opens a deeper, plain-English breakdown of why this email got its score â the links, the sender history, and the red flags. This is just information; it does not report or change anything."}}},{type:"concept",timer:20,title:"How a Community Alert Gets Raised",content:'As a Trusted Reporter you do NOT get a button to warn everyone by yourself â alerts are raised by agreement, not by one person. Here is how it works: (1) You and other Trusted Reporters Report Suspicious senders you encounter. (2) Once enough Trusted Reporters flag the SAME sender â your school sets the number, and it starts at two â TSNC automatically raises a Community Alert: the sender is flagged dangerous org-wide, their trust score drops on every screen, and your admins are notified. (3) Two groups CA
1N alert instantly, in one click: your Org/IT admins, and a few trusted staff each school may hand-pick as "Org Reporters." This consensus model means no single ordinary reporter can warn the whole org alone â and accurate reporters are what make it work.',stats:[{value:"2+",label:"trusted reporters (set by your school)"},{value:"1 click",label:"admins & Org Reporters"},{value:"100%",label:"logged for review"}],callout:{icon:"\uD83D\uDD12",title:"Your status, your responsibility",text:'Finishing this course makes you a Trusted Reporter â your reports count toward the consensus that raises an alert. It does not give you a solo "alert everyone" button (that is only for admins and the Org Reporters they choose). Report honestly; every report is logged and reviewed, and misuse can cost your status.'}},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"An email looks a little off, but you are not sure it is phishing. Which button?",options:["\uD83E\uDDD0 Report Suspicious","â Mark Safe","Do nothing","Forward it to a coworker"],correct:0,explanation:"When unsure, Report Suspicious â it is private and reviewed. There is no harm in over-reporting."},{q:"How does a sender become a Community Alert for your whole organization?",options:["Any one user clicks an alert button","When enough Trusted Reporters (your school sets the number â usually two) flag the same sender â or an admin/Org Reporter triggers one instantly","TSNC deletes the email automatically","It never happens automatically"],correct:1,explanation:"A Community Alert is raised by consensus â your school sets how many Trusted Reporters are needed (it starts at two). Admins and designated Org Reporters can also trigger one instantly."},{q:"As a Trusted Reporter, can you send an instant Community Alert all by yourself?",options:["Yes â finishing this training gives me that button","No â my reports count toward consensus; only admins and admin-chosen Org Reporters alert instantly","Yes, up to 5 times a day","Only on weekends"],correct:1,explanation:"Being a Trusted Reporter means your reports carry weight toward the consensus â it does NOT give you a solo alert button. Instant alerts are reserved for admins and the Org Reporters they designate."},{q:"A scammer impersonating your principal emails several staff asking for gift cards. As a Trusted Reporter, what do you do?",options:["Nothing â wait for an admin","Report Suspicious â and once enough Trusted Reporters do too, it auto-alerts the org","Mark Safe","Reply to ask questions"],correct:1,explanation:"Report it. Dangerous senders usually get caught by more than one reporter â and once your school's threshold of Trusted Reporters flag the same sender, everyone is warned automatically."},{q:"What does being a Trusted Reporter mean?",options:["You can warn the whole org with one click","Your reports count toward the auto-alert consensus, and every report is logged and reviewed","You can mark any sender safe permanently","Nothing changes"],correct:1,explanation:"Trusted Reporters' reports carry extra weight â enough agreeing reporters auto-alert the org. Reports are logged; misuse can cost your status."}]},{type:"complete",timer:5,title:"You are now a Trusted Reporter!",takeaways:["Report Suspicious = your everyday tool for anything that feels off","Mark Safe = tell us a sender is legitimate","Enough Trusted Reporters flagging the same sender (your school sets the number â usually two) auto-alerts your whole org","You do NOT get a solo alert button â admins and the Org Reporters they choose are the only ones who alert instantly"]}]},"permission-to-push-back":{title:"Permission to Push Back",icon:"â",duration:"10 min",isPublic:!0,curriculum:!0,series:"anatomy-of-a-scam",seriesOrder:1,seriesLever:"Authority",slides:[{type:"title",timer:5,title:"Permission to Push Back",subtitle:"Why the request landed on you, and what to do about it",objectives:["Read why a request was aimed at you specifically","Name the three things that should stop you, even when each looks normal","Know what to do when you can't verify and the deadline is real"]},{type:"concept",timer:20,title:"1:47 on a Thursday",content:"It's 1:47 on a Thursday. You are due back with your class in eight minutes and a parent is
1waiting in the hall. An email from your principal: the district office needs the eighth-grade roster today â names, grades, parent emails. Send it straight over, and don't route it through the office, the list isn't final yet.\n\nNothing in that message is a payment. Nothing is attached. There's no link to click. It was written for the tired version of you, mid-hallway, who doesn't want to be the reason the district office is kept waiting.",callout:{icon:"\uD83E\uDDED",title:"A different question",text:"Most training teaches you what to spot. This one asks something else â why did this land on you? That question still works on an attack nobody has catalogued yet."},variantKey:"opening"},{type:"concept",timer:20,title:"Why It Landed on You",content:"Attackers read your school's website like a staff directory. Your name, your role, the newsletter mentioning you coordinate the student council, the photo caption naming your principal. Ten minutes of reading tells someone who to impersonate, who to send it to, and which deadline will sound real.\n\nLeaders get impersonated. Staff get asked. And a request that appears to come from your principal arrives with a cost attached to questioning it â asking \"is this really you?\" can feel like insubordination.\n\nThat's a permission problem, not a knowledge problem.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Filters help. They don't finish.",text:"A filter can catch a lookalike domain or flag an outside sender. It can't tell whether you should have been asked for this list in the first place. That judgement is yours."},variantKey:"whyYou"},{type:"keypoints",timer:25,title:"Interrogate the Ask, Not the Sender",points:[{icon:"\uD83C\uDFAF",label:"Why me?",desc:"Does this request belong to my job? If it doesn't, that's the strongest signal there is.",color:"#ef4444"},{icon:"â±",label:"Why now?",desc:"Who set this deadline? Urgency you didn't choose is someone else's tool.",color:"#f97316"},{icon:"\uD83E\uDD10",label:"Why quietly?",desc:"Confidentiality is normal at a school. Confidential plus urgent plus valuable is not.",color:"#eab308"},{icon:"\uD83D\uDD00",label:"Why here?",desc:"Would this person normally email me about this? Real requests arrive where they always have.",color:"#22c55e"},{icon:"\uD83D\uDEAA",label:"What does yes hand over?",desc:"Money, a password, a door code, or a list of children and their parents. Some of those can't be taken back.",color:"#3b82f6"}]},{type:"scenario",timer:0,title:"The List Is Due Today",steps:[{text:"Back to 1:47. The roster is due to the district office today, and your principal asked for it directly. What's your first move?",choices:[{label:"Send it â she asked for it",next:1},{label:"Reply to the email to confirm",next:2},{label:"Call her on the number you already have",next:3},{label:"Walk to the office and ask",next:4}]},{text:"Sent. The reply-to address was a lookalike domain. Those families' names and contact details are now somewhere you can't reach, and there is no recalling a roster.",outcome:"bad",lesson:"A real deadline never makes an unverified send safe. The list was the whole target.",choices:[{label:"Try again",next:0}]},{text:'The answer comes back in seconds: "In a meeting â just send it." Which proves nothing. A reply only ever reaches whoever sent the email.',choices:[{label:"Send it",next:1},{label:"Call her on the number you already have",next:3}]},{text:"Voicemail. She's off-site until tomorrow. The deadline is still today, and now you're stuck.",choices:[{label:"Send it and sort it out tomorrow",next:1},{label:"Ask someone else who would know",next:4}]},{text:"The office has no such request on file, and no roster was ever asked for. Nobody sent it.\n\nAnd if it had been genuine? The list would have gone out an hour later than it might have. That is the entire cost of checking.",outcome:"best",lesson:"Can't reach the person who asked? Ask someone else who would know. A late list is recoverable. A sent one is not.",choices:[{label:"Continue",next:-1}]}],variantKey:"scenario"},{type:"concept",timer:20,title:"You're Allowed to Ask",content:"Here's what security training usually leaves out: checking has a social cost. You might look
1slow. You might look like you don't trust your principal. That cost is real, and pretending otherwise would be insulting.\n\nIt is also small, and survivable. A principal mildly irritated on a Thursday is a Thursday problem. A roster of children that has already left the building is not.\n\nSo have the sentence ready before you need it.",callout:{icon:"\uD83D\uDCAC",title:"When you can't reach them",text:'Ask a second person who would know â the office, the business manager, whoever owns the process. And send this back: "Happy to get this over. I just need to confirm by voice or with the office first â if it\'s urgent, who else can approve it?" That buys time without refusing anyone.'}},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"A message asks for something outside your job, today, and asks you not to involve the office. Which part matters most?",options:["The spelling and grammar","That all three arrived together, even though each one alone is ordinary","The time of day it was sent","Whether there is an attachment"],correct:1,explanation:"Each of those is normal at a school on its own. Outside your role, urgent, and quiet â arriving together â is the combination worth stopping for."},{q:"You reply to the email to check it's really them, and they reply \"yes, it's me.\" What have you confirmed?",options:["That the request is genuine","Nothing â a reply only reaches whoever sent it","That they are at their desk","That the address is valid"],correct:1,explanation:"Replying stays inside the channel the sender controls. Confirm somewhere they didn't choose â a known number, or in person."},{q:"You can't reach the person it came from and the deadline is genuinely today. Best move?",options:["Send it and sort it out tomorrow","Refuse until they are back","Confirm another way you choose â someone else who would know, or the organisation's own number looked up yourself â and tell the requester you are checking","Forward it around to ask whether it looks right"],correct:2,explanation:"Confirming through a channel you picked answers the question without refusing anyone â and it works whether you have a whole office around you or nobody at all. Deferring politely costs an hour; sending costs everything on the list."}]},{type:"complete",timer:5,title:"Lesson Complete!",takeaways:["Ask why a request landed on you â that question works on attacks nobody has catalogued yet","Confidential, urgent, and valuable arriving together is the pattern that should stop you","A reply only reaches whoever sent the email â confirm on a channel you chose","Can't reach them? Ask someone else who would know, and use Report Suspicious if it still feels wrong"]}],variants:{"just-me":{opening:{title:"7:40 on a Tuesday",content:"It's 7:40 on a Tuesday evening. The shopping is still on the counter and the day is finally done. An email from your bank's fraud team: someone tried to sign in to your account from a new device, and unless you confirm your details tonight the account will be locked. It's the account everything comes out of. Reply with your date of birth, your account number and the answers to your security questions â and don't use the app, it won't show the alert until the review clears.\n\nNothing in that message is a payment. Nothing is attached. There's no link to click. It was written for the tired ver
1sion of you, at the end of a long day, who doesn't want to wake up locked out of their own money."},scenario:{title:"The Account Locks Tonight",steps:[{text:"Back to 7:40. The account locks overnight unless you confirm, and the message came from the bank. What's your first move?",choices:[{label:"Reply with the details",next:1},{label:"Reply and ask if it's genuine",next:2},{label:"Call the number on your card",next:3},{label:"Open the bank's own app and look",next:4}]},{text:"Sent. The reply-to address was a lookalike domain. Your date of birth and security answers are now somewhere you can't reach, and unlike a password, you can't change your birthday.",outcome:"bad",lesson:"A real deadline never makes an unverified reply safe.",choices:[{label:"Try again",next:0}]},{text:'The answer comes back in seconds: "Yes, this is us â please finish verifying." Which proves nothing. A reply only ever reaches whoever sent the email.',choices:[{label:"Reply with the details",next:1},{label:"Call the number on your card",next:3}]},{text:"Hold music. The queue is long and the account is due to lock tonight. Now you're stuck.",choices:[{label:"Reply now, sort it out tomorrow",next:1},{label:"Open the bank's own app and look",next:4}]},{text:"The app opens the way it always does. No alert, no new device, no lock. The bank never sent it.\n\nAnd if the warning had been real? The app would have shown it too â and you'd have known in the time it took to unlock your phone. That is the entire cost of checking.",outcome:"best",lesson:"No one else to ask? Go back to them through a door they didn't hand you. A locked account is recoverable. A stranger inside one is not.",choices:[{label:"Continue",next:-1}]}]},whyYou:{content:"No employer publishes a page about you, so they read what is already public. An old email address in a breach dump, a profile naming your town, a public reply to your bank's support account. None of that takes an investigation. It tells someone which institution to impersonate, which inbox to send it to, and which threat will sound real.\n\nInstitutions get impersonated. You get asked. And a warning that appears to come from your bank arrives with a cost attached to questioning it â asking 'is this really you?' can feel like being difficult with the institution holding your money.\n\nThat's a permission problem, not a knowledge problem.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Filters help. They don't finish.",text:"A filter can catch a lookalike domain or mark a message as suspicious. It can't tell whether you should have been asked for your security answers in the first place. That judgement is yours."}}},"school-teacher":{opening:{title:"1:47 on a Thursday",content:"It's 1:47 on a Thursday. You are due back with your class in eight minutes and a parent is waiting in the hall. An email from your principal: the district office needs the eighth-grade roster today â names, grades, parent emails. Send it straight over, and don't route it through the office, the list isn't final yet.\n\nNothing in that message is a payment. Nothing is attached. There's no link to click. It was written for the tired ver
1sion of you, mid-hallway, who doesn't want to be the reason the district office is kept waiting."},scenario:{title:"The List Is Due Today",steps:[{text:"Back to 1:47. The roster is due to the district office today, and your principal asked for it directly. What's your first move?",choices:[{label:"Send it â she asked for it",next:1},{label:"Reply to the email to confirm",next:2},{label:"Call her on the number you already have",next:3},{label:"Walk to the office and ask",next:4}]},{text:"Sent. The reply-to address was a lookalike domain. Those families' names and contact details are now somewhere you can't reach, and there is no recalling a roster.",outcome:"bad",lesson:"A real deadline never makes an unverified send safe. The list was the whole target.",choices:[{label:"Try again",next:0}]},{text:'The answer comes back in seconds: "In a meeting â just send it." Which proves nothing. A reply only ever reaches whoever sent the email.',choices:[{label:"Send it",next:1},{label:"Call her on the number you already have",next:3}]},{text:"Voicemail. She's off-site until tomorrow. The deadline is still today, and now you're stuck.",choices:[{label:"Send it and sort it out tomorrow",next:1},{label:"Ask someone else who would know",next:4}]},{text:"The office has no such request on file, and no roster was ever asked for. Nobody sent it.\n\nAnd if it had been genuine? The list would have gone out an hour later than it might have. That is the entire cost of checking.",outcome:"best",lesson:"Can't reach the person who asked? Ask someone else who would know. A late list is recoverable. A sent one is not.",choices:[{label:"Continue",next:-1}]}]},whyYou:{content:"Attackers read your school's website like a staff directory. Your name, your role, the newsletter mentioning you coordinate the student council, the photo caption naming your principal. Ten minutes of reading tells someone who to impersonate, who to send it to, and which deadline will sound real.\n\nLeaders get impersonated. Staff get asked. And a request that appears to come from your principal arrives with a cost attached to questioning it â asking 'is this really you?' can feel like insubordination.\n\nThat's a permission problem, not a knowledge problem.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Filters help. They don't finish.",text:"A filter can catch a lookalike domain or flag an outside sender. It can't tell whether you should have been asked for this list in the first place. That judgement is yours."}}},"school-office":{opening:{title:"10:20 on a Tuesday",content:"It's 10:20 on a Tuesday. There's a parent at the counter, two lines holding, and a student waiting on a late slip. An email from your principal: the new family directory has to go to the printer today â every family's name, home address, phone and email, the version you keep. Send it straight across, and don't run it past the registrar, some of it isn't confirmed yet.\n\nNothing in that message is a payment. Nothing is attached. There's no link to click. It was written for the busy version of you, mid-counter, who assembles lists like this often enough that this one asks for nothing unusual."},scenario:{title:"The Printer Needs It Today",steps:[{text:"Back to 10:20. The directory is due at the printer today, and your principal asked for it directly. What's your first move?",choices:[{label:"Attach it and send",next:1},{label:"Reply to the email to confirm",next:2},{label:"Call her mobile â you have the number",next:3},{label:"Ask the registrar",next:4}]},{text:"Sent. The reply-to address was a lookalike domain. Every family in the school â home addresses, phone numbers â is now somewhere you can't reach, and there is no recalling a directory.",outcome:"bad",lesson:"A real deadline never makes an unverified send safe.",choices:[{label:"Try again",next:0}]},{text:'The answer comes back in seconds: "In a meeting â just send it." Which proves nothing. A reply only ever reaches whoever sent the email.',choices:[{label:"Attach it and send",next:1},{label:"Call her mobile â you have the number",next:3}]},{text:"Voicemail. You already knew she was at the district office all day â you put it in the calendar. The printer deadline is still today, and now you're stuck.",choices:[{label:"Send it and sort it out tomorrow",next:1},{label:"Ask someone else who would know",next:4}]}
1,{text:"The registrar has no printer deadline, and nobody has ordered a directory this year. Nobody sent it.\n\nAnd if it had been genuine? The file would have gone out twenty minutes later. That is the entire cost of checking.",outcome:"best",lesson:"Can't reach the person who asked? Ask someone else who would know. A late file is recoverable. A sent one is not.",choices:[{label:"Continue",next:-1}]}]},whyYou:{content:"Attackers don't have to dig for you. The contact page puts the office first, with your name and a number that reaches you, and it tells families to call the office about anything to do with their records. The same site names your principal. Ten minutes of reading tells someone who to impersonate, who to send it to, and which list you're the one who holds.\n\nLeaders get impersonated. The office gets asked. And a request that appears to come from your principal arrives with a cost attached to questioning it â the whole job is being the person who gets things moving, and asking 'is this really you?' can feel like getting in the way.\n\nThat's a permission problem, not a knowledge problem.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Filters help. They don't finish.",text:"A filter can catch a lookalike domain or flag an outside sender. It can't tell whether you should have been asked for this directory in the first place. That judgement is yours."}}},parish:{opening:{title:"4:15 on a Tuesday",content:"It's 4:15 on a Tuesday. The office closes soon, the phone has been ringing since lunch, and someone is still waiting at the counter. An email from your pastor: he needs the parish contact list today â every registered family, with addresses and phone numbers. Send it straight over, and keep it between the two of you for now.\n\nNothing in that message is a payment. Nothing is attached. There's no link to click. It was written for the tired ver
1sion of you, at the end of a long afternoon, who doesn't want to be the reason the pastor has to ask twice."},scenario:{title:"Before the Office Closes",steps:[{text:"Back to 4:15. The pastor needs the parish contact list today, and he asked for it directly. What's your first move?",choices:[{label:"Send it â he asked for it",next:1},{label:"Reply to the email to confirm",next:2},{label:"Call him on the number you already have",next:3},{label:"Walk over and ask him in person",next:4}]},{text:"Sent. The reply-to address was a lookalike domain. Every family in the parish â addresses, phone numbers â is now somewhere you can't reach, and there is no recalling a list.",outcome:"bad",lesson:"A real deadline never makes an unverified send safe.",choices:[{label:"Try again",next:0}]},{text:'The answer comes back in seconds: "Yes, it\'s me â please send it." Which proves nothing. A reply only ever reaches whoever sent the email.',choices:[{label:"Send it",next:1},{label:"Call him on the number you already have",next:3}]},{text:"It rings out. He's out on visits and the office closes in forty minutes. Now you're stuck.",choices:[{label:"Send it and mention it tomorrow",next:1},{label:"Hold it until you can reach him",next:4}]},{text:"You leave it in the drafts folder and catch him in the morning. He never sent it, and he's glad you waited.\n\nAnd if it had been genuine? He'd have had the list before nine. That is the entire cost of checking.",outcome:"best",lesson:"Nobody else to ask? Then it waits until you can reach them another way. A list sent late is recoverable. A list sent to a stranger is not.",choices:[{label:"Continue",next:-1}]}]},whyYou:{content:"Attackers read your parish bulletin the way you'd read a staff directory. Your name, your role, the office hours, the pastor's name on the front. Bulletins go online and they stay there, so it isn't one week's worth â it's months. Ten minutes of reading tells someone who to impersonate, who to send it to, and which deadline will sound real.\n\nPastors get impersonated. Parish staff get asked. And a request that appears to come from your pastor arrives with a cost attached to questioning it â asking 'is this really you?' can feel like doubting him. Often there's no one else in the office to check with.\n\nThat's a permission problem, not a knowledge problem.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Filters help. They don't finish.",text:"A filter can catch a lookalike domain or flag an outside sender. It can't tell whether you should have been asked for the parish contact list in the first place. That judgement is yours."}}},nonprofit:{opening:{title:"4:40 on a Tuesday",content:"It's 4:40 on a Tuesday. A volunteer has been waiting twenty minutes on an answer only you can give, and tomorrow's mailing still isn't finished. An email from your executive director: the board needs the donor list today â names, giving history, contact details. Send it straight over, and don't copy anyone else, the numbers aren't final yet.\n\nNothing in that message is a payment. Nothing is attached. There's no link to click. It was written for the tired ver
1sion of you, at the end of a long day doing three people's jobs, who doesn't want to be the reason the board is kept waiting."},scenario:{title:"The Board Wants It Today",steps:[{text:"Back to 4:40. The donor list is due to the board today, and your executive director asked for it directly. What's your first move?",choices:[{label:"Send it â she asked for it",next:1},{label:"Reply to the email to confirm",next:2},{label:"Call her on the number you already have",next:3},{label:"Ask the colleague who runs the mailings",next:4}]},{text:"Sent. The reply-to address was a lookalike domain. Every donor's name, giving history and contact details are now somewhere you can't reach, and there is no recalling a donor list.",outcome:"bad",lesson:"A real deadline never makes an unverified send safe.",choices:[{label:"Try again",next:0}]},{text:'The answer comes back in seconds: "On a call â just send it." Which proves nothing. A reply only ever reaches whoever sent the email.',choices:[{label:"Send it",next:1},{label:"Call her on the number you already have",next:3}]},{text:"Voicemail. She's with a funder until tomorrow. The board meets tonight, and now you're stuck.",choices:[{label:"Send it and flag it tomorrow",next:1},{label:"Ask someone else who would know",next:4}]},{text:"There's no board meeting tonight, and nobody has asked for donor records. Nobody sent it.\n\nAnd if it had been genuine? The list would have gone over twenty minutes later. That is the entire cost of checking.",outcome:"best",lesson:"Can't reach the person who asked? Ask someone else who would know. A late list is recoverable. A sent one is not.",choices:[{label:"Continue",next:-1}]}]},whyYou:{content:"Attackers read your website like a staff directory. Your name and role on the staff page, the annual report naming your executive director and thanking donors by giving level. Small organizations publish more about themselves than they realize, because funders expect to see it. Ten minutes of reading tells someone who to impersonate, who to send it to, and which deadline will sound real.\n\nLeaders get impersonated. Staff get asked. And a request that appears to come from your executive director arrives with a cost attached to questioning it â on a team this small, asking 'is this really you?' can feel like an accusation.\n\nThat's a permission problem, not a knowledge problem.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Filters help. They don't finish.",text:"A filter can catch a lookalike domain or flag an outside sender. It can't tell whether you should have been asked for the donor list in the first place. That judgement is yours."}}},workplace:{opening:{title:"4:52 on a Thursday",content:"It's 4:52 on a Thursday. You're ten minutes from heading home and a customer is on hold. An email from the owner: the accountant needs the staff list today â names, roles, home addresses. Send it straight over, and don't loop in the bookkeeper, it isn't her call to make.\n\nNothing in that message is a payment. Nothing is attached. There's no link to click. It was written for the tired ver
1sion of you, one foot out the door, who doesn't want to be the reason the accountant is kept waiting."},scenario:{title:"The Owner Needs It Today",steps:[{text:"Back to 4:52. The accountant needs the staff list today, and the owner asked for it directly. What's your first move?",choices:[{label:"Send it â he asked for it",next:1},{label:"Reply to the email to confirm",next:2},{label:"Call him on the number you already have",next:3},{label:"Ask the bookkeeper",next:4}]},{text:"Sent. The reply-to address was a lookalike domain. Your colleagues' names and home addresses are now somewhere you can't reach, and there is no recalling a staff list.",outcome:"bad",lesson:"A real deadline never makes an unverified send safe.",choices:[{label:"Try again",next:0}]},{text:'The answer comes back in seconds: "With a client â just send it." Which proves nothing. A reply only ever reaches whoever sent the email.',choices:[{label:"Send it",next:1},{label:"Call him on the number you already have",next:3}]},{text:"Straight to voicemail. He's driving back from a site and won't be in until morning. The accountant still needs it today, and now you're stuck.",choices:[{label:"Send it and tell him tomorrow",next:1},{label:"Ask someone else who would know",next:4}]},{text:"The bookkeeper has no request from the accountant, and no staff list was ever asked for. Nobody sent it.\n\nAnd if it had been genuine? The list would have gone out ten minutes later. That is the entire cost of checking.",outcome:"best",lesson:"Can't reach the person who asked? Ask someone else who would know. A late list is recoverable. A sent one is not.",choices:[{label:"Continue",next:-1}]}]},whyYou:{content:"Attackers start with what your company puts online. The owner's name on the site and on LinkedIn, a customer review that thanks you by first name, and an address format anyone can guess once they have that name. Ten minutes of reading tells someone who to impersonate, who to send it to, and which deadline will sound real.\n\nOwners get impersonated. Staff get asked. And a request that appears to come from the owner arrives with a cost attached to questioning it â they're out on a job, they need it now, and asking 'is this really you?' can feel like you don't trust them.\n\nThat's a permission problem, not a knowledge problem.",callout:{icon:"\uD83D\uDEE1ï¸",title:"Filters help. They don't finish.",text:"A filter can catch a lookalike domain or flag an outside sender. It can't tell whether you should have been asked for this staff list in the first place. That judgement is yours."}}}},upsellSlide:{type:"concept",timer:15,title:"If You Want More Than a Lesson",content:"This module is free, and it stays free. If it was useful, there's more.\n\nAn individual subscription adds the browser extension â a trust score on every email before you open it â plus the rest of this library and monthly practice attacks sent to you.\n\nIf your school signs up, staff get all of that, and administrators can see who has trained, who reported what, and where the gaps are.",callout:{icon:"\uD83C\uDF93",title:"Your certificate",text:"Enter your email and we'll send you a certificate for completing this module, plus a link to pick up where you left off. That's all we use it for."}}},"anatomy-urgency":{title:"The Clock Isn't Yours",icon:"â³",duration:"8 min",isPublic:!0,curriculum:!1,series:"anatomy-of-a-scam",seriesOrder:2,seriesLever:"Urgency",slides:[{type:"title",timer:5,title:"The Clock Isn't Yours",subtitle:"Anatomy of a Scam, Part 2 â Urgency",objectives:["See how a countdown turns a careful person into a fast one","Recognize that the deadline itself is the thing to be suspicious of","Learn the one move that makes a fake clock fall apart"]},{type:"concept",timer:20,title:"The Bait",content:"It's the last period on a Friday. You're switching between two classes, phone in one hand, and an email loads: \"District IT â Action Required.\" Your Microsoft 365 account will be locked in 24 hours for failed security verification. Re-enter your password at the link to keep access to your email and gradebook over the weekend.\n\nThere's a clock on the screen counting down. There's a district logo. There's a Monday you can already picture â locked out, grades due, no help desk until 8 a.m. So you tap the link with the part of your brain that just wants Monday to be fine.\n\nAuthority was the last part we took apart â why a message gets aimed at you. This is the next one: why it won't let you stop and think.",callout:{icon:"â³",title:"Notice what's missing",text:"No real IT department locks your account in a way you fix by typing your password into an email link. The urgency is doing the work the facts can't."}},{type:"concept",timer:20,title:"The Mechanism",content:"A manufactured deadline doesn't make you dumber. It makes you faster â and fast is exactly where careful judgment goes quiet. Psychologists call the underlying pull scarcity: we value what's about to be taken away, and we stop weighing it clearly the moment a clock starts.\n\nThe numbers are stark. Verizon's 2024 Data Breach Investigations Report found that when someone falls for a phishing email, the median time is under a minute â roughly 21 seconds to click, another 28 to hand over data. And a 2025 experiment in Information & Computer Security found that people given 7 seconds to judge an email instead of 15 were about twice as bad at spotting the fake. The scam isn't beating your knowledge. It's beating your clock.\n\nThat's why the FBI's tally for business email compromise â the classic \"do this now, don't call to check\" scam â sits near $55 billion in reported losses over about a decade. It rushes, and rushing works.",callout:{icon:"\uD83E\uDDE0",title:"Speed is the attack",text:"The deadline isn't context around the scam. It IS the scam â a tool for taking away the ten seconds you'd have used to notice."}},{type:"keypoints",timer:25,title:"The Tell",points:[{icon:"â±ï¸",label:"The clock is someone else's",desc:"You didn't choose this deadline. Urgency you didn't set is a lever, not a fact.",color:"#ef4444"},{icon:"\uD83D\uDEAA",label:"The exit is one link",desc:"Real problems have several ways to fix them. A fake one funnels you to a single button, right now.",color:"#f97316"},{icon:"\uD83D\uDCF5",label:'"No time to check"',desc:"Any message that discourages you from confirming is telling you exactly what would expose it.",color:"#eab308"}
1,{icon:"\uD83D\uDE28",label:"The cost is your Monday",desc:"Locked out, grades late, no help desk â the threat is picked to make waiting feel expensive.",color:"#3b82f6"},{icon:"\uD83E\uDDEA",label:"It can't survive ten minutes",desc:"A real deadline is fine if you verify. A fake one needs you to move before you think.",color:"#22c55e"}]},{type:"scenario",timer:0,title:"24 Hours to Reset",steps:[{text:'Friday, 2:40 p.m. "District IT: your account locks in 24 hours â re-verify your password now." A countdown ticks on the page. You have a class in five minutes. What do you do?',choices:[{label:"Click the link and re-enter your password so you're not locked out over the weekend",next:1},{label:"Reply to the email asking IT to confirm it's really them",next:2},{label:"Ignore the clock â open a new tab and log in to Microsoft 365 the way you always do",next:3},{label:"Call the IT help desk at the number you already have, not one from this email",next:4}]},{text:"The link opens a page that looks like the Microsoft sign-in. You type your password. Nothing locks â because nothing was ever going to. You just handed your login to whoever built the page. By Monday it's sending scam invoices to the whole staff directory, from you.",outcome:"bad",lesson:"The countdown existed to get your password typed before you could check. A real lockout is never resolved by entering your password into an emailed link.",choices:[{label:"Try again",next:0}]},{text:'You reply. A friendly answer comes back in two minutes: "Yes, this is IT, please verify quickly, the window is closing." Fast and reassuring â because you\'re talking to the attacker. Asking the sender to confirm the sender only ever confirms what they want.',outcome:"bad",lesson:"Confirmation has to travel on a channel you chose, not the one the message handed you. The reply-to is theirs.",choices:[{label:"Try again",next:0}]},{text:"You skip the link entirely and sign in to Microsoft 365 your usual way. Everything works. No lockout, no warning inside the actual account. The 'emergency' only existed inside that one email. You delete it and report it after class.",outcome:"best",lesson:"You added friction on purpose and let the deadline prove itself. It couldn't. A fake clock can't survive a channel you picked.",choices:[{label:"Continue",next:-1}]},{text:'You call the help desk on the number you already had. Thirty seconds: "That\'s not us â your account is fine, forward it to us and delete it." The whole 24-hour emergency evaporates on one short call you controlled.',outcome:"best",lesson:"Ten minutes of friction is all a fake deadline can't afford. A real one would still be true after the call.",choices:[{label:"Continue",next:-1}]}]},{type:"concept",timer:20,title:"The Antibody",content:"You beat urgency by refusing to run its race. The antidote isn't spotting a cleverer clue â it's adding friction on purpose, in the exact moment the message wants you to skip it.\n\nSo when a deadline lands that you didn't choose, do the thing the message quietly discourages: stop, and confirm on a channel YOU pick. Not the reply button. Not the link. Open the app the normal way. Call the number already in your phone. Walk to the office. That small, deliberate delay is what a real deadline can easily survive â and what a fake one can't.\n\nBack in Part 1 the question was \"Why now?\" This is the answer to it: when the \"now\" isn't yours, treat the clock as the tell and make it wait. If it's real, ten minutes won't hurt it. If it isn't, ten minutes is exactly what kills it.",callout:{icon:"\uD83D\uDEE1ï¸",title:"The move",text:"Verify on a channel you choose, and let the deadline prove itself by surviving the wait. Almost nothing legitimate fails that test."}},{type:"quiz",title:"Knowledge Check",timer:0,questions:[{q:"An email warns your account locks in 24 hours unless you act now. What is the single most suspicious thing about it?",options:["It mentions your account","The deadline you didn't choose, designed to stop you from checking","It arrived on a Friday","It has the district logo"],correct:1,explanation:"A logo can be copied and any day can be a Friday. The manufactured deadline is the lever â it exists to collapse the time you'd spend verifying. The urgency is the tell."},{q:"Why is replying to the urgent email to 'confirm it's really IT' a weak check?",options:["Replies are slower than a phone call","It confirms the sender using a channel the sender controls","IT never answers email","It leaves a paper trail"],correct:1,explanation:"Confirmation only means something on a channel YOU choose â the app opened normally, a number you already have. Asking the sender to vouch for themselves just reaches the attacker again."},{q:"What's the reasoning behind 'let the deadline prove itself by surviving a ten-minute check'?",options:["Ten minutes is a company policy","Attackers give up after ten minutes","A real deadline is unharmed by a short verification; a fake one depends on you not doing it","It gives filters time to catch the email"],correct:2,explanation:"A genuine urgent request is still true after you confirm it. A manufactured one needs you to move before you think â so the deliberate delay is precisely what exposes it."}]},{type:"complete",timer:5,title:"Chapter Complete!",takeaways:["A manufactured deadline works by making you fast â and fast is where careful judgment goes quiet. Falling for it is a normal brain under a clock, not a failure.","The urgency you didn't choose IS the tell. When people fall, they fall in under a minute (Verizon 2024) â the scam is racing your clock, not your knowledge.","Add friction on purpose: confirm on a channel YOU pick â the app opened normally, a number already in your phone â never the link or the reply.","A real deadline survives a ten-minute check; a fake one can't afford one. Next lever â Fear: when the message doesn't rush you, it scares you."]}]},"anatomy-fear":{title:"The Fear Is the Attack",icon:"\uD83D\uDE28",duration:"9 min",isPublic:!0,curriculum:!1,series:"anatomy-of-a-scam",seriesOrder:3,seriesLever:"Fear / Loss",slides:[{type:"title",timer:5,title:"The Fear Is the Attack",subtitle:"Anatomy of a Scam \xb7 Part 3 \xb7 The Fear / Loss lever",objectives:["See how a threat narrows your attention until checking feels like a luxury","Name the tells that mark a fear email, even when it wears IT's face","Have one move ready for when the deadline is real and the panic is louder"]},{type:"concept",timer:20,title:"The Bait",content:"It's 4:40 on a Frid
1ay. Grades are due at five, your coat is half on, and the classroom is finally quiet. An email drops in from IT Help Desk: your school email will be deactivated in 24 hours. Storage migration. Confirm your password at the link below to keep your account, or lose access Monday morning.\n\nMonday morning. Your inbox, your gradebook logins, the parent you still owe a reply. All of it gone before first period, unless you handle this now, in the ninety seconds you have before you leave.\n\nSo you don't read it like a puzzle. You read it like a warning, and warnings are for obeying.",callout:{icon:"\uD83E\uDDED",title:"The last part, and the next one",text:"Authority was the previous lever â a request that felt like it came from someone above you. Fear is the next one. It doesn't ask you to respect the sender. It asks you to outrun a loss."}},{type:"concept",timer:20,title:"The Mechanism",content:"Here is the uncomfortable part: the panic isn't a side effect of the scam. The panic is the scam. Everything else â the logo, the deadline, the fake ticket number â exists to manufacture it.\n\nPsychologists Daniel Kahneman and Amos Tversky showed that losing something hurts about twice as much as gaining the same thing feels good. A threat to take away your account, your paycheck, or your license reaches straight for that wiring. Dread floods in, your attention narrows to the one exit the email is pointing at, and you cross the line from checking into doing without noticing you crossed it.\n\nAnd it works at scale. In the FBI's 2024 Internet Crime Report, extortion â the whole family of 'pay or lose it' threats â was the second most-reported crime type of the year, with 86,415 complaints, behind only phishing. Fear isn't a fringe tactic. It's the main event.",callout:{icon:"\uD83D\uDD25",title:"Read the feeling as a signal",text:"The dread in your chest isn't proof the email is real. It's proof the email was built well. Same feeling, opposite conclusion."}},{type:"keypoints",timer:25,title:"The Tell",points:[{icon:"â³",label:"A clock you didn't start",desc:"24 hours, end of day, 'immediate action required' â the deadline exists to stop you from sleeping on it.",color:"#ef4444"},{icon:"\uD83D\uDCA5",label:"A threat to something you can't afford to lose",desc:"Your account, your job, your credential, your last paycheck. The bigger the loss, the smaller your judgment gets.",color:"#f97316"},{icon:"\uD83D\uDD17",label:"The link IS the fix",desc:"'Click here to keep your access.' Real systems make you go to them. A scam brings the door to you.",color:"#eab308"},{icon:"\uD83C\uDFAD",label:"It borrows a badge",desc:"IT, HR, the IRS, a licensing board. Fear almost always wears Authority's face â two levers stacked into one.",color:"#3b82f6"},{icon:"\uD83D\uDD11",label:"It wants a credential, right now",desc:"Confirm your password, verify your login, re-enter your SSN. The 'fix' is you handing over the keys.",color:"#22c55e"}]},{type:"scenario",timer:0,title:"The License Notice",steps:[{text:"Tuesday, during your prep period. An email lands with a state seal at the top: OFFICE OF EDUCATOR LICENSING. A complaint has been filed against your teaching credential. Your certification will be suspended in 72 hours unless you review and respond to the case. There's a case number, a red 'Respond to Complaint' button, and a phone number. Your stomach drops. What do you do?",choices:[{label:"Click 'Respond to Complaint' and sign in to see the case",next:1},{label:"Reply to the email asking what the complaint is about",next:2},{label:"Call the phone number printed at the bottom of the notice",next:3},{label:"Close it, open your bookmark for the real licensing portal, and log in there",next:4}]},{text:"The button opens a page that looks exactly like the state portal. You enter your username and password to 'view the case.' There is no case. There never was. You just handed your credential login to whoever built the page â and the dread they manufactured is the only reason you didn't look at the address bar.",outcome:"bad",lesson:"A link inside a threat is the one door you should never take. The fear was the whole point of the email.",choices:[{label:"Try again",next:0}]},{text:"You hit reply and ask for details. That only confirms your address is live and that you're scared enough to engage. Within the hour a very 'helpful' officer writes back with a link to 'resolve it before suspension.' You're now deeper in the conversation the attacker wanted â and n
1o closer to a real record of any complaint.",outcome:"bad",lesson:"Replying negotiates with the sender on the sender's terms. The channel itself is the trap.",choices:[{label:"Try again",next:0}]},{text:"You call the number. A calm 'case officer' answers, confirms your 'file,' and walks you toward a payment to lift the suspension â or your login to 'verify your identity.' The number in the email reaches the person who wrote the email. Of course it sounded official. They cast the part.",outcome:"bad",lesson:"Never let the message hand you the way to verify it. The phone number in a scam rings the scammer.",choices:[{label:"Try again",next:0}]},{text:"You don't click, don't reply, don't call. You open the licensing portal the way you always do â your own bookmark â and sign in. No complaint. No case. Nothing. Then you report the email as phishing. Your credential was never in danger. The only real thing in that message was the fear.",outcome:"best",lesson:"Go to the real system the way you always reach it. If the threat were real, it would still be true when you got there calmly.",choices:[{label:"Continue",next:-1}]}]},{type:"concept",timer:20,title:"The Antibody",content:"Start from one fact that almost never fails: real institutions do not threaten to delete your account, suspend your license, or dock your pay through a link in an email. Your IT department doesn't migrate storage by asking for your password. A licensing board doesn't run a disciplinary case out of a red button. When the consequence is severe and the fix is a link, that combination is the warning â not the email.\n\nThen use the fear against itself. It's telling you to hurry, which is the exact reason to slow down. Ten seconds of pause is the one thing the whole message was designed to deny you.\n\nAnd the way out is always the same door: go to the real system or agency the way you already know â your bookmark, the app you use, a phone number you looked up yourself. Never the one the email hands you. It's not a small problem. The FTC reported $789 million lost to government-impersonation scams in 2024 â fake IRS, Social Security, and law-enforcement threats â up $171 million from the year before. The people who lost it weren't careless. They were rushed.",callout:{icon:"\uD83D\uDEE1ï¸",title:"One sentence to keep",text:"If it's real, it survives a two-minute wait and a trip to the real site. If it can't survive that, it was never real."}},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"An email says your school account will be deactivated in 24 hours unless you confirm your password at a link. What's the strongest single tell?",options:["The 24-hour deadline","A severe consequence whose 'fix' is a link asking for your password","It came from IT","It mentions storage migration"],correct:1,explanation:"The deadline and the IT sender are pressure and costume. The core tell is the pairing: a threat you can't afford to ignore, resolved by a link that wants your credential. Real systems make you come to them."},{q:"Why does a threat push you toward a mistake faster than an ordinary request?",options:["Threats are usually written more clearly","A potential loss feels about twice as powerful as an equal gain, so dread narrows your attention","People ignore emails that don't have deadlines","Fear makes you read more carefully"],correct:1,explanation:"Kahneman and Tversky's work on loss aversion: losing hurts roughly twice as much as gaining feels good. The threat hijacks that wiring, narrows your focus to the one exit the scam points at, and moves you from checking to doing."},{q:"A 'state licensing board' emails that your credential will be suspended in 72 hours. Best move?",options:["Click the case link quickly, before the 72 hours run out","Call the number printed in the email to confirm","Open your own bookmark for the real licensing portal and check there, then report the email","Reply and ask them to explain the complaint"],correct:2,explanation:"Every option the email offers you â its link, its number, its reply thread â reaches the attacker. Reach the real system your own way. If the threat were real, it would still be true when you arrived calmly."}]},{type:"complete",timer:5,title:"Chapter Complete!",takeaways:["The panic isn't a byproduct of the scam â the panic is the product. The dread means the email was built well, not that it's true.","The fear tells you to hurry, which is exactly why to slow down. Ten seconds
1is the thing the message was designed to steal.","Real institutions don't delete accounts, suspend licenses, or hold paychecks through a link. Go to the real system your own way â bookmark or known number, never the email's.","Reward is the flip side of this lever: when the email doesn't threaten you, it tempts you â and that's the next part we take apart."]}]},"anatomy-reward":{title:"The Prize With Your Name On It",icon:"\uD83C\uDF81",duration:"9 min",isPublic:!0,curriculum:!1,series:"anatomy-of-a-scam",seriesOrder:4,seriesLever:"Reward",slides:[{type:"title",timer:5,title:"The Prize With Your Name On It",subtitle:"Reward \xb7 Anatomy of a Scam, Part 4",objectives:["Notice the moment hope starts reading the email for you","Name the tell that separates a real award from a bait one","Learn the one rule that unlocks every prize scam"]},{type:"concept",timer:20,title:"The Bait",content:"It's a Tuesday in October, your prep period, and the subject line is the nicest thing your inbox has said all week: Congratulations â your classroom has been selected for a $2,500 technology grant.\n\nThe email is warm and specific. It names your school. It mentions the tablets you've been wanting for the reading corner. All you have to do is confirm your details and cover a small $40 processing fee to release the funds â fully refundable, of course, the moment the grant clears.\n\nFor a second you're already spending it. That second is the whole point.",callout:{icon:"\uD83C\uDF81",title:"The pause you skipped",text:"You didn't decide the grant was real. You decided it was wonderful, and let wonderful stand in for real."}},{type:"concept",timer:20,title:"The Mechanism",content:"We've been taking scams apart one piece at a time. The last lever needed someone above you to ask. This one needs nothing above you at all â it just needs you to want something.\n\nThe brain reacts to the anticipation of a windfall before the careful part gets a turn. Attention narrows onto the payoff â the tablets, the $2,500 â and everything around it, the odd fee, the sender you don't quite recognize, goes soft and out of focus. Hope does the reading for you.\n\nThe numbers say it works on grown, careful people. The FTC found that investment scams â the promise of outsized returns â were the single biggest fraud-loss category in 2024, at $5.7 billion, up nearly a quarter in one year. Prize, sweepstakes and lottery scams cost people another $351 million, with a typical loss around a thousand dollars, across more than 97,000 reports. None of those people were foolish. They were hopeful, which is a normal setting for a human being.",callout:{icon:"\uD83D\uDD01",title:"The gift that isn't",text:"Robert Cialdini's work on reciprocity explains the twist: hand someone a prize or a windfall they're 'owed' first, and a small step back â a fee, a login â feels like fair trade instead of a red flag."}},{type:"keypoints",timer:25,title:"The Tell",points:[{icon:"\uD83D\uDCB8",label:"There's a fee to get paid",desc:"A real grant, refund or prize deducts its costs from the award. It never asks you to pay first to unlock it.",color:"#ef4444"},{icon:"\uD83C\uDFB4",label:"The payment can't be undone",desc:"Gift cards, wires, crypto, apps with no reversal â the method IS the scam, not a detail of it.",color:"#f97316"},{icon:"â³",label:"The clock is loud",desc:"Confirm today, funds expire tonight, only three classrooms left. The urgency is there to skip your pause.",color:"#eab308"},{icon:"\uD83C\uDFAF",label:"It found you",desc:"You didn't enter anything. Real awards follow an application you actually remember making.",color:"#3b82f6"},{icon:"\uD83D\uDD17",label:"The money moves through a link",desc:"Owed money arrives by check, payroll or a portal you already use â never a link asking for your bank login.",color:"#22c55e"}]},{type:"scenario",timer:0,title:"The $2,500 Grant",steps:[{text:'Back to that Tuesday. "Your classroom has been selected for a $2,500 technology grant â confirm your details and pay the refundable $40 processing fee to release the funds by Friday." You can already picture the tablets in the reading corner. What do you do?',choices:[{label:"Pay the $40 â it's refund
1able, and the grant is worth sixty times that",next:1},{label:"Reply to ask which foundation this is and why there's a fee",next:2},{label:"Search the foundation's name and the exact grant online before anything",next:3},{label:"Ask your principal or business office whether the school applied for any such grant",next:4}]},{text:"You pay the $40 by card. The next day there's a 'currency conversion charge,' then a 'verification deposit.' The grant never arrives â because the $40 was the grant, flowing the wrong way, and there's always one more fee between you and money that doesn't exist.",outcome:"bad",lesson:"A real award deducts its costs from the award. The moment you pay to get paid, you've found the whole scam.",choices:[{label:"Try again",next:0}]},{text:"You reply with questions. A polished answer names a real-sounding foundation and calls the fee standard and refundable. It's fluent because they've sent it a thousand times â and now you're a confirmed, hopeful, reachable target.",outcome:"bad",lesson:"Replying only tells them a hopeful person is on the line. The channel is theirs.",choices:[{label:"Try again",next:0}]},{text:"You search the foundation and the grant. Nothing official â just other teachers posting the identical email. No legitimate grant runs this way, and none found you without an application you'd remember making.",outcome:"best",lesson:"You didn't enter anything, so nothing could have selected you. A prize that finds you unbidden and charges to release itself is the scam, start to finish.",choices:[{label:"Continue",next:-1}]},{text:"You ask the business office. They applied for no such grant, and they've seen the email make the rounds. You forward it to Report Suspicious so the next teacher sees a warning, not a countdown.",outcome:"best",lesson:"A real award has a paper trail your school knows about. Two minutes with someone who'd know beats a $40 leap of hope.",choices:[{label:"Continue",next:-1}]}]},{type:"concept",timer:20,title:"The Antibody",content:"Here's the whole defense, small enough to keep in a pocket: a real reward never charges a fee to release itself.\n\nMoney you've genuinely won or are genuinely owed does not arrive through a link that wants your bank login. A grant deducts its costs from the grant. A refund comes back the way the payment left. Legitimate prizes don't run on gift cards, and no manager who actually wants five of them needs the codes before lunch.\n\nSo when the payoff and the payment point in opposite directions â the reward is huge, and the way to unlock it is small, fast and untraceable â you're not looking at a lucky day. You're looking at the entire scam, laid out in one email. The unlock IS the trap.\n\nSlow the good news down. A real windfall can survive a night's sleep and a call to a number you already have. Only the fake one can't wait.",callout:{icon:"\uD83D\uDEE1ï¸",title:"One line, every time",text:"If unlocking the reward requires a gift card, a wire, or your login, the reward was never the point. You were."}},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"An email says your classroom won a $2,500 grant, but you must pay a $40 'processing fee' to release it. What's the tell?",options:["The amount is too round to be a real grant","A genuine award deducts costs from the award â it never asks you to pay first","$40 is too small for a real grant to bother collecting","Grants are always mailed, never emailed"],correct:1,explanation:"The fee-to-get-paid pattern is the core of prize fraud. Real money owed to you is never gated behind a payment you have to make first."},{q:"A 'principal' asks an aide to buy gift cards and send the codes, promising reimbursement. Why are the gift cards the giveaway?",options:["Schools never use gift cards for anything","The reimbursement would be taxable","The codes are untraceable and irreversible â once sent, the money is gone","Principals aren't allowed to text staff"],correct:2,explanation:"The payment method is the scam, not a detail of it. Gift cards, wires and crypto get chosen precisely because they can't be recalled."},{q:"The FTC found investment scams were the #1 fraud-loss category in 2024, at $5.7 billion. What does that say about who falls for reward scams?",options:["Only inexperienced people lose money to them","They work on careful, hopeful adults â hope, not foolishness, is the opening","The losses are usually too small to matter","They mostly target people who gamble"],correct:1,explanation:"At $5.7 billion in a single year, these losses aren't a story about gullible people. Anticipating a good outcome is a normal brain doing a normal thing â which is exactly what the lever exploits."}]},{type:"complete",timer:5,title:"Chapter Complete!",takeaways:["The reward lever gets you moving before the skeptical part asks 'is this real?' â hope does the reading for you.","A genuine prize, grant or refund never charges a fee, gift card or wire to release itself. The unlock is the whole scam.","When a 'prize' asks for a fee or a gift card, don't reply â report it and warn the front office, because the next inbox it hits is a colleague's.","Next we take apart Familiarity â sometimes the hook isn't what's offered, it's who it's from."]}]},"anatomy-familiarity":{title:"A Name You Already Trust",icon:"\uD83E\uDEAA",duration:"8 min",isPublic:!0,curriculum:!1,series:"anatomy-of-a-scam",seriesOrder:5,seriesLever:"Familiarity",slides:[{type:"title",timer:5,title:"A Name You Already Trust",subtitle:"Familiarity â why a known name gets waved through",objectives:["See how a display name borrows trust it never earned","Separate the name at the top from the address underneath","Know the one request that always earns a call to a number you already had"]},{type:"concept",timer:20,title:"The Bait: A Favor From Across the Hall",content:"It's 7:40 on a Tuesday, before the first bell. An email from Denise â the co-teacher across the hall. You've swapped classroom keys with her, covered each other's bus duty, split a granola bar at a staff meeting. The name at the top of the message is a name you like.\n\n\"Quick favor â can you send me the shared reading-group file? I'm doing this from my personal account, district mail's being weird this morning.\"\n\nWe've been taking scams apart one part at a time. You've named a few of the pieces already. This is the next one â and it's the quiet one, because it doesn't announce itself. There's no threat, no countdown, no wire transfer. Just a familiar name and a small, reasonable ask. You read \"Denise\" and your guard was already down before you finished the sentence.",callout:{icon:"\uD83E\uDEAA",title:"You read the name, not the address",text:'The brain answers "who is this from?" in a heartbeat. "Is this really them?" takes a second look â and the second look is the whole game.'}},{type:"concept",timer:20,title:"The Mechanism: Borrowed Trust",content:"Psychologists call it Liking â Robert Cialdini's word for a plain fact about people: we say yes far more easily to those we already know and like. It's not a flaw. It's the social wiring that lets a school run at all. You can't re-verify every colleague every morning; trust is the shortcut that makes a hallway function.\n\nAn attacker doesn't break that trust. He borrows it. He puts a familiar name in the \"From\" line â a co-teacher, the principal, Microsoft, the food-service company you've paid for years â and the whole message inherits a credibility it did nothing to earn. A stranger's request gets scrutiny. The same request under a known name gets a nod.\n\nThe Federal Trade Commission found that imposter scams â someone posing as a person or business you trust â were the single most-reported fraud in 2024, with reported losses around $2.95 billion. That's this exact lever, counted up.",callout:{icon:"\uD83C\uDFAD",title:"A display name is a costume",text:"The name shown at the top of an email is typed in by whoever sent it. Familiarity is borrowed, not proven â and it's the easiest thing in the message to fake."}},{type:"keypoints",timer:25,title:"The Tell: Where the Costume Slips",points:[{icon:"\uD83D\uDD0D",label:"The name fits, the address doesn't",desc:'"Denise Carter" up top, but the actual address is a gmail or an off-by-one lookalike â not the district account you\'ve always used.',color:"#ef4444"},{icon:"\uD83D\uDCF1",label:"A reason they're off their normal channel",desc:'"Doing this from my personal account," "my phone," "district mail is down" â a built-in excuse for why it doesn\'t look like them.',color:"#f97316"},{icon:"\uD83C\uDFE6",label:"The ask is data, money, or a login",desc:"A roster, a bank-detail change, a password, a gift card. Familiarity is the wrapper; the payload is always something that leaves the building.",color:"#eab308"},{icon:"â©ï¸",label:"Reply-to sends you somewhere else",desc:"The message shows one name, but hitting reply addresses a stranger. Your answer lands in the attacker's inbox, not your colleague's.",color:"#22c55e"},{icon:"\uD83E\uDD0F",label:"Just enough urgency to skip the check",desc:'Not a screaming deadline â a small "before the bell," "before this week\'s run." Gentle enough that pausing feels like overreacting.',color:"#3b82f6"}]}
1,{type:"scenario",timer:0,title:"The Vendor Changed Its Bank",steps:[{text:"You help with the front-office books. An email arrives from Metro Fresh Foods â the lunch vendor the school has paid every month for three years. Same logo, friendly tone: \"Please note our banking details have changed. Kindly update our account on file before this month's payment so there's no delay in service.\" A new routing and account number are attached. The name is one you've trusted for years. What do you do?",choices:[{label:"Update the account details and process the payment as normal",next:1},{label:"Hit reply and ask them to confirm the change",next:2},{label:"Call the number printed at the bottom of this email to verify",next:3},{label:"Call Metro Fresh at the number on last month's invoice",next:4}]},{text:"You update the vendor record and send the month's payment to the new account. Two weeks later the real Metro Fresh calls: they never got paid, and they never changed their bank. The money went to a criminal who spoofed a name your school has trusted for years â and it's already gone.",outcome:"bad",lesson:"Longtime familiarity is exactly what makes this work. A trusted name is the reason to check harder, not the reason to skip the check.",choices:[{label:"Try again",next:0}]},{text:'You reply asking them to confirm. A warm, professional reply comes back within the hour: "Yes, all confirmed, thank you!" But you never left the email. If the sender is the attacker, you just asked the attacker whether the attacker is real â and he said yes.',outcome:"bad",lesson:"Confirming inside the same thread proves nothing. The channel you verify on has to be one the attacker doesn't control.",choices:[{label:"Try again",next:0}]},{text:"You call the number at the bottom of the email. A polite voice confirms the new account and thanks you for being thorough. It felt like verification â but the phone number was printed by the same person who typed the fake bank details. You verified the forgery against itself.",outcome:"bad",lesson:"Any contact detail inside a suspect message can be part of the forgery. Never verify a request using the request's own phone number.",choices:[{label:"Try again",next:0}]},{text:"You pull last month's paid invoice, find Metro Fresh's number on it, and call. Their accounts manager is alarmed: they sent no such email and their bank hasn't changed. You just stopped a payment from walking out the door â with one phone call to a number you already had.",outcome:"best",lesson:"A request to move money or change bank details always earns a call to a number you already trusted â never the one the message hands you.",choices:[{label:"Continue",next:-1}]}]},{type:"concept",timer:20,title:"The Antibody: Two Names, Two Channels",content:"The defense is small, and it's the same every time. First, read the actual address, not just the name â hover the \"From,\" open it, look. A name you trust sitting on top of an address you don't is the whole scam in one line.\n\nSecond, check both against a channel you already have. Not a reply. Not a number in the email. Denise is three doors down â walk over. The vendor is on last month's invoice â dial that. A second channel the attacker doesn't control is what turns a familiar name back into a verified one.\n\nAnd hold one bright line above all of it: any request to move money, change bank details, or hand over credentials earns a phone call to a number you already had, every single time, no matter how well you know the name on it. The FBI reported that business email compromise â criminals impersonating a trusted boss, colleague, or vendor to redirect a payment â drove about $2.77 billion in U.S. losses in 2024. Nearly all of it would have failed against one call to a known number.",callout:{icon:"âï¸",title:"The number matters more than the name",text:'"Is this really them?" is answered on a second channel â the invoice, the staff directory, the hallway â never on the one the message arrived on.'}},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:'An email\'s display name reads "Principal Alvarez," but the address is [email protected]. What does that tell you?',options:["Nothing â administrators often email from personal accounts","The name was typed in freely and doesn't match the real district address; treat it as unverified","It's fine as long as the message doesn't contain a link","It's automatically safe because you recognize the name"],correct:1,explanation:"The display name is just text the sender chooses. A trusted name over an unfamiliar address is the classic familiarity tell â verify on a channel you already have before acting."},{q:"A trusted vendor emails that their bank account has changed and asks you to update it before the next payment. What's the right move?",options:["Update it â you've worked with them for years","Reply to the email and ask them to confirm the change","Call the vendor using a number from a past invoice, not the email","Call the number printed in the email to double-check"],correct:2,explanation:"A request to change bank details always earns a call to a number you already had. Replying or using the email's own number just verifies the message against itself â the one place the attacker controls."}
1,{q:"Why does a message from a familiar name get less scrutiny than the same message from a stranger?",options:["Familiar senders are technically harder to impersonate","We comply more readily with people we know and like, so we check them less â trust the attacker borrows","Email filters trust known names automatically","Familiar senders never ask for sensitive information"],correct:1,explanation:"That's the Liking principle. Attackers don't break your trust in a colleague or vendor â they borrow it by putting the familiar name on top. The trust is real; the sender isn't."}]},{type:"complete",timer:5,title:"Chapter Complete!",takeaways:["Familiarity is borrowed, not proven â a display name is a costume anyone can put on.","Read the actual address, not just the name; a trusted name over an unfamiliar address is the whole scam in one line.","Verify on a second channel you already control â the hallway, the invoice, a known number â never a reply or a number inside the message.","Any request to move money or change bank details always earns a call to a number you already had â no matter how well you know the name. Next: Helpfulness â the last part turns your best instinct against you."]}]},"anatomy-helpfulness":{title:"Only Trying to Help",icon:"\uD83E\uDD1D",duration:"9 min",isPublic:!0,curriculum:!1,series:"anatomy-of-a-scam",seriesOrder:6,seriesLever:"Helpfulness",slides:[{type:"title",timer:5,title:"Only Trying to Help",subtitle:"The last lever â and the one you'd never want to lose",objectives:["See how 'can you handle a quick thing for me?' turns a strength into a doorway","Name the tell in a favor that's been engineered, not just asked","Say the one sentence that lets you help and verify at the same time"]},{type:"concept",timer:20,title:"The Bait",content:"It's your third week at the front desk. You still double-check which key opens the supply closet. You want, more than anything, to be the aide who's easy to work with â the one they're glad they hired.\n\nAn email from the principal, warm and a little rushed: \"Quick favor â could you grab six $100 gift cards for the staff appreciation lunch on Friday? Trying to keep it a surprise, so let's keep it between us. I'll square up with you after. You're a lifesaver.\"\n\nThere's no threat in it. No scary link. Just a small ask, wrapped in trust, aimed at the part of you that wants to be useful. Authority was the first part we took apart in this series. This is the last one â and it doesn't push you. It leans on you.",callout:{icon:"\uD83E\uDD1D",title:"Not a knowledge problem",text:"You're not falling for this because you don't know better. You're leaning in because you're conscientious. That's a helpfulness problem â and helpfulness is a good thing to have."}},{type:"concept",timer:20,title:"The Mechanism",content:"Most careful people run a quiet default: when someone you trust asks for something small, you say yes. It's how a school stays glued together â the copier jam, the covered lunch duty, the 'can you keep an eye on my class for two minutes.' Reciprocity and the instinct to be a good employee are features, not flaws.\n\nAn attacker doesn't fight that instinct. He rents it. He picks a small, doable, plausible favor, attaches it to a trusted name, adds a soft reason to stay quiet, and lets your best qualities carry the rest.\n\nThis is why it pays so well. The FBI calls it Business Email Compromise â a scam that works entirely by borrowing a helpful, responsive person inside a trusted relationship â and it's the single most lucrative email fraud category they track, roughly $55 billion in reported losses over about a decade. Not one giant heist. Millions of small, reasonable-sounding favors.",callout:{icon:"\uD83D\uDCCA",title:"Small ask, big category",text:"The FTC ranked imposter scams the #1 most-reported fraud of 2024, at $2.95 billion. Most started the same gentle way this one did â a familiar name, a modest request."}},{type:"keypoints",timer:25,title:"The Tell",points:[{icon:"\uD83C\uDF81",label:"The favor moves value",desc:"Gift cards, a wire, a 'flexible, just this once' change to a vendor's bank details â the ask quietly converts your goodwill into money that's gone the moment you send it.",color:"#ef4444"},{icon:"\uD83E\uDD2B",label:"Keep it between us",desc:"Real favors survive a second person hearing about them. A favor that needs secrecy is protecting the scam, not the surprise.",color:"#f97316"},{icon:"\uD83D\uDCF5",label:"Stay in this channel",desc:"'Just reply here, I'm in meetings.' Steering you away from a hallway or a known phone number keeps you from the one thing that would end it â hearing the real person's voice.",color:"#eab308"},{icon:"âï¸",label:"Bend the rule once",desc:"The ask is framed as an exception â skip the office, skip the two-signature step, I'll reimburse you after. The 'just this once' is the whole con.",color:"#22c55e"},{icon:"\uD83C\uDF1F",label:"It flatters the eager",desc:"'You're a lifesaver.' It's aimed at whoever most wants to prove they belong â the new hire, the temp, the one covering a colleague's desk.",color:"#3b82f6"}]},{type:"scenario",timer:0,title:"You're a Lifesaver",steps:[{text:"The gift-card email is sitting open. You genuinely want to help, and the principal genuinely runs staff lunches. You've got a card of your own you could use and get paid back Friday. What do you do?",choices:[{label:"Buy the cards now â it's a small favor and you'll be reimbursed",next:1},{label:"Reply to the email asking if she's sure about the amount",next:2},{label:"Walk down the hall to the principal's office and ask her in person",next:3},{label:"Call the principal on the number in the staff directory before doing anything",next:4}]},{text:"You buy six cards, scratch off the codes, and email them over because she asked for the numbers 'to send out today.' The reply comes fast: 'Perfect, you're the best â can you grab four more?' There is no lunch. There is no reimbursement. The codes were drained within the hour.",outcome:"bad",lesson:"Once the codes leave your hands, the money is gone and untraceable. The 'quick favor' was engineered to spend exactly your best quality.",choices:[{label:"Try again",next:0}]},{text:"You reply asking to confirm. 'Yes! Sorry for the rush â you're a star.' Of course it says yes. You replied to the attacker; he's thrilled to reassure you. A confirmation from inside the same email proves nothing about who's really there.",outcome:"bad",lesson:"You can't verify a suspicious sender by asking that same sender. The answer will always be the one they need.",choices:[{label:"Try again",next:0}]},{text:"You walk down the hall. The principal looks up, puzzled: 'Gift cards? I didn't send that.' Ten steps and thirty seconds ended it. You forward the message to Report Suspicious so the next person on her staff list sees a warning instead of a checkout line.",outcome:"best",lesson:"The favor was real-sounding; the request was not. Verifying in person cost you almost nothing and cost the attacker everything.",choices:[{label:"Continue",next:-1}]},{text:"You call the number in the staff directory â not any number in the email. She picks up: 'That's not me. Don't buy anything.' The one channel the attacker couldn't sit inside is the one that saved you. You report the message and go back to your afternoon.",outcome:"best",lesson:"A known, independent channel is the attacker's blind spot. Being helpful and calling to check are not in conflict â one made the other safe.",choices:[{label:"Continue",next:-1}]}]},{type:"concept",timer:20,title:"The Antibody",content:"The fix is not to become the person who says no to everything and treats every colleague like a suspect. That version of you is worse at the job, and it still wouldn't be safe â it'd just be unpleasant.\n\nThe fix is smaller and kinder than that. You keep the yes. You add four words. 'Happy to â let me just confirm first.' Then you confirm through a channel the request didn't choose for you: a walk to the office, a call to the number you already have, a quick word with someone else who'd know.\n\nHelping and verifying were never opposites. Confirming a changed vendor account, or an unusual gift-card ask, is part of doing the favor well â it's what a careful, valuable employee does. A good colleague will never be annoyed that you checked. The only person who needs you to skip the check is the one who shouldn't have asked.",callout:{icon:"â
",title:"A complete, kind sentence",text:"'Happy to â let me just confirm first' asks for nothing, accuses no one, and closes the door on every scam in this series at once."}},{type:"quiz",timer:0,title:"Knowledge Check",questions:[{q:"A vendor you've paid for years emails that their bank details have changed â 'please update before this month's invoice, and thanks for being flexible.' What's the safest move?",options:["Update the details and pay â you have a long, trusted relationship","Reply to the email to confirm the new account number","Call the vendor on the number you already had on file â not one in this email â before changing anything","Pay a small test amount first to see if it goes through"],correct:2,explanation:"Changed payment details are the classic 'be flexible, just this once' favor. Confirming through the number you already had â never one supplied in the request â is the check that catches it. Replying to the email just asks the attacker to reassure you."},{q:"Which detail in a favor should make you slow down the most?",options:["It's addressed warmly and uses your first name","It asks you to move something valuable, keep it quiet, and stay in email","It comes from a senior person","It mentions a real event happening this week"],correct:1,explanation:"Warmth, seniority, and a real event are all normal â attackers borrow them precisely because they're normal. The combination that should stop you is value moving + secrecy + a channel you're steered to stay inside."},{q:"What's the problem with 'just be unhelpful and suspicious of everyone' as a defense?",options:["It works, but it's rude","It makes you worse at your job and still isn't safe â the real fix is to help and verify","It's the only reliable way to stay safe","It stops phishing but not gift-card scams"],correct:1,explanation:"Your helpfulness is a strength worth keeping. You don't remove it â you pair it with a quick, independent check. 'Happy to â let me just confirm first' keeps the good part and cuts out the risk."}]},{type:"complete",timer:5,title:"Chapter Complete!",takeaways:["Six levers, one anatomy: Authority makes you comply, Urgency makes you rush, Fear makes you freeze, Reward makes you reach, Familiarity makes you trust, and Helpfulness makes you want to say yes â a real attack usually stacks several at once.","The one question that cuts through all six is still the first one we asked: why did this land on me, and what does 'yes' hand over?","You were never the bug. Being conscientious, responsive, and eager to help is what makes a school work â attackers rent those strengths, they don't create weakness in you.","You can be helpful and still verify â 'happy to, let me just confirm first,' then check through a channel the request didn't pick for you, and forward anything that fails the check to Report Suspicious. That's the whole course, in one habit."]}]}};function i(e="en"){return Object.entries("es"===e?t:s).filter(([,e])=>!0===e.isPublic).map(([e,a])=>({slug:e,...a}))}let r={"anatomy-of-a-scam":{id:"anatomy-of-a-scam",title:"Anatomy of a Scam",tagline:"Why scams work on careful people â and how to push back.",description:"Every scam is built from the same handful of psychological parts. In six short chapters we take them apart one at a time â so you learn to recognize the move, not just memorize the trick. No account, no cost, and a certificate when you finish a chapter.",stat:"Phishing is the #1 reported internet crime, and 68% of data breaches involve a person â not a machine.",statSource:"FBI IC3 2024 \xb7 Verizon 2024 DBIR"}};function l(e="en",a="staff"){if("student"===a)return Object.entries(n).map(([e,a])=>({slug:e,title:a.title,icon:a.icon,duration:a.duration,level:a.level||null,slideCount:a.slides.length}));let o="es"===e?t:s,i="object"==typeof r&&r||{},c=new Set;for(let e of Object.keys(i))for(let[a,o]of Object.entries(s))o.series===e&&c.add(a);let d=[];for(let[e,a]of Object.entries(o))c.has(e)||(!0===a.curriculum||!0!==a.isPublic)&&d.push({slug:e,title:a.title,icon:a.icon,duration:a.duration,slideCount:(a.slides||[]).length});for(let[e,a]of Object.entries(i)){let o=Object.entries(s).filter(([,a])=>a.series===e).sort((e,a)=>(e[1].seriesOrder||99)-(a[1].seriesOrder||99)).map(([e,a])=>({slug:e,title:a.title,icon:a.icon,duration:a.duration,lever:a.seriesLever||"",order:a.seriesOrder||null,slideCount:(a.slides||[]).length}));o.length&&d.push({slug:o[0].slug,seriesId:e,isSeries:!0,title:a.title,icon:o[0].icon||"\uD83D\uDCD8",duration:`${o.length} chapters`,slideCount:o.reduce((e,a)=>e+(a.slideCount||0),0),chapters:o})}return d}let c={catholic:{school_name:"St. Mary's",school_short:"St. Mary's",school_domain:"stmarys.edu",spoof_domain:"di0cese-tech.com",spoof_link:"diocse-portal.com",spoof_sender_label:"IT Support",spoof_explain_domain:"The sender domain uses a zero instead of 'o' â it's not your real domain.",spoof_explain_link:"The link domain is misspelled â this goes to a fake site.",leader_name:"Fr. Michael Torres",leader_short:"Fr. Torres",leader_title:"Pastor",principal_title:"Principal",principal_name_example:"Dr. Sarah Mitchell",principal_short_example:"Dr. Mitchell",business_manager_title:"Business Manager",business_manager_name_example:"Maria Gonzalez",it_contact_title:"IT Director",org_term:"school",org_account:"parish account",network_term:"diocese",network_leader:"bishop",worship_place:"parish",gift_card_event:"a staff appreciation event at the parish",greeting:"God bless",password_example:"StMarys2024!",password_new:"StMarys2025!",meeting_sender_name:"Sarah Mitchell",meeting_sender_email:"[email protected]",meeting_sender_to:"[email protected]",meeting_sender_title:"Assistant Principal"},christian:{school_name:"Faith Academy",school_short:"Faith Academy",school_domain:"faithacademy.edu",spoof_domain:"church-sch00l-portal.com",spoof_link:"faith-acadamy-p
1ortal.com",spoof_sender_label:"IT Support",spoof_explain_domain:"The sender domain uses zeros instead of 'o' â it's not your real domain.",spoof_explain_link:'The link domain has "acadamy" misspelled â this goes to a fake site.',leader_name:"Pastor David Johnson",leader_short:"Pastor Johnson",leader_title:"Senior Pastor",principal_title:"Principal",principal_name_example:"Dr. Sarah Mitchell",principal_short_example:"Dr. Mitchell",business_manager_title:"Business Manager",business_manager_name_example:"Maria Gonzalez",it_contact_title:"IT Director",org_term:"school",org_account:"church account",network_term:"district",network_leader:"superintendent",worship_place:"church",gift_card_event:"a staff appreciation event at the church",greeting:"God bless",password_example:"FaithAcademy2024!",password_new:"FaithAcademy2025!",meeting_sender_name:"Sarah Mitchell",meeting_sender_email:"[email protected]",meeting_sender_to:"[email protected]",meeting_sender_title:"Assistant Principal"},jewish:{school_name:"Beit Sefer Academy",school_short:"Beit Sefer",school_domain:"beitsefer.edu",spoof_domain:"daysch00l-network.org",spoof_link:"beitsefer-acadamy.com",spoof_sender_label:"IT Support",spoof_explain_domain:"The sender domain uses zeros instead of 'o' â it's not your real domain.",spoof_explain_link:'The link domain has "acadamy" misspelled â this goes to a fake site.',leader_name:"Rabbi David Cohen",leader_short:"Rabbi Cohen",leader_title:"Rabbi",principal_title:"Head of School",principal_name_example:"Dr. Sarah Goldstein",principal_short_example:"Dr. Goldstein",business_manager_title:"Business Manager",business_manager_name_example:"Rachel Levine",it_contact_title:"IT Director",org_term:"day school",org_account:"school account",network_term:"network",network_leader:"director",worship_place:"synagogue",gift_card_event:"a community Hanukkah celebration",greeting:"Shalom",password_example:"BeitSefer2024!",password_new:"BeitSefer2025!",meeting_sender_name:"Sarah Goldstein",meeting_sender_email:"[email protected]",meeting_sender_to:"[email protected]",meeting_sender_title:"Assistant Head of School"},muslim:{school_name:"Al-Noor Academy",school_short:"Al-Noor",school_domain:"alnooracademy.edu",spoof_domain:"islamic-sch00l-admin.com",spoof_link:"alnoor-acadamy.com",spoof_sender_label:"IT Support",spoof_explain_domain:"The sender domain uses zeros instead of 'o' â it's not your real domain.",spoof_explain_link:'The link domain has "acadamy" misspelled â this goes to a fake site.',leader_name:"Imam Hassan Ali",leader_short:"Imam Hassan",leader_title:"Imam",principal_title:"Principal",principal_name_example:"Fatima Ahmed",principal_short_example:"Ms. Ahmed",business_manager_title:"Business Manager",business_manager_name_example:"Aisha Rahman",it_contact_title:"IT Director",org_term:"school",org_account:"school account",network_term:"network",network_leader:"director",worship_place:"masjid",gift_card_event:"an end-of-Ramadan iftar celebration",greeting:"Jazakallahu khairan",password_example:"AlNoor2024!",password_new:"AlNoor2025!",meeting_sender_name:"Fatima Ahmed",meeting_sender_email:"[email protected]",meeting_sender_to:"[email protected]",meeting_sender_title:"Assistant Principal"},secular:{school_name:"Westfield Academy",school_short:"Westfield",school_domain:"westfieldacademy.edu",spoof_domain:"district-admin-p0rtal.com",spoof_link:"westfield-acadamy.com",spoof_sender_label:"IT Support",spoof_explain_domain:"The sender domain uses a zero instead of 'o' â it's not your real domain.",spoof_explain_link:'The link domain has "acadamy" misspelled â this goes to a fake site.',leader_name:"Dr. James Wilson",leader_short:"Dr. Wilson",leader_title:"Superintendent",principal_title:"Principal",principal_name_example:"Dr. Sarah Mitchell",principal_short_example:"Dr. Mitchell",business_manager_title:"Business Manager",business_manager_name_example:"Maria Gonzalez",it_contact_title:"IT Director",org_term:"school",org_account:"school account",network_term:"district",network_leader:"superintendent",worship_place:"campus",gift_card_event:"a staff appreciation event",greeting:"Best regards",password_example:"Westfield2024!",password_new:"Westfield2025!",meeting_sender_name:"Sarah Mitchell",meeting_sender_email:"[email protected]",meeting_sender_to:"[email protected]",meeting_sender_title:"Assistant Principal"}};function d(e){if(!e)return null;let a=e.trim().split(/\s+/);return a.length<2?e:["Fr.","Fr","Dr.","Dr","Rabbi","Imam","Pastor","Rev.","Rev","Mr.","Ms.","Mrs."].includes(a[0])?`${a[0]} ${a[a.length-1]}`:a[a.length-1]}function u(e,a){let o=c[e]||c.catholic,t=a||{},n=t.role_titles||{},s=t.role_names||{},i=s.pastor||o.leader_name,r=s.pastor?d(s.pastor):o.leader_short,l=n.pastor||o.leader_title,u=s.principal||o.principal_name_example,h=s.principal?d(s.principal):o.principal_short_example,p=n.principal||o.principal_title,m=s.business_manager||o.business_manager_name_example,y=n.business_manager||o.business_manager_title,g=n.it_contact||o.it_contact_title,f=t.org_name||o.school_name,b=t.org_name||o.school_short;return{...o,school_name:f,school_short:b,leader_name:i,leader_short:r,leader_title:l,principal_name:u,principal_short:h,principal_title:p,business_manager_name:m,business_manager_title:y,it_contact_title:g}}function h(e,a="catholic",o=null){if(n[e])return n[e];if("es"===(a&&"object"==typeof a&&a.lang||"en")){let n=t[e];return n?function(e,a="catholic",o=null){let t,n;"string"==typeof a?(t=a,n=o):a&&"object"==typeof a?(t=a.tradition||"catholic",n=a.orgProfile||null):(t="catholic",n=null);let s=u(t,n),i=JSON.parse(JSON.stringify(e)),r=(s.school_domain||"stmarys.edu").split(".")[0],l=e=>e&&"string"==typeof e?e.replace(/stmarys\.edu/g,s.school_domain).replace(/admin@stmarys\b/g,`admin@${r}`).replace(/@stmarys\b/g,`@${r}`).replace(/St\. Mary's/g,s.school_short):e,c=e=>{if(Array.isArray(e))return void e.forEach(c);if(e&&"object"==typeof e)for(let a of Object.keys(e))"string"==typeof e[a]?e[a]=l(e[a]):c(e[a])};return i.title=l(i.title),c(i.slides),i}(n,a,o):null}let i=s[e];return i?function(e,a="catholic",o=null){let t,n;"string"==typeof a?(t=a,n=o):a&&"object"==typeof a?(t=a.tradition||"catholic",n=a.orgProfile||null):(t="catholic",n=null);let s=u(t,n),i=JSON.parse(JSON.stringify(e)),r=e=>{if(!e||"string"!=typeof e)return e;let a=e;return a=(a=(a=(a=(a=(a=(a=(a=(a=(a=a.replace(/Fr\. Michael Torres/g,s.leader_name)).replace(/Fr\. Torres/g,s.leader_short)).replace(/parish account/g,s.org_account)).replace(/parish event/g,`${s.worship_place} event`)).replace(/stmarys\.edu/g,s.school_domain)).replace(/admin@stmarys/g,`admin@${s.school_domain.split(".")[0]}`)).replace(/@stmarys\b/g,`@${s.school_domain.split(".")[0]}`)).replace(/St\. Mary's/g,s.school_short)).replace(/StMarys2024!/g,s.password_example)).replace(/StMarys2025!/g,s.password_new),s.principal_title&&"Principal"!==s.principal_title&&(a=(a=(a=(a=(a=a.replace(/\bthe principal\b/g,`the ${s.principal_title.toLowerCase()}`)).replace(/\bYour principal\b/g,`Your ${s.principal_title.toLowerCase()}`)).replace(/\byour principal\b/g,`your ${s.principal_title.toLowerCase()}`)).replace(/\bprincipal's office\b/g,`${s.principal_title.toLowerCase()}'s office`)).replace(/\bprincipal's known phone number\b/g,`${s.principal_title.toLowerCase()}'s known phone number`)),a=(a=(a=(a=a.replace(/di0cese-tech\.com/g,s.spoof_domain)).replace(/diocse-portal\.com/g,s.spoof_link)).replace(/\nGod bless,/g,` 2${s.greeting},`)).replace(/^God bless,/g,`${s.greeting},`)};for(let e of i.slides){if(e.content&&(e.content=r(e.content)),e.callout?.text&&(e.callout.text=r(e.callout.text)),e.callout?.title&&(e.callout.title=r(e.callout.title)),e.subtitle&&(e.subtitle=r(e.subtitle)),e.title&&(e.title=r(e.title)),Array.isArray(e.objectives)&&(e.objectives=e.objectives.map(r)),Array.isArray(e.points))for(let a of e.points)a.label&&(a.label=r(a.label)),a.desc&&(a.desc=r(a.desc));if(e.email){let a=e.email;a.from?.address==="[email protected]"?(a.from.address=`support@${s.spoof_domain}`,a.from.name=s.spoof_sender_label,a.to&&(a.to=a.to.replace(/@school\.edu/g,`@${s.school_domain}`)),a.body&&(a.body=r(a.body)),Array.isArray(a.redFlags)&&(a.redFlags=a.redFlags.map(e=>"di0cese-tech.com"===e.highlight?{highlight:s.spoof_domain,explanation:s.spoof_explain_domain}:"diocse-portal.com"===e.highlight?{highlight:s.spoof_link,explanation:s.spoof_explain_link}:{...e,explanation:r(e.explanation)}))):a.from?.address==="[email protected]"?(a.from={name:s.meeting_sender_name,address:s.meeting_sender_email},a.to=s.meeting_sender_to,a.body&&(a.body=a.body.replace(/Sarah Mitchell/g,s.meeting_sender_name).replace(/Assistant Principal/g,s.meeting_sender_title)),a.legitimateReasons&&(a.legitimateReasons=r(a.legitimateReasons))):(a.body&&(a.body=r(a.body)),a.legitimateReasons&&(a.legitimateReasons=r(a.legitimateReasons)),Array.isArray(a.redFlags)&&(a.redFlags=a.redFlags.map(e=>({...e,explanation:r(e.explanation)})))),a.subject&&(a.subject=r(a.subject))}if(Array.isArray(e.steps))for(let a of e.steps)a.text&&(a.text=a.text.replace(/a staff appreciation event\b/g,s.gift_card_event),a.text=r(a.text)),a.lesson&&(a.lesson=r(a.lesson)),Array.isArray(a.choices)&&(a.choices=a.choices.map(e=>({...e,label:r(e.label)})));if(Array.isArray(e.questions))for(let a of e.questions)a.q&&(a.q=r(a.q)),Array.isArray(a.options)&&(a.options=a.options.map(r)),a.explanation&&(a.explanation=r(a.explanation));Array.isArray(e.takeaways)&&(e.takeaways=e.takeaways.map(r))}return i}(i,a,o):null}},82849:(e,a,o)=>{function t(e){for(var a=1;a<arguments.length;a++){var o=arguments[a];for(var t in o)"__proto__"!==t&&(e[t]=o[t])}return e}o.r(a),o.d(a,{default:()=>n});var n=function e(a,o){function n(e,n,s){if("u">typeof document){"number"==typeof(s=t({},o,s)).expires&&(s.expires=new Date(Date.now()+864e5*s.expires)),s.expires&&(s.expires=s.expires.toUTCString()),e=encodeURIComponent(e).replace(/%(2[346B]|5E|60|7C)/g,decode
vendor: 1,009 bytes, line 2
2URIComponent).replace(/[()]/g,escape);var i="";for(var r in s)s[r]&&(i+="; "+r,!0!==s[r]&&(i+="="+s[r].split(";")[0]));return document.cookie=e+"="+a.write(n,e)+i}}return Object.create({set:n,get:function(e){if("u">typeof document&&(!arguments.length||e)){for(var o=document.cookie?document.cookie.split("; "):[],t={},n=0;n<o.length;n++){var s=o[n].split("="),i=s.slice(1).join("=");try{var r=decodeURIComponent(s[0]);if(r in t||(t[r]=a.read(i,r)),e===r)break}catch(e){}}return e?t[e]:t}},remove:function(e,a){n(e,"",t({},a,{expires:-1}))},withAttributes:function(a){return e(this.converter,t({},this.attributes,a))},withConverter:function(a){return e(t({},this.converter,a),this.attributes)}},{attributes:{value:Object.freeze(o)},converter:{value:Object.freeze(a)}})}({read:function(e){return'"'===e[0]&&(e=e.slice(1,-1)),e.replace(/(%[\dA-F]{2})+/gi,decodeURIComponent)},write:function(e){return encodeURIComponent(e).replace(/%(2[346BF]|3[AC-F]|40|5[BDE]|60|7[BCD])/g,decodeURIComponent)}},{path:"/"})}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.