Messages arrive in your inbox: emails, text messages, phone calls (written out as what the caller says) and web pages. The oldest one is open. Read it and decide before the inbox fills: when 5 are waiting and another arrives, the oldest is lost, and so is a life. A wrong answer costs a life too, and the clue you missed is boxed in red on the message, with why.
- Core: Trust (1 or ←) or Report (2 or →).
- Advanced: name it: Phishing 1, Smishing 2, Vishing 3, Pharming 4 or Legitimate 5. Name a threat right and the buttons change: choose the best defence (1 to 4).
The threats
- Phishing: a fake email that looks as if it's from a real organisation, to get you to click a link to a fake website, open an attachment, or hand over personal details.
- Smishing (SMS phishing): the same trick by text message, often with a short link or a number to ring.
- Vishing (voice phishing): the same trick by phone call, sometimes a recorded message, with the caller pretending to be a bank, a government department, the police or tech support.
- Pharming: malicious code installed on your computer, or on a web server, redirects you to a fake website even though you typed the right address (or used your bookmark). You did nothing wrong, so there's no message to spot: the clues are on the page itself.
The clues
- The sender: an email address whose domain isn't the organisation's (
kauribank-alerts.com, not kauribank.co.nz), or a text from an overseas or personal mobile number. New Zealand government sites end in .govt.nz.
- The link: the words shown can say anything. Hover over a link (or press and hold on a phone) to see where it really goes. A shortened link hides its address.
- Attachments: a file that runs code (
.exe, a .zip from a stranger, a document that asks you to enable macros) can install malware.
- Urgency and threats: "within 24 hours", "your account will be closed", "a warrant for your arrest". Pressure is there to stop you checking.
- What it asks for: no genuine bank, shop or government department asks for your PIN, your full password, a code it has just texted you, gift cards, or a transfer to a "safe account". A generic greeting ("Dear Customer") instead of your name is another sign.
- On a web page: no
https and no padlock, a certificate warning, or a page asking for much more than usual.
The defences
- Call back on the official number (vishing, and texts that ask you to ring): hang up, and call the number on your card, your bill or the organisation's own website, never one the caller or message gives you.
- Don't click or reply (phishing and smishing links): open the organisation's app, or type its real address yourself, and check there. Report the message and delete it.
- Leave the site (pharming): don't enter anything; check the address and the certificate, run up-to-date anti-malware, and tell the organisation.
- Don't open the attachment: delete the email and report it; anti-malware software scans attachments too.
Also: keep software and anti-malware up to date, use two-factor authentication, and never share a one-time code.
Common exam mistakes
- Mixing up the names: phishing is email, smishing is SMS, vishing is voice. Pharming needs no message at all.
- Saying pharming happens "because the user clicked a link": that's phishing. In pharming the user types the correct address and is still redirected.
- "Look for the padlock" on its own: a padlock only means the connection is encrypted, so check the address too.
- Vague answers like "be careful": name the action (don't click the link; check the sender's address; call the bank on its official number).
Every organisation, person, number and address in the game is made up, except Inland Revenue (ird.govt.nz) and NZ Post (nzpost.co.nz) in their genuine messages; the scams that pretend to be them use made-up addresses.
Scoring
A right answer scores 10 in Core and 15 in Advanced, plus up to half as much again for a quick one, and a streak multiplies it (×2 from 4 right in a row, up to ×5). In Advanced, the right defence for a threat you've named scores 10 more. A wrong answer, or a card you miss, costs a life and starts your streak again. Scores are checked on the server, so the leaderboards (the world's, and your class's and school's when you're signed in) are fair.
Objective: recognise phishing, smishing, vishing and pharming, the clues that give them away, and how to prevent and deal with each (Cambridge IGCSE ICT 0417, section 8, safety and security; Cambridge International AS Level Information Technology 9626, topic 5, eSecurity).
Where this fits
- AP: AP Computer Science Principles
- Cambridge: Cambridge IGCSE Information and Communication Technology (0417); Cambridge IGCSE Computer Science (0478); Cambridge A Level Computer Science (9618); Cambridge AS Level Computer Science (9618); Cambridge A Level Information Technology (9626); Cambridge AS Level Information Technology (9626)
- IB: IB Computer Science HL; IB Computer Science SL
- NCEA Level 2 Digital Technologies: 91898 Demonstrate understanding of a computer science concept; 91898 Demonstrate understanding of a computer science concept
- Pearson Edexcel International: Edexcel International GCSE Computer Science (4CP0); Edexcel International GCSE ICT (4IT1); Edexcel International A Level Information Technology
- USDP: USDP Computer Science