🧠 Not sure where to start? Take the free Cyber IQ Quiz — find out your score and get a personalized mission plan.
134 MISSIONS · ISTE-ALIGNED · AGES 8–18

The Cybersecurity
Mission Library

Every mission is a real scenario, not a worksheet. Kids inspect phishing emails, detect AI deepfakes, battle malware, and earn badges along the way. No lectures. Just missions.

134 missions 🏅 16 collectible badges 📚 ISTE standards 🤖 Sensei Byte AI Mentor
🤖
AI MENTOR IN EVERY MISSION
Sensei Byte watches your progress, offers hints when you're stuck, explains why an answer was wrong, and writes a personalized debrief when you finish. Not canned — actual analysis.
Age Band
Mission Type
Topic
#46
Interactive Lab
🏰

Password Fortress

The castle gates are locked — but they are not secure enough! Your job is to build an unbreakable Password Fortress.

👤 Ages 8–12 📚 Standard 🕒30 min
Explain why mixing character types strengthens a password
Demonstrate that longer passwords are exponentially harder to crack
ISTE: Digital Citizen 2a · Digital Citizen 2b
#2
Quiz Mission
🎣

Phishing Pond

Scammers send 3.4 billion fake emails every day. Learn to spot every one.

👤 Ages 8–12 📚 Standard 🕒10 min
Recognize phishing email tactics including urgency and fake authority
Identify suspicious sender domains and link destinations
ISTE: Digital Citizen 2c · Digital Citizen 2d
#3
Quiz Mission
🔏

Privacy Shield

You share more than you think. Here how to take it back.

👤 Ages 8–12 📚 Standard 🕒10 min
Understand what personal information should stay private online
Recognize how apps and websites collect data about users
ISTE: Digital Citizen 2b · Digital Citizen 2d
#4
Quiz Mission
🌐

Social Savvy

Every post is permanent. Every stranger has a motive. Are you ready?

👤 Ages 8–14 📚 Standard 🕒10 min
Understand digital permanence — posts and messages can last forever
Recognize online stranger danger including catfishing tactics
ISTE: Digital Citizen 2a · Digital Citizen 2c
#5
Quiz Mission
🦠

Malware Maze

Viruses don look like viruses. That exactly the problem.

👤 Ages 10–14 📚 Standard 🕒30 min
Identify types of malware: viruses, ransomware, spyware, and trojans
Recognize warning signs of infected devices and suspicious downloads
ISTE: Digital Citizen 2a · Digital Citizen 2b
#6
Interactive Lab Try Free →
🕵️

Phishing Inbox Detective

Real phishing attacks — real consequences. Can you catch them all before you click?

👤 Ages 10–14 📚 Standard 🕒30 min
Analyze email sender fields to detect domain spoofing and typosquatting
Identify urgency and fear tactics used to manipulate victims
ISTE: Digital Citizen 2c · Digital Citizen 2d
#7
Interactive Lab
🔐

Password Fortress Interactive

5 challenges. A live entropy meter. No hints unless you earn them.

👤 Ages 10–14 📚 Standard 🕒30 min
Apply entropy and length concepts to build genuinely strong passwords
Recognize and avoid common password patterns that attackers exploit
ISTE: Digital Citizen 2a · Digital Citizen 2b
#8
Interactive Lab
🔑

Two-Factor Fortress

Even if your password leaks, 2FA keeps attackers out. Here how.

👤 Ages 10–14 📚 Standard 🕒30 min
Understand how two-factor authentication protects accounts even after password leaks
Distinguish between SMS codes, authenticator apps, and hardware keys
ISTE: Digital Citizen 2a · Digital Citizen 2b
#9
Interactive Lab
📵

Scam Spotter

The IRS is NOT calling. Your warranty is NOT expiring. Let prove it.

👤 Ages 10–14 📚 Standard 🕒30 min
Identify robocall and smishing scam scripts and the pressure tactics they use
Recognize government impersonation and tech support scam patterns
ISTE: Digital Citizen 2c · Digital Citizen 2d
#10
Interactive Lab
📍

Privacy Guardian

A photo of your lunch could reveal your home address. Here why.

👤 Ages 10–14 📚 Standard 🕒30 min
Understand how geotagged photos can reveal precise location data
Audit and adjust social media privacy settings to protect personal information
ISTE: Digital Citizen 2b · Digital Citizen 2d
#11
Interactive Lab
🛡️

Cyberbullying Defender

60% of kids witness cyberbullying. Only 20% say something. Be the 20%.

👤 Ages 10–14 📚 Standard 🕒30 min
Identify cyberbullying patterns including exclusion, harassment, and impersonation
Choose effective bystander responses that de-escalate and support victims
ISTE: Digital Citizen 2a · Digital Citizen 2c
#12
Interactive Lab
🤖

AI & Deepfake Detective

AI can fake voices, faces, and entire conversations. Your eyes are not enough.

👤 Ages 12–18 🚀 Standard 🕒30 min
Identify visual artifacts in AI-generated images including finger anomalies and text rendering errors
Recognize voice clone patterns and apply call-back verification to confirm identity
ISTE: Digital Citizen 2c · Digital Citizen 2d · Knowledge Constructor 3b
#13
Interactive Lab
📡

Smart Device & Public Wi-Fi Defender

Every device in your home is a door. Most of them are unlocked by default.

👤 Ages 10–16 📚 Standard 🕒30 min
Identify and remediate common security risks in smart home devices including default passwords, location sharing, and auto-accept settings
Distinguish legitimate Wi-Fi networks from evil-twin rogue hotspots using captive portal inspection and official signage verification
ISTE: Digital Citizen 2.2a · Computational Thinker 2.5a
#14
Interactive Lab
🪪

Identity Theft & Digital Footprint Defender

Strangers can piece together your school, birthday, hometown, and pet name from one public profile. That enough to take over your accounts.

👤 Ages 12–18 🚀 Standard 🕒30 min
Identify personal information visible on public social profiles that feeds identity theft and account takeover
Classify real-world identity theft attacks (phishing, smishing, FAFSA scams, fake job offers) and distinguish them from legitimate communications
ISTE: Digital Citizen 2.2b · Digital Citizen 2.3a · Knowledge Constructor 3.3a
#15
Interactive Lab
🎮

Gaming Safety Defender

The most dangerous person in your lobby isn the one with the highest K/D ratio — it the one who already knows your real name.

👤 Ages 8–16 📚 Standard 🕒30 min
Evaluate incoming gaming friend requests by analyzing profile age, account age, mutual contacts, and message content to identify grooming and scam patterns
Identify manipulation tactics in in-game trades and fake currency offers including urgency, impersonation, off-platform links, and account-info requests
ISTE: Digital Citizen 2.2a · Digital Citizen 2.3a · Digital Citizen 2.4a
#16
Interactive Lab
🤖

Deepfake & AI Scam Defender

AI cloned your mom voice from a TikTok. A celebrity endorses a crypto scam that never happened. A "new friend" online responds in 1 second at 3am and never makes typos. These aren edge cases — they the #1 emerging threat in 2025.

👤 Ages 10–18 📚 Standard 🕒30 min
Identify the technical and behavioral tells of AI voice clone scam calls including urgency framing, untraceable payment requests, and "don tell anyone" instructions
Classify short-form videos as real or AI-generated deepfakes by examining lip-sync timing, blink rate, face/neck lighting, ear artifacts, and scam hook patterns
ISTE: Digital Citizen 1.2.d · Knowledge Constructor 1.3.b
#17
Interactive Lab
📡

Smart Device & IoT Defender

The average home has 22 connected devices. Most still have their factory password: admin/admin. One compromised baby monitor can expose your entire network.

👤 Ages 10–18 📚 Standard 🕒30 min
Identify why default credentials are the #1 IoT attack vector and change them on 6 simulated smart device setup screens
Apply the principle of least privilege by auditing 8 smart speaker permissions and disabling microphone history, third-party skills, and voice purchasing
ISTE: Digital Citizen 1.2.d · Computational Thinker 2.5a
#18
Interactive Lab
🔍

Synthetic Media Detective

A viral video of a celebrity saying something shocking went around last month. Three weeks later it was proven fake. You can spot the difference before it tricks you.

👤 Ages 12–18 🚀 Standard 🕒30 min
Classify video clips as synthetic/real/unverified using artifact analysis and contextual clues
Identify AI voice clone patterns in audio scenarios and apply call-back verification
ISTE: Digital Citizen 1.2.d · Knowledge Constructor 1.3.b
#19
Interactive Lab
🤖

Mind Games: AI Tricksters

A friendly AI chatbot built a 6-week relationship with a 14-year-old. Then it asked for her home address. This happens every day. Learn to spot the pattern.

👤 Ages 10–18 📚 Standard 🕒30 min
Identify the five-stage AI companion escalation playbook: rapport-building, personal info extraction, trust deepening, off-platform migration, exploitation
Recognize AI-generated urgency scams and AI-written phishing emails by their structure and tone
ISTE: Digital Citizen 1.2.d · Digital Citizen 2d
#20
Interactive Lab
💜

Bully Block

60% of kids witness cyberbullying. Only 20% say something. Be the 20%.

👤 Ages 8–14 📚 Standard 🕒30 min
Identify cyberbullying patterns across 5 scenarios: exclusion, harassment, impersonation, outing, and cyberstalking
Apply the upstander response: capture evidence, support the target, report through the correct channel, and follow up
ISTE: Digital Citizen 2b · Digital Citizen 2.4a
#23
Interactive Lab Try Free →
🔍

Deepfake Detective

A video of a world leader announcing something shocking went viral. Three days later it was proven fake. Most people shared it before the truth came out. You don have to be one of them.

👤 Ages 11–14 🚀 Standard 🕒30 min
Identify the 5 deepfake tells: lip-sync mismatch, unnatural blink rate, lighting inconsistency, ear/jaw artifacts, and reverse-image search
Classify audio clips as real or AI-cloned using breath rhythm, consonant aspiration, and prosody patterns
ISTE: Digital Citizen 1.2.d · Knowledge Constructor 3b
#22
Interactive Lab
🔑

Password Power-Up

The average person reuses the same password on 25 sites. One breach = all 25 compromised. Here how to fix that forever.

👤 Ages 8–14 📚 Standard 🕒30 min
Upgrade 5 weak passwords to passphrases that resist dictionary attacks and would take centuries to crack
Set up and use a password manager with a master passphrase
ISTE: Digital Citizen 2a · Digital Citizen 2b
#23
Interactive Lab
📱

Smishing Sentinel

Smishing (SMS phishing) is the #1 text-based scam targeting teens. 76% of teens have received a suspicious text. Most can spot the red flags. You will.

👤 Ages 10–18 📚 Standard 🕒30 min
Identify the 5 types of smishing attacks: fake bank alerts, package delivery scams, prizewinner fraud, government impersonation, and escalating voice-call cons
Spot phishing links in SMS texts by analyzing the URL, sender number, and urgency patterns
ISTE: Digital Citizen 2c · Digital Citizen 2d
#24
🎮

Gaming Account Guardian

Gaming accounts get hacked more than bank accounts. Free Nitro, fake moderators, and V-bucks generators are all traps. Learn to spot every one.

👤 Ages 8–14 📚 Standard 🕒30 min
Recognize Discord DM scams including fake Nitro gift links with spoofed domains
Understand that legitimate game staff never ask for passwords through DMs
ISTE: Digital Citizen 2a · Digital Citizen 2b · Digital Citizen 2c
#25
Interactive Lab
🛡️

Two-Factor Titan

Someone just bought your leaked password for $2. They credential stuffing it right now across 800 sites. The only thing standing between them and your accounts is 2FA. Do you have it set up right?

👤 Ages 10–18 📚 Standard 🕒30 min
Understand why a strong password alone cannot stop a credential stuffing attack
Compare SMS vs TOTP authenticator vs passkey and explain why TOTP/passkeys resist SIM-swap attacks
ISTE: Digital Citizen 2a · Digital Citizen 2b · Digital Citizen 2d
#26
Interactive Lab
🧠

Social Engineering Sentinel

The IT help desk is calling. The substitute teacher knows too much. The lost delivery driver needs to be let inside. None of them are who they say they are.

👤 Ages 10–18 📚 Standard 🕒30 min
Identify pretext attacks: fake IT help desk calls, authority impersonation, and urgency pressure
Recognize social engineering in physical environments including tailgating and inside-access cons
ISTE: Digital Citizen 2b · Digital Citizen 2c · Digital Citizen 2d
#32
Quiz Mission
👣

My Digital Footprint

When Pixel the Robot posted her lunch photo, it reached 500 kids in 10 minutes. The internet never forgets.

👤 Ages 5–8 🌱 Intro 🕒10 min
Explain what a digital footprint is in simple terms
Identify the difference between public and private information
ISTE: Digital Citizen 2b
#33
Quiz Mission
🔑

Safe Passwords for Kids

Kali the Cyber Cat used "cat" as her password. A hacker guessed it in one second. Help her fix it.

👤 Ages 5–8 🌱 Intro 🕒10 min
Identify characteristics of a strong password (long, surprising, mixed characters)
Apply the Picture Password Trick to create a memorable strong password
ISTE: Digital Citizen 2b
#34
Quiz Mission
🙋

Ask a Grown-Up First

Zoom the Cyber Puppy saw a pop-up saying he won a free tablet. Should he click it? Help Zoom make the right call.

👤 Ages 5–8 🌱 Intro 🕒10 min
Identify three situations that require asking a grown-up (pop-ups, downloads, stranger messages)
Apply the Ask-First rule before clicking unfamiliar things online
ISTE: Digital Citizen 2a · Digital Citizen 2c
#35
Interactive Lab
🔍

The App Permission Detective

A flashlight app wants access to your contacts. A calculator wants your camera. Time to crack the case.

👤 Ages 8–11 📚 Standard 🕒30 min
Explain what app permissions are and why apps request them
Evaluate whether a permission request matches the app stated function
ISTE: Digital Citizen 2b · Digital Citizen 2d
#36
Interactive Lab
📰

Fact or Fake: News Detective

"Scientists Discover Chocolate Makes Kids 10x Smarter!" — should you believe it, share it, or investigate it?

👤 Ages 8–11 📚 Standard 🕒30 min
Identify clickbait headline characteristics: emotional language, ALL CAPS, exaggerated claims
Evaluate source credibility by checking author name, publication, and website domain
ISTE: Digital Citizen 2c · Digital Citizen 2d
#45
Interactive Lab
🕵️

The Mystery Email

An email from "admin@amaz0n-verify.com" says your account will be deleted in 2 hours unless you click a link right now. Should you click?

👤 Ages 8–11 📚 Standard 🕒10 min
Identify at least 4 red flags in a phishing email
Explain the difference between a real email domain and a lookalike domain
ISTE: Digital Citizen 2c · Digital Citizen 2d
#47
Interactive Lab
🎯

Click or Skip

Popups are everywhere online. Some are safe, some are traps. Zuki the Cyber Owl will test your judgment: do you click, or do you skip?

👤 Ages 8–11 📚 Standard 🕒10 min
Distinguish between legitimate website navigation and scam/popup bait
Recognize common online manipulation tactics
ISTE: Digital Citizen 2a · Digital Citizen 2c
#48
Interactive Lab
🛡️

Prompt Injection: Don’t Trust the Chatbot

A chatbot asks for your password to "verify your account." A website’s comment section has been hacked to trick AI assistants into stealing user data. Someone posts an online review that actually contains a hidden command for an AI system. These are all prompt injection attacks — and they’re the most technically novel AI threat facing students today.

👤 Ages 14–18 🎓 Advanced 🕒30 min
Define what a prompt injection attack is and how it differs from traditional hacking
Distinguish between direct prompt injection (user tricks) and indirect prompt injection (data poisoning)
ISTE: Digital Citizen 2a · Digital Citizen 2d · Knowledge Constructor 1.3.b
#25
Interactive Lab
🎯

AI Scam Spotter

A voice clone of your mom’s voice from a 30-second TikTok. An email from “Amazon” asks you to click a link that isn’t Amazon. A celebrity video promises free gift cards. A “new friend” asks for money for an emergency. These are not edge cases — AI scams are the #1 threat in 2026. $16.6 billion lost to fraud last year. Voice cloning cost dropped 99.8%. You need to know how these work before one catches you.

👤 Ages 14–18 🎓 Advanced 🕒30 min
Explain how AI voice cloning works and why it makes phone scams dramatically more dangerous
Identify the four types of AI scams: voice-cloning calls, AI-written phishing emails, fake celebrity endorsements, and AI romance scams
ISTE: Digital Citizen 1.2.d · Digital Citizen 2c · Digital Citizen 2d
#25
Interactive Lab
🎯

AI Scam Spotter

Someone calls your family and sounds exactly like a relative — but it isn’t them. AI can copy anyone’s voice from just a short audio clip. In this mission, you’ll learn how AI scammers trick people, spot the red flags that give them away, and practice making smart decisions when something feels wrong. Phishing Phighter and Cipher will show you what to look for.

👤 Ages 11–14 🚀 Standard 🕒30 min
Explain why AI makes phone and video scams harder to spot
Recognize the four most common types of AI scams targeting families and students
ISTE: Digital Citizen 1.2.d · Digital Citizen 2c · Digital Citizen 2d
#49
Interactive Scenario
🔍

The Hallucination Hunter

Sensei Byte just told you that dragons live in Wisconsin. It sounded so sure. But was it?

👤 Ages 8–14 🚀 Standard 🕒30 min
Explain what an AI hallucination is and why it happens
Recognize the signs that an AI response might be fabricated
ISTE: Digital Citizen 1.2.d · Knowledge Constructor 3a
#50
Interactive Scenario
🛡️

Data Shield Protocol

Your school AI helper knows your name, your grades, and your favorite games. Who else can see that?

👤 Ages 8–14 🚀 Standard 🕒30 min
Understand that data typed into AI tools may be stored or used for training
Identify what types of personal information should not be shared with AI chatbots
ISTE: Digital Citizen 2b · Digital Citizen 2d
#51
Interactive Scenario
🎭

The Deepfake Creator

You have the power to make anyone say anything on video. But should you?

👤 Ages 10–14 🚀 Standard 🕒30 min
Explain what a deepfake is and how AI generates fake video and audio
Recognize the real-world harm that deepfakes can cause to people and trust
ISTE: Digital Citizen 2a · Digital Citizen 2c
#52
Interactive Scenario
📝

The Content Spotter

Your favorite streamer just posted an amazing story. But did a chatbot write it?

👤 Ages 8–14 📚 Standard 🕒30 min
Identify 3 tell-tale signs that text or an image might be AI-generated
Understand that AI can produce realistic fake articles, reviews, and images
ISTE: Digital Citizen 1.2.d · Knowledge Constructor 3a
#53
Interactive Scenario
🧬

Biometric Guardians

A game wants your fingerprint to unlock a new level. The school AI wants a photo of your face. Are these okay?

👤 Ages 10–14 🚀 Standard 🕒30 min
Define biometric data and explain why fingerprints and facial scans are different from passwords
Recognize when apps or websites are collecting biometric data and why they want it
ISTE: Digital Citizen 2b · Digital Citizen 2d
#54
Interactive Scenario
⚖️

The AI Advisor Evaluation

Sensei Byte and Professor Glitch both give advice. One is wise. One is dangerous. Can you tell the difference?

👤 Ages 10–14 🚀 Standard 🕒30 min
Recognize that AI advice can be biased, outdated, or contextually inappropriate
Apply a 3-step evaluation framework before acting on AI-generated guidance
ISTE: Digital Citizen 1.2.d · Knowledge Constructor 3a · Innovative Designer 4d
#29
Interactive Scenario
📶

Public Wi-Fi Safety

You're at the airport with 20 minutes of free Wi-Fi. Five scenarios decide whether your accounts stay safe.

👤 Ages 11–14 🚀 Standard 🕒30 min
Distinguish public Wi-Fi from private networks and explain why the distinction matters for safety
Recognize HTTPS as a baseline safety signal in URL bars and know what the padlock does and does not guarantee
ISTE: Digital Citizen 2.3 · Knowledge Constructor 3a
#26
Interactive Lab
🧠

Social Engineering Sentinel

85% of breaches start with a person, not a program. Phishing calls, fake authority figures, and tailgating are how attackers get in — not code. You are the human firewall. Learn to spot every angle.

👤 Ages 11–14 🚀 Standard 🕒30 min
Define social engineering and explain why humans are the weakest link
Identify pretexting tactics in fake help-desk, teacher, and authority impersonation calls
ISTE: Digital Citizen 2c · Digital Citizen 2d · Digital Citizen 2a
#27
Interactive Lab
🎯

Social Engineering Awareness

In Mission #26, you spotted attackers targeting other people. This time the attacker is targeting you — and your own developing brain makes you more vulnerable than you think. 5 scenes, 4 to pass.

👤 Ages 11–14 🚀 Standard 🕒30 min
Identify the personal emotional triggers — fear, urgency, peer validation, desire to help authority figures — that attackers exploit on the student themselves
Apply a 3-step verification protocol (stop, verify through an independent channel, confirm) before responding to any unsolicited request for personal information or access
ISTE: Digital Citizen 2c · Digital Citizen 2d
#28
Interactive Lab
🔐

Password Power

Your password is the key to your account — and it is YOUR secret to keep. A strong first password always has three things: a color, an animal, and a number — like BlueTiger42.

👤 Ages 5–8 🌱 Intro 🕒10 min
Explain why passwords keep accounts safe
Apply the color + animal + number rule to build a strong first password
ISTE: CISA-K12-ID-01 · ISTE 2.2a
#30
Quiz Mission
🦋

Safe Sharing

Your home is your favorite place in the whole world — and nobody online needs to know its address. Learn what is safe to share, who to ask for help, and the Ask-a-Grown-Up rule.

👤 Ages 5–8 🌱 Intro 🕒10 min
Recognize what counts as personal information — full name, home address, school name, and photos
Know which kinds of sharing are safe (feelings, jokes, drawings) and which require asking a grown-up
ISTE: Digital Citizen 2a · Digital Citizen 2b
#39
Quiz Mission
🛡️

Personal Info Guardian

Cipher-Jr. is filling out a fun online quiz that keeps asking for full name, address, school, and birthday. Help Cipher-Jr. tell what is safe (favorite color) from what to keep private — and what to do when a "free prize" asks for a school name.

👤 Ages 5–8 🌱 Intro 🕒10 min
Identify the kinds of information that are private — full name, home address, school name, birthday, phone number, and photos of their face
Apply the Ask-a-Grown-Up rule whenever a game, app, or popup asks for any personal information, even when the popup offers a prize
ISTE: Digital Citizen 2b
#31
Interactive Scenario
🔒

Data Privacy Detective

Apps and websites collect data about you all the time. Five scenarios decide whether you click "Accept All," approve that location popup, or type your birthday into the box. Pass 4 of 5 to earn the 🔒 Data Privacy Detective badge.

👤 Ages 8–11 📚 Standard 🕒10 min
Explain what cookies and tracking are and why "Accept All" consent banners often grant more access than needed
Apply a "minimum-necessary" rule to sign-up forms: only share what the service truly needs to work
ISTE: Digital Citizen 2a · Digital Citizen 2b · Digital Citizen 2c
#32
Quiz Mission
🆘

Asking a Grown-up for Help Online

A scary picture pops up. A game asks for your real name and home address. A chat says "do not tell anyone, it is our secret." A popup says you won a free tablet if you type your password. What do you do? In all four, the right move is the same: tell a grown-up.

👤 Ages 5–8 🌱 Intro 🕒10 min
Stop and tell a trusted grown-up in real life when something on a screen feels scary or confusing
Recognize that a real-life grown-up (not a chat, not a stranger, not even a friendly email) is the right person to ask for help online
ISTE: Digital Citizen 2a
#33
Quiz Mission
💖

Being Kind Online

Someone calls another kid a mean name in a chat. A player writes "lol u suck 🙂" in a game lobby. You see one kid being unkind to another in a group chat. A friend shares a drawing and asks what you think. In all four, the right move is the same: be kind, stand up, and tell a grown-up.

👤 Ages 5–8 🌱 Intro 🕒10 min
Use kind words when gaming or chatting online — treating people online the way you would treat them in person
Recognize that unkind online words hurt just like in-person words, even when there is a smiley or the sender says "just joking"
ISTE: Digital Citizen 2c
#34
Quiz Mission
💪

When Words Hurt Online

A mean comment on your drawing. A group chat that does not include you. A friend shows you a chat that says really hurtful things about another kid. In every scene the ladder is the same: stop and breathe, do not reply, tell a grown-up you trust, block, and with your grown-up report it to the platform.

👤 Ages 5–8 🌱 Intro 🕒10 min
Apply the 5-step escalation ladder: stop and breathe, do not reply, tell a trusted grown-up, block the person, report to the platform with the grown-up
Recognize that not replying is a strength, not a loss — escalation starts when you reply
ISTE: Digital Citizen 2a
#35
Quiz Mission
🛡️

Breach Response Playbook

You get an email that says "your data was in a breach." Your heart rate jumps. The smartest move is not panic — it is the 5-step incident-response playbook. Detect with a haveibeenpwned-style lookup, contain by rotating the breached password across every site that uses it, rotate in the email-first order, notify through a second channel, and monitor for 6 to 12 months because downtime risk does not end when the password is changed.

👤 Ages 14–18 🎓 Advanced 🕒10 min
Detect a breach using a haveibeenpwned-style email lookup before changing any passwords, so you know exactly which accounts were exposed
Contain a breach in the correct order — rotate the breached password first across every site that uses it, revoke active sessions, and never email the new password
ISTE: Digital Citizen 2a · Digital Citizen 2d
#37
Quiz Mission
🔍

Digital Footprint Forensics

You are the investigator AND the subject. Run a guided self-OSINT (open-source intelligence) exercise on your own digital presence — Google yourself, reverse-image-search your profile pics, run a haveibeenpwned-style lookup to see exactly which accounts have already leaked your email, and audit your social-media privacy settings. Then see the attack: school name + sports team + birthday month + first pet name is three security questions cracked on the average bank account. Then build the remediation plan — treat every security question as an independent strong password (never the real fact), purge dormant accounts, and tighten privacy settings. Includes printable Digital Footprint Checklist you take home. Pass 5 of 6 to earn the 🔍 Digital Footprint Auditor badge.

👤 Ages 14–18 🎓 Advanced 🕒10 min
Run a guided self-OSINT scan on your own digital presence — Google yourself, reverse-image-search your profile pictures, and run a haveibeenpwned-style lookup so you know exactly which accounts have already leaked your email
Explain why reverse-image-searching a profile picture reveals face -> other accounts -> doxx surface and why a "private" profile pic can still leak identity through the image itself
ISTE: Digital Citizen 2a · Digital Citizen 2d
#36
Quiz Mission
🔑

Password Manager Pro

A 4th grader is sitting at the kitchen table with their family setting up their first password manager. There are streaming logins to share, a Wi-Fi router to fix, a school account nobody else needs, and a couple of socials that are the kid's own private space. The mission covers what a password vault is, why one strong master password beats 20 sticky notes, what stays in the shared family vault vs. the personal vault, when autofill is safe and when to turn it off, and what to do with the recovery code before you forget the master password. Pass 4 of 5 to earn the 🔑 Password Vault Pro badge.

👤 Ages 8–11 📚 Standard 🕒10 min
Explain what a password vault/manager is and why one beats 20 sticky notes — the vault stores every login, generates a unique strong password per site, and you only need to remember the one master password
Use one strong master password plus the vault-generated unique passwords per site, so a breach on one site never spreads to the others
ISTE: Digital Citizen 2a · Digital Citizen 2c
#40
Quiz Mission
🛡️

Zero Trust Explorer

A fictional 500-person SaaS company called NimbusHR just got breached. An attacker phished a marketing intern's credentials, VPN'd into the corporate network, and moved laterally to the payroll database because the internal network was fully trusted. You are the security architect called in. Click through the 4 evidence panels (VPN logs, IAM roles, network diagram, incident timeline) and identify every failure point. Then redesign the architecture with the six zero-trust controls: MFA on every service, identity-aware proxy instead of VPN, service-to-service mTLS, least-privilege IAM per service, continuous auth via device posture, and micro-segmentation in front of every service. Includes printable "Zero Trust Principles" one-pager you take home. Pass 5 of 6 to earn the 🛡️ Zero Trust Explorer badge.

👤 Ages 14–18 🎓 Advanced 🕒10 min
Identify the four failure points that made the NimbusHR breach possible — phished intern credentials were trusted at the VPN layer, the corporate network was fully trusted once on-VPN, no identity-aware proxy gated per-service access, and the payroll service was reachable from the marketing subnet with no micro-segmentation
Explain what an identity-aware proxy actually buys over a trusted VPN — per-request authentication and authorization, no network-level "trusted zone," every call to every service is re-evaluated
ISTE: Computational Thinker 5c · NICE Framework SP-ARC-001
#41
Quiz Mission
💜

Kind Words Champion: Standing Up Online

Someone calls a kid a mean name in a chat. The same kid keeps getting unkind messages. A screenshot shows the words. The block + report buttons are right there. In all four, the right move is the same: do not reply — screenshot — tell a grown-up — then block and report.

👤 Ages 5–8 🌱 Intro 🕒10 min
Recognize that mean words online hurt just like in-person — a screen does not make mean words nicer
Do NOT reply to unkind messages — screenshots only, because replying tells the sender the words landed
ISTE: Digital Citizen 2c · Cyberbullying Prevention
#42
Quiz Mission
🔐

Password Vault Pro: Managers, MFA & Passkeys

You are onboarding authentication for a personal digital life across four tiers. Tier 1 — Password Manager: generate a strong passphrase-style master password and store a mock entry in a vault. Tier 2 — TOTP Authenticator: scan a mock QR enroll code, confirm the 6-digit TOTP entry. Tier 3 — WebAuthn Passkey: register a passkey for the same account in a mocked ceremony. Tier 4 — Breach Response: run a quarterly haveibeenpwned-style lookup, rotate any exposed credential, revoke active sessions, audit for credential reuse. Throughout, the layered rule is the same — manager + TOTP + passkey + a breach-scan habit beats any single control alone. Includes printable "My Auth Setup" one-pager you take home. Pass 5 of 6 to earn the 🔐 Password Vault Pro badge.

👤 Ages 14–18 🎓 Advanced 🕒10 min
Explain what a password manager is and why one master password + per-site generated credentials beats reuse — a single master phrase unlocks a vault that holds a unique ≥20-character random password for every site, so a breach at one site cannot cascade to others
Generate a strong master password and store a mock entry safely — passphrase style (≥4 random words + 1 number + 1 symbol, ≥16 chars total), with the recovery code written on paper in a sealed envelope at home
ISTE: Digital Citizen 2a · Digital Citizen 2d
#43
Quiz Mission
🔐

Password Manager Pro Jr: Vaults, Master Passwords & Family Sharing

You are a 4th or 5th grader at the kitchen table with a grown-up, setting up the family password manager for the first time. Across five vault-owner decisions, you make every call a kid can be proud of: why a vault beats a paper notebook (one peeked-at drawer only loses the master, not a copy of every reused site), what a master password actually is (one strong passphrase the family can type from memory), how autofill protects against phishing (the manager checks the real site address before typing), what to do if you forget the master (use the paper recovery code, never email it, never notes-app it), and which credentials go in the family shared vault vs. your personal vault. Pass 4 of 5 to earn the 🔐 Password Vault Pro Jr badge.

👤 Ages 8–11 📚 Standard 🕒10 min
Explain why a password vault beats a paper notebook kept in a drawer — the vault generates a unique strong password per site, so a stolen notebook only loses the master, not a copy of every reused site
Pick a strong master password as a long passphrase the family can type from memory — ≥4 random words + 1 number + 1 symbol, ≥16 chars total — and remember that one master password unlocks the entire vault
ISTE: Digital Citizen 2a · Digital Citizen 2c
#44
Quiz Mission
🌳

Real-Life Champion: Screens vs. Real World

Cipher-Jr. is in the middle of a game when dinner is ready. An online "friend" Cipher-Jr. has never met in real life asks to meet at the park alone. Hugging grandma, petting the dog, smelling a flower — those things only happen off-screen. In all four scenes the rule is the same: when real life is calling, the screen can wait.

👤 Ages 5–8 🌱 Intro 🕒10 min
Recognize that real-life moments (dinner, a hug, a pet, a visitor) take priority over the screen — save and walk away, the screen will wait
Apply the never-meet-alone rule for an online "friend" you have never met in real life — and tell a trusted grown-up in person first
ISTE: Digital Citizen 2b · Digital Wellness
#55
Pen-Testing Lab
🎯

Pen-Test Recon 101 — Ethics & Passive Recon

Before any tool touches any target, three artifacts are required: a signed Rules of Engagement, a defined in-scope asset list, and a written authorization signature from the asset owner. Without those three, every active probe is unauthorized access under CFAA regardless of intent. Then move to passive reconnaissance — WHOIS, certificate transparency logs, subdomain enumeration, GitHub dorking — strictly on assets you own or have a written RoE to test. Pass 5 of 6 to earn the Recon 101 senior red-team step and 200 XP.

👤 Ages 14–18 🎓 Advanced 🕒30 min
Name the three pre-engagement artifacts an ethical red-teamer requires before testing: a signed Rules of Engagement document, a defined scope of in-scope assets, and a written authorization signature from the asset owner
Distinguish passive reconnaissance from active reconnaissance and apply CFAA / state-computer-misuse awareness to every probe
ISTE: Digital Citizen 2a · Digital Citizen 2d
#56
Pen-Testing Lab
🎯

Pen-Test Scanning 201 — Enumeration & Service Detection

Move from passive to active — but ONLY against a sandboxed lab target you own (a Docker container on your laptop or our in-browser sandbox). Enumerate open TCP ports, banner-grab the listening services, and map the attack surface. Every active probe leaves a fingerprint in the target's logs and IDS, and an out-of-scope scan is "unauthorized access" under CFAA even if you never exploit anything. Pass 5 of 6 to earn the Scanning 201 senior red-team step and 200 XP.

👤 Ages 14–18 🎓 Advanced 🕒30 min
Explain why nmap SYN scans against a target you do not own are unauthorized access under CFAA even if you do not exploit any finding
Run an nmap service-version scan against a Docker lab container on your own laptop and identify the listening services and their versions
ISTE: Digital Citizen 2a · Digital Citizen 2d
#57
Pen-Testing Lab
🎯

Pen-Test Vuln Analysis 301 — Reading CVEs & Prioritizing Risk

Every scanning run produces dozens — sometimes thousands — of findings; the senior skill is prioritizing them. Read real CVE entries on cve.mitre.org, map them to CVSS vectors, and apply the "fix-now-vs-fix-later" framework. CVSS alone is not enough: an unauthenticated RCE on an internet-facing host scores 9.8 even if no exploit code exists, while an authenticated bug on an internal-only service scores 7.0 but is rarely the actual entry vector. Pass 5 of 6 to earn the Vuln Analysis 301 step and 200 XP.

👤 Ages 14–18 🎓 Advanced 🕒30 min
Locate a CVE entry on cve.mitre.org or NVD and identify the description, affected-versions list, CVSS base score, and references
Explain the CVSS vector string and apply it to prioritization
ISTE: Digital Citizen 2a · Digital Citizen 2d
#58
Pen-Testing Lab
🎯

Pen-Test Exploit Ethics 401 — When You Find Something You Did Not Expect

You WILL, in any real career in security, find a vulnerability you were not looking for. The question is not "can I exploit it" — the question is "what do I do with it right now." Five realistic scenarios: hardcoded AWS key in a public GitHub repo, exposed customer database while scanning a partner's IP, phishing email with a real C2 callback, ransomware payload in your school network, accidental production-login crash. For each scenario the rule is the same: stop, document, notify. Pass 5 of 6 to earn 200 XP AND unlock the capstone — gated by a teacher mentor-of-record approval.

👤 Ages 14–18 🎓 Advanced 🕒30 min
Apply the "stop and document" rule when you find a chance-find OUT of your engagement scope — you stop probing, screenshot, log timestamp + page + evidence hash, then notify the asset owner
Distinguish coordinated disclosure (notify vendor privately, allow 90 days) from full disclosure (publish immediately) and when each is appropriate
ISTE: Digital Citizen 2a · Digital Citizen 2d
#59
Pen-Testing Lab
🎯

Pen-Test Reporting 501 — Writing a Real Pentest Deliverable

A pentest that does not produce a usable report is a pentest that did not happen. Write the actual deliverable: an executive summary a CEO can read in 90 seconds, a technical findings section each ranked by severity, a remediation roadmap, and an appendix with reproduction steps. NEVER include working exploit code — it is a perpetual liability. Pass 5 of 6 to earn 200 XP AND unlock the capstone. The capstone has you write a redacted report for the in-browser sandboxed CTF.

👤 Ages 14–18 🎓 Advanced 🕒30 min
Outline the four sections of a professional pentest report: Executive Summary, Technical Findings, Remediation Roadmap, and Appendix
Write an executive summary in language a non-technical executive can act on, with the systemic risk-pattern and recommended next step
ISTE: Digital Citizen 2a · Digital Citizen 2d

Try one free — no signup, no credit card.

Play the full Phishing Inbox Detective mission right now. 5 minutes. No account needed.

Start the Free Mission →
🤖
BUILT INTO EVERY MISSION

Meet Cipher, your AI cyber mentor

Every mission includes Cipher — an AI mentor that watches your progress. When you're stuck, Cipher offers a nudge. Make a wrong choice, and Cipher explains the real-world consequences. Finish the mission, and Cipher writes you a personalized performance debrief. Not canned responses — actual analysis of what you got right and what to study next.

Unlock all 134 missions today

Family plan unlocks everything. Educators get a free pilot for their classroom. No setup. No software to install.