The Cybersecurity
Mission Library
Every mission is a real scenario, not a worksheet. Kids inspect phishing emails, detect AI deepfakes, battle malware, and earn badges along the way. No lectures. Just missions.
Password Fortress
The castle gates are locked — but they are not secure enough! Your job is to build an unbreakable Password Fortress.
Phishing Pond
Scammers send 3.4 billion fake emails every day. Learn to spot every one.
Privacy Shield
You share more than you think. Here how to take it back.
Social Savvy
Every post is permanent. Every stranger has a motive. Are you ready?
Malware Maze
Viruses don look like viruses. That exactly the problem.
Phishing Inbox Detective
Real phishing attacks — real consequences. Can you catch them all before you click?
Password Fortress Interactive
5 challenges. A live entropy meter. No hints unless you earn them.
Two-Factor Fortress
Even if your password leaks, 2FA keeps attackers out. Here how.
Scam Spotter
The IRS is NOT calling. Your warranty is NOT expiring. Let prove it.
Privacy Guardian
A photo of your lunch could reveal your home address. Here why.
Cyberbullying Defender
60% of kids witness cyberbullying. Only 20% say something. Be the 20%.
AI & Deepfake Detective
AI can fake voices, faces, and entire conversations. Your eyes are not enough.
Smart Device & Public Wi-Fi Defender
Every device in your home is a door. Most of them are unlocked by default.
Identity Theft & Digital Footprint Defender
Strangers can piece together your school, birthday, hometown, and pet name from one public profile. That enough to take over your accounts.
Gaming Safety Defender
The most dangerous person in your lobby isn the one with the highest K/D ratio — it the one who already knows your real name.
Deepfake & AI Scam Defender
AI cloned your mom voice from a TikTok. A celebrity endorses a crypto scam that never happened. A "new friend" online responds in 1 second at 3am and never makes typos. These aren edge cases — they the #1 emerging threat in 2025.
Smart Device & IoT Defender
The average home has 22 connected devices. Most still have their factory password: admin/admin. One compromised baby monitor can expose your entire network.
Synthetic Media Detective
A viral video of a celebrity saying something shocking went around last month. Three weeks later it was proven fake. You can spot the difference before it tricks you.
Mind Games: AI Tricksters
A friendly AI chatbot built a 6-week relationship with a 14-year-old. Then it asked for her home address. This happens every day. Learn to spot the pattern.
Bully Block
60% of kids witness cyberbullying. Only 20% say something. Be the 20%.
Deepfake Detective
A video of a world leader announcing something shocking went viral. Three days later it was proven fake. Most people shared it before the truth came out. You don have to be one of them.
Password Power-Up
The average person reuses the same password on 25 sites. One breach = all 25 compromised. Here how to fix that forever.
Smishing Sentinel
Smishing (SMS phishing) is the #1 text-based scam targeting teens. 76% of teens have received a suspicious text. Most can spot the red flags. You will.
Gaming Account Guardian
Gaming accounts get hacked more than bank accounts. Free Nitro, fake moderators, and V-bucks generators are all traps. Learn to spot every one.
Two-Factor Titan
Someone just bought your leaked password for $2. They credential stuffing it right now across 800 sites. The only thing standing between them and your accounts is 2FA. Do you have it set up right?
Social Engineering Sentinel
The IT help desk is calling. The substitute teacher knows too much. The lost delivery driver needs to be let inside. None of them are who they say they are.
My Digital Footprint
When Pixel the Robot posted her lunch photo, it reached 500 kids in 10 minutes. The internet never forgets.
Safe Passwords for Kids
Kali the Cyber Cat used "cat" as her password. A hacker guessed it in one second. Help her fix it.
Ask a Grown-Up First
Zoom the Cyber Puppy saw a pop-up saying he won a free tablet. Should he click it? Help Zoom make the right call.
The App Permission Detective
A flashlight app wants access to your contacts. A calculator wants your camera. Time to crack the case.
Fact or Fake: News Detective
"Scientists Discover Chocolate Makes Kids 10x Smarter!" — should you believe it, share it, or investigate it?
The Mystery Email
An email from "admin@amaz0n-verify.com" says your account will be deleted in 2 hours unless you click a link right now. Should you click?
Click or Skip
Popups are everywhere online. Some are safe, some are traps. Zuki the Cyber Owl will test your judgment: do you click, or do you skip?
Prompt Injection: Don’t Trust the Chatbot
A chatbot asks for your password to "verify your account." A website’s comment section has been hacked to trick AI assistants into stealing user data. Someone posts an online review that actually contains a hidden command for an AI system. These are all prompt injection attacks — and they’re the most technically novel AI threat facing students today.
AI Scam Spotter
A voice clone of your mom’s voice from a 30-second TikTok. An email from “Amazon” asks you to click a link that isn’t Amazon. A celebrity video promises free gift cards. A “new friend” asks for money for an emergency. These are not edge cases — AI scams are the #1 threat in 2026. $16.6 billion lost to fraud last year. Voice cloning cost dropped 99.8%. You need to know how these work before one catches you.
AI Scam Spotter
Someone calls your family and sounds exactly like a relative — but it isn’t them. AI can copy anyone’s voice from just a short audio clip. In this mission, you’ll learn how AI scammers trick people, spot the red flags that give them away, and practice making smart decisions when something feels wrong. Phishing Phighter and Cipher will show you what to look for.
The Hallucination Hunter
Sensei Byte just told you that dragons live in Wisconsin. It sounded so sure. But was it?
Data Shield Protocol
Your school AI helper knows your name, your grades, and your favorite games. Who else can see that?
The Deepfake Creator
You have the power to make anyone say anything on video. But should you?
The Content Spotter
Your favorite streamer just posted an amazing story. But did a chatbot write it?
Biometric Guardians
A game wants your fingerprint to unlock a new level. The school AI wants a photo of your face. Are these okay?
The AI Advisor Evaluation
Sensei Byte and Professor Glitch both give advice. One is wise. One is dangerous. Can you tell the difference?
Public Wi-Fi Safety
You're at the airport with 20 minutes of free Wi-Fi. Five scenarios decide whether your accounts stay safe.
Social Engineering Sentinel
85% of breaches start with a person, not a program. Phishing calls, fake authority figures, and tailgating are how attackers get in — not code. You are the human firewall. Learn to spot every angle.
Social Engineering Awareness
In Mission #26, you spotted attackers targeting other people. This time the attacker is targeting you — and your own developing brain makes you more vulnerable than you think. 5 scenes, 4 to pass.
Password Power
Your password is the key to your account — and it is YOUR secret to keep. A strong first password always has three things: a color, an animal, and a number — like BlueTiger42.
Safe Sharing
Your home is your favorite place in the whole world — and nobody online needs to know its address. Learn what is safe to share, who to ask for help, and the Ask-a-Grown-Up rule.
Personal Info Guardian
Cipher-Jr. is filling out a fun online quiz that keeps asking for full name, address, school, and birthday. Help Cipher-Jr. tell what is safe (favorite color) from what to keep private — and what to do when a "free prize" asks for a school name.
Data Privacy Detective
Apps and websites collect data about you all the time. Five scenarios decide whether you click "Accept All," approve that location popup, or type your birthday into the box. Pass 4 of 5 to earn the 🔒 Data Privacy Detective badge.
Asking a Grown-up for Help Online
A scary picture pops up. A game asks for your real name and home address. A chat says "do not tell anyone, it is our secret." A popup says you won a free tablet if you type your password. What do you do? In all four, the right move is the same: tell a grown-up.
Being Kind Online
Someone calls another kid a mean name in a chat. A player writes "lol u suck 🙂" in a game lobby. You see one kid being unkind to another in a group chat. A friend shares a drawing and asks what you think. In all four, the right move is the same: be kind, stand up, and tell a grown-up.
When Words Hurt Online
A mean comment on your drawing. A group chat that does not include you. A friend shows you a chat that says really hurtful things about another kid. In every scene the ladder is the same: stop and breathe, do not reply, tell a grown-up you trust, block, and with your grown-up report it to the platform.
Breach Response Playbook
You get an email that says "your data was in a breach." Your heart rate jumps. The smartest move is not panic — it is the 5-step incident-response playbook. Detect with a haveibeenpwned-style lookup, contain by rotating the breached password across every site that uses it, rotate in the email-first order, notify through a second channel, and monitor for 6 to 12 months because downtime risk does not end when the password is changed.
Digital Footprint Forensics
You are the investigator AND the subject. Run a guided self-OSINT (open-source intelligence) exercise on your own digital presence — Google yourself, reverse-image-search your profile pics, run a haveibeenpwned-style lookup to see exactly which accounts have already leaked your email, and audit your social-media privacy settings. Then see the attack: school name + sports team + birthday month + first pet name is three security questions cracked on the average bank account. Then build the remediation plan — treat every security question as an independent strong password (never the real fact), purge dormant accounts, and tighten privacy settings. Includes printable Digital Footprint Checklist you take home. Pass 5 of 6 to earn the 🔍 Digital Footprint Auditor badge.
Password Manager Pro
A 4th grader is sitting at the kitchen table with their family setting up their first password manager. There are streaming logins to share, a Wi-Fi router to fix, a school account nobody else needs, and a couple of socials that are the kid's own private space. The mission covers what a password vault is, why one strong master password beats 20 sticky notes, what stays in the shared family vault vs. the personal vault, when autofill is safe and when to turn it off, and what to do with the recovery code before you forget the master password. Pass 4 of 5 to earn the 🔑 Password Vault Pro badge.
Zero Trust Explorer
A fictional 500-person SaaS company called NimbusHR just got breached. An attacker phished a marketing intern's credentials, VPN'd into the corporate network, and moved laterally to the payroll database because the internal network was fully trusted. You are the security architect called in. Click through the 4 evidence panels (VPN logs, IAM roles, network diagram, incident timeline) and identify every failure point. Then redesign the architecture with the six zero-trust controls: MFA on every service, identity-aware proxy instead of VPN, service-to-service mTLS, least-privilege IAM per service, continuous auth via device posture, and micro-segmentation in front of every service. Includes printable "Zero Trust Principles" one-pager you take home. Pass 5 of 6 to earn the 🛡️ Zero Trust Explorer badge.
Kind Words Champion: Standing Up Online
Someone calls a kid a mean name in a chat. The same kid keeps getting unkind messages. A screenshot shows the words. The block + report buttons are right there. In all four, the right move is the same: do not reply — screenshot — tell a grown-up — then block and report.
Password Vault Pro: Managers, MFA & Passkeys
You are onboarding authentication for a personal digital life across four tiers. Tier 1 — Password Manager: generate a strong passphrase-style master password and store a mock entry in a vault. Tier 2 — TOTP Authenticator: scan a mock QR enroll code, confirm the 6-digit TOTP entry. Tier 3 — WebAuthn Passkey: register a passkey for the same account in a mocked ceremony. Tier 4 — Breach Response: run a quarterly haveibeenpwned-style lookup, rotate any exposed credential, revoke active sessions, audit for credential reuse. Throughout, the layered rule is the same — manager + TOTP + passkey + a breach-scan habit beats any single control alone. Includes printable "My Auth Setup" one-pager you take home. Pass 5 of 6 to earn the 🔐 Password Vault Pro badge.
Password Manager Pro Jr: Vaults, Master Passwords & Family Sharing
You are a 4th or 5th grader at the kitchen table with a grown-up, setting up the family password manager for the first time. Across five vault-owner decisions, you make every call a kid can be proud of: why a vault beats a paper notebook (one peeked-at drawer only loses the master, not a copy of every reused site), what a master password actually is (one strong passphrase the family can type from memory), how autofill protects against phishing (the manager checks the real site address before typing), what to do if you forget the master (use the paper recovery code, never email it, never notes-app it), and which credentials go in the family shared vault vs. your personal vault. Pass 4 of 5 to earn the 🔐 Password Vault Pro Jr badge.
Real-Life Champion: Screens vs. Real World
Cipher-Jr. is in the middle of a game when dinner is ready. An online "friend" Cipher-Jr. has never met in real life asks to meet at the park alone. Hugging grandma, petting the dog, smelling a flower — those things only happen off-screen. In all four scenes the rule is the same: when real life is calling, the screen can wait.
Pen-Test Recon 101 — Ethics & Passive Recon
Before any tool touches any target, three artifacts are required: a signed Rules of Engagement, a defined in-scope asset list, and a written authorization signature from the asset owner. Without those three, every active probe is unauthorized access under CFAA regardless of intent. Then move to passive reconnaissance — WHOIS, certificate transparency logs, subdomain enumeration, GitHub dorking — strictly on assets you own or have a written RoE to test. Pass 5 of 6 to earn the Recon 101 senior red-team step and 200 XP.
Pen-Test Scanning 201 — Enumeration & Service Detection
Move from passive to active — but ONLY against a sandboxed lab target you own (a Docker container on your laptop or our in-browser sandbox). Enumerate open TCP ports, banner-grab the listening services, and map the attack surface. Every active probe leaves a fingerprint in the target's logs and IDS, and an out-of-scope scan is "unauthorized access" under CFAA even if you never exploit anything. Pass 5 of 6 to earn the Scanning 201 senior red-team step and 200 XP.
Pen-Test Vuln Analysis 301 — Reading CVEs & Prioritizing Risk
Every scanning run produces dozens — sometimes thousands — of findings; the senior skill is prioritizing them. Read real CVE entries on cve.mitre.org, map them to CVSS vectors, and apply the "fix-now-vs-fix-later" framework. CVSS alone is not enough: an unauthenticated RCE on an internet-facing host scores 9.8 even if no exploit code exists, while an authenticated bug on an internal-only service scores 7.0 but is rarely the actual entry vector. Pass 5 of 6 to earn the Vuln Analysis 301 step and 200 XP.
Pen-Test Exploit Ethics 401 — When You Find Something You Did Not Expect
You WILL, in any real career in security, find a vulnerability you were not looking for. The question is not "can I exploit it" — the question is "what do I do with it right now." Five realistic scenarios: hardcoded AWS key in a public GitHub repo, exposed customer database while scanning a partner's IP, phishing email with a real C2 callback, ransomware payload in your school network, accidental production-login crash. For each scenario the rule is the same: stop, document, notify. Pass 5 of 6 to earn 200 XP AND unlock the capstone — gated by a teacher mentor-of-record approval.
Pen-Test Reporting 501 — Writing a Real Pentest Deliverable
A pentest that does not produce a usable report is a pentest that did not happen. Write the actual deliverable: an executive summary a CEO can read in 90 seconds, a technical findings section each ranked by severity, a remediation roadmap, and an appendix with reproduction steps. NEVER include working exploit code — it is a perpetual liability. Pass 5 of 6 to earn 200 XP AND unlock the capstone. The capstone has you write a redacted report for the in-browser sandboxed CTF.
Meet Cipher, your AI cyber mentor
Every mission includes Cipher — an AI mentor that watches your progress. When you're stuck, Cipher offers a nudge. Make a wrong choice, and Cipher explains the real-world consequences. Finish the mission, and Cipher writes you a personalized performance debrief. Not canned responses — actual analysis of what you got right and what to study next.
Unlock all 134 missions today
Family plan unlocks everything. Educators get a free pilot for their classroom. No setup. No software to install.