What your child will learn
Detect a breach using a haveibeenpwned-style email lookup before changing any passwords, so you know exactly which accounts were exposed
Contain a breach in the correct order — rotate the breached password first across every site that uses it, revoke active sessions, and never email the new password
Rotate credentials in the email-first order: email first because it is the master reset vector, then banking, then social
Recognize credential stuffing as the specific attack where reused passwords across sites get tested automatically
Notify affected accounts through a second channel — text, phone, or in person — never from the same compromised platform
Monitor for identity theft for 6 to 12 months after a breach — credit reports, transaction alerts, and SSN-reuse watch
Build a personal 5-step incident response playbook (detect, contain, rotate, notify, monitor)
How this mission works
You get an email that says "your data was in a breach." The notification names a service you use. Your heart rate jumps. Now what? This mission walks advanced learners through the 5-step personal incident-response playbook: detect with a haveibeenpwned-style lookup to find exactly which accounts were exposed, contain by revoking active sessions and rotating the breached password first across every site that uses it, rotate credentials in the canonical email-first order (because email is the master reset vector for every other account), notify your friend through a second channel when a sketchy DM came from your account, and monitor credit reports and bank alerts for 6 to 12 months after the breach window closes. Includes credential-stuffing recognition, MFA recovery flow with backup codes, and a printable personal playbook you keep. Pass 5 of 6 to earn the Incident Commander badge and 200 XP. Designed for Grades 9 through 12 — server-graded 6-question quiz, advanced reading level, no client-side scene rendering.
What students actually encounter
You receive an email that says "your data was in a breach" from a service you use. What is the smartest FIRST move before you touch any passwords?
You discover your password for the breached service is reused on 4 other sites. What is the correct CONTAINMENT order?
You need to rotate credentials across email, banking, and social. Which account do you rotate FIRST, and why?
Cipher is with them the whole way
When a student gets stuck on Breach Response Playbook, Cipher appears with a mission-specific nudge — no spoilers, just a hint toward the right thinking. Make a wrong choice, and Cipher explains the real-world consequence. Finish the mission, and Cipher generates a personalized performance debrief based on exactly how the student played it.
ISTE alignment
Advanced learners build a personal 5-step breach-response playbook — detect with a haveibeenpwned-style lookup, contain via session revocation and password rotation, rotate in email-first order, notify through a second channel, and monitor for 6 to 12 months of downstream identity-theft risk. Aligned to ISTE Digital Citizen 2a (advocate for safe digital behaviors) and 2d (understand threats and vulnerabilities).