Start with a simple definition
A useful explanation is: phishing is when someone sends a message that pretends to be from a person, game, school, service or company you trust so they can persuade you to click, sign in, share information or send something valuable.
Children do not need a technical explanation of email headers or domain registration to understand the idea. They need to recognise the behaviour of the trick. The message may look familiar, but the sender is trying to borrow someone else's trust.
Teach the warning signs without creating fear
A suspicious message often tries to create a strong feeling first: panic, excitement, curiosity or pressure. That emotional reaction is useful to the scammer because it encourages a fast decision.
Instead of teaching children that every strange message is a scam, teach them to notice combinations of warning signs.
- It says something bad will happen immediately unless they act.
- It promises a prize, reward, free item or special access that seems unexpected.
- It asks for a password, verification code, payment, gift card or personal information.
- It contains a link and tells them they must use that link to fix the problem.
- It appears to come from someone they know, but the wording or request feels unusual.
Give them a safer replacement action
Telling a child 'do not click suspicious links' is useful, but it is stronger when they also know what to do instead. The replacement action should be easy enough to remember under pressure.
A good rule is: do not use the message to prove the message is real. If an account warning arrives, open the real app or website yourself. If a friend sends an unusual request, contact that friend another way. If the message involves school, ask a teacher or parent using a contact method you already trust.
Practise with everyday examples
Short scenarios work better than long lectures. Ask what they would do if a gaming message said their account would be deleted, if a classmate suddenly asked for a sign-in code, or if a delivery text arrived when they were not expecting a parcel.
The useful part is not whether they guess 'phishing' correctly. The useful part is whether they slow down, question the message and choose a trusted way to check.
What if they already clicked?
Children should know that hiding a mistake usually makes the situation harder to fix. If they clicked a suspicious link, entered a password or shared a sign-in code, the best next step is to tell a trusted adult promptly.
The adult can help close the page, change affected passwords, sign out other sessions, check account recovery details and contact the service or school if needed. The lesson should be about recovery and better decisions next time, not punishment for admitting what happened.
The Ranger version is simple: question the message, check through a trusted route, verify before acting and ask for help when unsure.
Continue with the Cyber Safety Hub, practise the ideas in Ranger Academy, or use the free printable resources at home or in the classroom.