Beyond the Inbox: Protecting Staff and Students from Evolving K-12 Phishing
Phishing in K-12 succeeds because it exploits trust, not just technology. Messages that borrow the authority of a district leader, the urgency of a payroll or benefits notice, or the familiarity of a classroom tool consistently outperform technical defenses. Staff remain the foundation of this risk, but the same trust chain now reaches students — a single compromised staff account keeps its authentic address, contacts, and message history, which means closing external student email does not close every path a trusted sender can travel. As AI makes these messages faster to produce and easier to personalize, the gap between filtering and human judgment is widening. Drawing on anonymized data from CyberNut phishing simulations across more than 100 districts, this session examines how staff-targeted attacks work, how student-facing lures still arrive even in closed environments, why AI is changing the scale, speed, and personalization of these attacks, and how to move from phishing training to broader student cyber readiness with five actions districts can take now. In partnership with CyberNut.