Cybersecurity Awareness
For Staff · Tech Tips · Cybersecurity
You Are Our First Line of Defense
Schools are a favorite target, and most attacks start with an email that looks harmless. One click can open a fake login page or quietly install malware. This page is what to watch for, what to do, and who to call.
AI has made scam emails harder to spot and easier to send. The two attacks we see most are stolen login credentials and ransomware — and the best defense against both is a staff that pauses, checks, and reports.
Companion guides: Fake Invoices, Gift Cards, and Impostors · Security at Home and on Your Phone · Passwords and Two-Step Verification
Suspicious email? Report it — don’t reply, forward, or click.
Use the Phish Alert Report button on the Outlook ribbon or in Webmail. One click sends the email to Technology and removes it from your inbox. Not in Outlook? Open a ticket instead. We would much rather look at ten harmless emails than miss one.
The Technology Department Will Never
Ask for your password or a verification code — not by phone, email, or text. Threaten to close your account unless you click a link today. Ask you to buy gift cards or send money. Change your payroll or bank details from an email. If a message does any of these, it isn’t from us — report it.
Phishing: Spot It, Report It
Phishing is an email — or a text, or a call — that pretends to be from someone you trust: a bank, a vendor, a coworker, even the Technology Department. The goal is to get you to hand over a password, click a link, or send money. It is the most common attack there is, and it works because it looks ordinary. (More background in KnowBe4’s phishing overview.)
Sources: Microsoft Cyber Signals (education was the third most targeted industry in analyzed events, Q2 2024) and the KnowBe4 Phishing Threat Trends Report, March 2025. The three words that appear most often in phishing emails: urgent, review, sign.
Where to Look and What Gives It Away
| Part of the email | Red flags |
|---|---|
| From | An address you don’t recognize; a display name that doesn’t match the address behind it; a sender you know, but the message is unexpected or out of character. Real vendors and coworkers email you from their own address, every time. |
| To | You were copied along with people you don’t know, or the message isn’t addressed to anyone by name. |
| Date | Sent at an odd hour (3 a.m.) or on a day that doesn’t fit the sender’s normal habits. |
| Subject | Irrelevant to the message, a reply to something you never sent, or a pile of reference numbers designed to look like a system generated it. |
| Links | Hover shows a different address than the text says; a misspelled or look-alike domain; a shortened link that hides where it goes; a link that is the entire message. |
| Attachments | Anything you weren’t expecting — especially invoices, “shared documents,” ZIP files, or HTML files. The external-sender banner covers everything under it. |
| Content | Urgency and consequences (“within 24 hours”); a request for a password, gift cards, banking changes, or staff information; a pasted-in “approval” from the boss; bad grammar — or, increasingly, perfect grammar with a story that doesn’t add up. |
The best AI-written scams have perfect spelling and a believable back-story. Watching for typos no longer works on its own — the lie is in the story, and only a person can catch that.
What the Red Banner Means
Email from outside the district is tagged [EXTERNAL] in the subject and carries a red banner: “This email was sent from outside of Noble Schools. Please use caution when clicking on links or attachments.” It means exactly one thing: the whole message came from outside — including everything pasted under the banner. A “reply from Mr. Solomon” sitting below it arrived in that same outside email; a real reply from him would be in his mailbox, not a stranger’s.
The banner does not mean an email is dangerous — parents, vendors, and your KnowBe4 training invitations all arrive with it. And no banner does not mean safe: when a coworker’s account is broken into, the scammer’s mail comes from inside, with no warning at all. Judge the request, not the banner.
When a Suspicious Email Lands in Your Inbox
Do
- Pause. Anything involving money, bank details, gift cards, passwords, or staff information gets a second look — especially if it wants you to hurry.
- Check the sender’s actual email address and hover over every link.
- Ask the person it claims to be from — in person, or by calling a number you already have. “Did you send this?” takes ten seconds.
- Report it with the Phish Alert Report button. Not in Outlook? Open a ticket.
- Already clicked, typed a password, or sent something? Skip to If You Clicked.
Don’t
- Don’t reply. If the account was compromised, the person who answers won’t be who you expect — and a reply tells the scammer they found a live target.
- Don’t forward it to a coworker for a second opinion. Now two people can click the link.
- Don’t just mark it as spam. That hides the email; it doesn’t tell us anyone else received it.
- Don’t call a phone number that appears in the email — even if you do business with the company named. Look the number up yourself.
- Don’t open unexpected attachments or click links to “confirm,” “review,” or “sign” anything you didn’t ask for.
How to Report with Phish Alert
-
Open the suspicious email, but don’t click anything in it
Reading the message is safe. Links, attachments, and “unsubscribe” buttons are not.
-
Click the Phish Alert Report button
It is on the Outlook ribbon on district computers and in the Webmail toolbar. Confirm when it asks.
-
That’s it — the email goes to Technology and leaves your inbox
We review it, block the sender, and check who else received it. If it turns out to be harmless, we’ll let you know.
Some of the phishing emails you get are ours. We regularly send simulated phishing emails so everyone gets practice spotting the real thing. Reporting one of ours with the Phish Alert Report button counts as a win — that is exactly the habit we are building.
If You Clicked
It happens to careful people — even experts get fooled sometimes. What matters now is speed, not embarrassment. Nobody gets in trouble for reporting fast; the only mistake is waiting.
Did a File Open or a Download Start?
Unplug first: pull the Ethernet cable from the back of the computer or turn Wi-Fi off, then leave the computer alone and go straight to calling us. It’s the same first move as a suspected ransomware infection.
-
Stop, and don’t try to fix it quietly
Don’t reply, don’t keep clicking to see what happens, and don’t investigate on your own. Just note what you clicked, what you typed, and roughly when.
-
If you typed a password, change it right away
On a district Windows computer, press Ctrl+Alt+Delete and choose Change a password; or, while you’re on the school network, use the district password reset page. Then change it on any other site where you used the same password. Stuck? Call us and we’ll reset it with you.
-
Tell Technology the same hour
Call (405) 872-3452, dial extension 7800 from a district phone, or open a ticket from another device. If money or information already went out, say that first — banks can sometimes stop a wire in the first few hours.
-
Still report the email with Phish Alert
Even now. It tells us exactly what to block and who else received it.
-
Watch for what comes next
Tap Deny on any two-step sign-in prompt you didn’t start. Tell us if you see inbox rules or forwarding you didn’t set up, or if coworkers say they got odd email “from you.” If you don’t have two-step verification on yet, set it up today.
If it was a personal account or your own credit card, also report it on the Federal Trade Commission’s identity theft recovery site.
Ransomware
Ransomware is malicious software that locks up your files — on your computer, your phone, even your Google Drive or OneDrive — until a ransom is paid. For a school district it means days without systems and files that may never come back. It usually gets in through a phishing link or attachment, a computer that missed a security update, or a stolen password — so let your computer restart for updates when it asks.
In the education sector, phishing remains the most commonly reported root cause, accounting for 22% of incidents. However, the four main attack vectors — phishing, malicious emails, exploited vulnerabilities, and compromised credentials — are each within 3% of one another. Source: The State of Ransomware in Education 2025, Sophos.
If You Think Your Computer Is Infected
Speed matters more than certainty. If you see a ransom message, files that suddenly won’t open, or strange pop-ups, follow these steps immediately.
-
Unplug the computer from the network
Remove the blue, black, or gray Ethernet cable from the back of the computer. On a laptop, turn Wi-Fi off too.
-
Take a picture of any messages on your screen
Use your phone. The exact wording and any addresses shown help us identify what hit you.
-
Power off and unplug the computer
If it will not shut down like normal, just pull the power plug for your computer tower from the wall.
-
Notify Technology immediately
Call (405) 872-3452 (extension 7800 from a district phone) or open a ticket from another device. Give us any details on what you saw.
-
Do not turn the computer back on
Leave it off until the Technology team has cleared it for use.
Keep a Current Backup of Your Documents
Backing up your own documents is up to you — if a computer is infected, everything on it is lost. Copy your documents to a flash drive and keep it unplugged, and back up your OneDrive and Google Drive too, since ransomware can lock those as well. If you can’t afford to lose it and can’t recreate it, back it up regularly.
In the Classroom and Office
Not every risk arrives by email. Your gradebook, your inbox, and student records are open on a screen in a room full of people every day. A few habits keep them yours.
- Lock your screen when you step away. Windows key + L. Even for a minute, even to the door.
- Don’t open email while you’re projecting. Freeze or blank the SMART Board, or stop sharing, before you check mail. A parent’s message or a student’s IEP on a 75-inch screen is a privacy breach.
- Students never use your logged-in computer. If a student needs a computer, they sign in with their own account. Your login is your gradebook.
- Found a USB drive? Bring it to Technology. Don’t plug it in to see whose it is. A planted drive is a classic way to install malware.
- Sign out of shared and lab computers. And never save a password in the browser on a machine that isn’t yours.
- Paper counts too. Rosters, printed passwords, and student information left on a desk or in the copier tray are as exposed as an open screen. Shred what you don’t need.
- Visitors check in at the front office. Don’t hold a secure door for someone you don’t recognize — point them to the office instead.
More Guides
Three companion pages go deeper on the scams that cost the most, the habits that protect your own devices, and the two-step verification that protects your accounts.
Your Training: KnowBe4
We use KnowBe4, a leader in security awareness training, for short, practical lessons built for teachers and office staff: how to recognize and respond to phishing, ransomware, and the person-to-person tricks scammers rely on, plus newer modules on AI and deepfakes. What you learn protects your own accounts at home as much as the district’s.
This Email Is Legitimate
When you are enrolled, the invitation comes from Knowbe4 Training <support@nobleps.com> with the subject “[EXTERNAL] You’ve been enrolled in training.” It is safe to click. KnowBe4 uses a login link instead of a password: enter your email address and you’ll receive a secure sign-in link by email.
- No certificates to print, no PD points to submit. The system records your completion automatically.
- Short modules, on your schedule. Each one takes a few minutes; finish them before the due date in your enrollment email.
- Expect practice phishing emails. Simulated phishing is part of the program. Report them with the Phish Alert Report button just like the real thing.
Handouts and Downloads
One-page flyers from KnowBe4’s security team, plus our own breakdown of the fake-invoice email. Print them for the workroom or keep them handy.
Phishing and Email Scams
- The Email That Could Have Cost Us $49,760 — Noble Technology’s four-page breakdown of the September 2026 fake invoice
- Be On the Lookout for Phishing — the three signs: mysterious messages, urgent demands, sneaky links
- You Are a Target — social engineering by email, phone, and in person, with the seven places to check in an email
- Multi-Stage Vishing — the email-plus-phone-call scam
- Cybercrime Happens Way More Than You Think — a cyberattack every 36 seconds
- Cybersmart Safety Tips — phishing, business email compromise, pretexting, chatbots, social media
AI and Deepfakes
- The Dangers of AI Art and Deepfakes
- What Are AI Chatbots? — five security tips for using them at work
Home and Mobile
- How Secure Is Your Mobile Device?
- 20 Ways to Block Mobile Attacks — Wi-Fi, apps, browser, Bluetooth, texts, calls
- QR Codes: Enjoy Safe Scanning
Something Look Off? Ask.
Report suspicious email with the Phish Alert Report button, or open a ticket and we’ll take a look. You can always reach the Technology Department at (405) 872-3452 or extension 7800 from a district phone. More guides live in the Help Center.
More tech tips: Tech Tips · Fake Invoices & Impostors · Security at Home · Passwords & Two-Step Verification · Staff Personal Devices · ChatGPT for Teachers · GoGuardian Teacher · Meet Your SMART Board · Get to Know Your Phone · Get More Out of Your Monitor
-
Anatomy of a Fake Invoicepdf
-
Be On Lookout Phishing Red Flagspdf
-
Cybercrime Happens Way More Than You Thinkpdf
-
Cybersmart Safety Tipspdf
-
How To Block Mobile Attackspdf
-
Multi Stage Vishingpdf
-
QR Codes Enjoy Safe Scanningpdf
-
Security Hints and Tips Dangers AI Art Deepfakespdf
-
Security Hints and Tips How Secure Mobile Devicepdf
-
What Are AI Chatbotspdf
-
You Are A Targetpdf
