Skip to content

Latest commit

 

History

History
141 lines (105 loc) · 7.95 KB

File metadata and controls

141 lines (105 loc) · 7.95 KB

Learner Guide: Navigating Digital Threats: Proactive Measures Against Cyber Frauds and Scams

Course code: TGS-2024043420
Version: v9.0
Release date: 7 September 2026

Learning Outcomes

  • LO1 Identify potential cyber security risks and threats, including internet frauds and scams.
  • LO2 Protect personal and business information from internet frauds and scams.
  • LO3 Interpret and escalate cyber frauds and scams to relevant authorities.

Detailed Activities

Activity 1: Scam Signal Triage

Classify a suspicious contact using channel, claim, pressure, requested action and payment route.

  1. Open the supplied message pack and assign each item an evidence ID.
  2. Record the claimed sender, channel, callback details, URL and requested action.
  3. Mark authority, urgency, scarcity, fear, reward and secrecy pressure cues.
  4. Identify the asset at risk: credentials, money, device access, identity or business data.
  5. Trace the proposed payment or access route and note reversibility.
  6. Score likelihood and impact from 1 to 5 using the worksheet rubric.
  7. Choose block, verify, monitor or escalate and state the evidence for the choice.
  8. Peer-review one classification and revise unsupported assumptions.

Evidence: Completed signal matrix with risk score and decision rationale. Acceptance: Every decision cites at least two observable indicators; no decision relies only on spelling or grammar.

Activity 2: Phishing URL and Header Analysis

Inspect a simulated phishing message without opening its link or attachment.

  1. Work only from the supplied offline email sample and URL text file.
  2. Compare the display name with the From and Reply-To domains.
  3. Read Received hops from bottom to top and identify the first untrusted handoff.
  4. Check SPF, DKIM and DMARC results recorded in Authentication-Results.
  5. Decompose the URL into scheme, host, registrable domain, path and query.
  6. Flag punycode, look-alike characters, subdomain deception and redirect parameters.
  7. Write an independent verification route using a known bookmark or official directory.
  8. Capture the findings in the evidence template and assign a disposition.

Evidence: Annotated header and URL decomposition with disposition. Acceptance: The registrable domain and authentication result are stated correctly and no live suspect link is opened.

Activity 3: Independent Verification Drill

Break the scammer-controlled channel and verify a claim through trusted contact data.

  1. Select one impersonation scenario from the activity pack.
  2. List every contact path supplied by the sender and treat it as untrusted.
  3. Locate an official contact route from a saved statement, app, card or typed official domain.
  4. Draft a neutral verification script that reveals no OTP, password or account PIN.
  5. Verify the claimed event, transaction or officer identity through the official route.
  6. Record who was contacted, when, which reference was checked and the response.
  7. Decide whether to block, continue cautiously or escalate.
  8. Explain which trust boundary changed when you moved to the independent channel.

Evidence: Verification log and trust-boundary explanation. Acceptance: No sender-provided telephone number, link or QR code is used for verification.

Activity 4: Account and Device Hardening

Apply layered safeguards that reduce credential, session and malware-enabled fraud.

  1. Inventory two high-value accounts and the recovery channels attached to them.
  2. Replace any reused password with unique password-manager-generated credentials.
  3. Enable a phishing-resistant sign-in method or app-based MFA where available.
  4. Review active sessions, trusted devices, forwarding rules and recovery details.
  5. Enable automatic updates and verify the operating system security patch level.
  6. Disable installation from unknown sources and remove unneeded remote-access tools.
  7. Configure transaction notifications and a low-risk transfer limit for the exercise account.
  8. Record before-and-after settings without exposing secrets or recovery codes.

Evidence: Hardening checklist with redacted screenshots and residual risks. Acceptance: Credentials and recovery codes are absent; each control names the attack path it interrupts.

Activity 5: ScamShield Check and Report

Use ScamShield resources to check and report a simulated suspicious message safely.

  1. Open the official ScamShield site by typing the known government URL.
  2. Review the current Check for Scams and reporting options.
  3. Prepare the supplied simulated message, number and URL for checking.
  4. Submit only the fictional training data supplied in the activity pack.
  5. Record the result, confidence language and any follow-up advice.
  6. Create a report using the simulated screenshot and redact unrelated personal data.
  7. Compare the result with your own signal triage from Activity 1.
  8. Document what ScamShield can support and what still requires independent judgment.

Evidence: ScamShield check record, redacted report example and limitations note. Acceptance: Only simulated data is submitted; the learner distinguishes a tool result from proof of legitimacy.

Activity 6: Financial Control Plan

Design preventive and detective controls for a personal or small-business payment workflow.

  1. Map the payment workflow from request to approval, authentication and settlement.
  2. Identify where sender identity, account details and payment purpose are verified.
  3. Add an independent callback for changed beneficiary or urgent payment requests.
  4. Set a maker-checker rule and escalation threshold for high-risk transfers.
  5. Choose notification, transfer-limit and Money Lock controls appropriate to the scenario.
  6. Document exceptions and who may approve them.
  7. Run the supplied fraudulent-invoice scenario through the revised workflow.
  8. Record the blocked point, remaining exposure and recovery options.

Evidence: Payment control map, approval matrix and scenario test result. Acceptance: The design separates request, verification and approval, and names at least one preventive and one detective control.

Activity 7: Incident Evidence Pack

Preserve useful evidence and start containment without destroying the incident timeline.

  1. Start an incident log with date, time, timezone and reporter.
  2. Preserve the original message, sender identifiers, URLs, screenshots and transaction references.
  3. Record actions already taken, including clicks, downloads, credentials entered and transfers.
  4. If compromise is suspected, isolate the affected device without factory-resetting it.
  5. Use a separate trusted device to contact the bank and protect accounts.
  6. Change exposed credentials in priority order and revoke active sessions.
  7. List affected people, systems, data and financial accounts.
  8. Package evidence with neutral filenames and a chain-of-custody note.

Evidence: Incident timeline, evidence register and initial containment record. Acceptance: The chronology is complete, evidence remains unaltered, and containment actions are distinguished from eradication.

Activity 8: Escalation Tabletop

Route a scam incident to the right internal and external parties using severity and evidence.

  1. Read the capstone scenario and assign an initial severity.
  2. Identify immediate life-safety, financial, identity, device and business impacts.
  3. Choose internal recipients: manager, security, finance, legal, data protection or communications.
  4. Choose external recipients: bank, platform, ScamShield, Police or relevant dispute channel.
  5. Prepare a concise escalation brief with verified facts, unknowns and requested action.
  6. Sequence notifications to contain loss while preserving investigation options.
  7. Update severity when the scenario inject introduces a second victim and public exposure.
  8. Complete the after-action review with control improvements and owners.

Evidence: Escalation matrix, incident brief, notification sequence and after-action actions. Acceptance: The brief separates facts from assumptions and includes timestamps, evidence references, impact and a clear request.