Phishing in Schools: How Tartan Helps Teachers Stay Alert

Phishing in Schools: How Tartan Helps Teachers Stay Alert

Phishing in Schools: How Tartan Helps Teachers Stay Alert

Milo owner of Notion for Teachers

Article by

Milo

ESL Content Coordinator & Educator

ESL Content Coordinator & Educator

All Posts

Meta Title: Phishing in Schools: How Tartan Helps Teachers Stay Alert

Meta Description: Phishing is the top cyber threat facing schools. Here's how teachers can spot suspicious emails, protect student data, and build safer digital habits.

You're halfway through grading when an email pops up. It's from "IT Support," says your login will expire tonight, and asks you to confirm your password through a link. You've got forty more essays to get through. So you click.

That's the whole trick. Phishing doesn't beat teachers with clever code. It beats them with timing, and teachers are some of the busiest, most interruptible people in any building.

And the stakes are higher than most of us think about day to day. A teacher's accounts sit on top of student records, grades, parent contacts, and logins that quietly connect to Google Workspace, your LMS, and whatever else the district runs. Compromise one inbox and you've handed over a lot more than one inbox.

Still grading everything by hand?

EMStudio is a free teaching management app — manage your classes, students, lessons, and more!

Learn More

Still grading everything by hand?

EMStudio is a free teaching management app — manage your classes, students, lessons, and more!

Learn More

Table of Contents


Why the inbox is the target

Attackers go where the people are, and schools are full of people who click things all day as part of the job. Shared docs, permission slips, district announcements, parent replies. Even the tools meant to help, the shared calendars and cloud drives, add more doors to try. It all looks normal, which is the point.

Human error isn't a knock on teachers. It's what happens when smart people are moving fast. The messages that work best are the ones that feel routine:

  • A password reset from "the help desk"

  • A shared file you weren't quite expecting

  • A note from a "parent" with an attachment

  • A quick favor from the "principal," usually involving gift cards

None of those scream danger. That's the design.

What the numbers show

According toCISA, K-12 schools now average more than one cyber incident per school day. The 2025CIS MS-ISAC K-12 Cybersecurity Report found that 82% of reporting schools dealt with a cyber threat impact over an 18-month period, and that attacks leaning on human error outnumbered the purely technical ones. Phishing and social engineering sat near the top of the list.

What's actually at risk

Think about what a teacher keeps close at hand. Lesson plans, projects, classroom resources, professional notes. A lot of that lives in digital workspaces like Notion these days, alongside the district-approved systems that hold grades and official student records. It's handy right up until someone walks in with your login.

And it's not only your own data at stake. Depending on your role, a compromised account might expose student contact details, classroom records, internal messages, or other sensitive school information. None of that is meant to leave the building, which is reason enough to treat your login like a key.

One reused password is often all it takes. The attacker doesn't need to break Notion or Google. They just log in as you, because credentials exposed in some unrelated breach were reused here too. Boring, but that's usually how it goes.


Building the reflex, not just the rule

Here's the part schools tend to get wrong. They send a memo, everyone nods, and nothing sticks. A policy you read once doesn't change what you do at 9pm with a full inbox.

What changes behavior is practice. The goal is a small reflex: a two-second pause before you click, where you look at who sent the thing and where the link really goes. That reflex is learnable, and it gets stronger the more it's used.

This is why a lot of districts have moved toward security awareness training that runs in the background all year instead of a single fall workshop. Some of it comes in the form of practice phishing emails, the safe kind sent by your own IT team, so staff can get caught by a fake before they get caught by a real one. That's the idea behind platforms like tartan.app, which pair phishing simulations with ongoing security awareness training built for K-12 staff and students rather than generic office workers. The point isn't the tool itself. It's that repetition, not paperwork, is what builds the habit.

Habits worth starting this week

You don't need a district rollout to get better at this. A few small moves cover most of the risk:

  1. Slow down on links. Hover first, read the actual address, then decide.

  2. Check the real sender, not just the display name. "Principal Reyes" can be anyone.

  3. Stop reusing passwords. A password manager makes this painless.

  4. Turn on two-factor wherever it's offered, especially email and your LMS.

  5. Report the weird ones. If it feels off, forward it to IT instead of deleting it quietly.

None of this takes special training. It's mostly about slowing down for the half-second where the mistake happens.

That last point matters more than it looks. When one teacher flags a phishing attempt, IT can warn everyone else before the next person clicks. Reporting is a team sport.

And honestly, most of this is the same mindset you already use to keep a classroom running. You build a system, you repeat it until it's automatic, you don't rely on remembering. Security is just another part of that system.

It's not all on you

Teachers shouldn't have to be the last line of defense. Good habits at the desk work best alongside a school that's doing its part: IT teams watching for threats, training that repeats, and a culture where reporting a mistake doesn't feel like confessing one.

The aim was never to make anyone paranoid about their inbox. It's just that little pause. Look before you click, and most of the trick stops working.


Why the inbox is the target

Attackers go where the people are, and schools are full of people who click things all day as part of the job. Shared docs, permission slips, district announcements, parent replies. Even the tools meant to help, the shared calendars and cloud drives, add more doors to try. It all looks normal, which is the point.

Human error isn't a knock on teachers. It's what happens when smart people are moving fast. The messages that work best are the ones that feel routine:

  • A password reset from "the help desk"

  • A shared file you weren't quite expecting

  • A note from a "parent" with an attachment

  • A quick favor from the "principal," usually involving gift cards

None of those scream danger. That's the design.

What the numbers show

According toCISA, K-12 schools now average more than one cyber incident per school day. The 2025CIS MS-ISAC K-12 Cybersecurity Report found that 82% of reporting schools dealt with a cyber threat impact over an 18-month period, and that attacks leaning on human error outnumbered the purely technical ones. Phishing and social engineering sat near the top of the list.

What's actually at risk

Think about what a teacher keeps close at hand. Lesson plans, projects, classroom resources, professional notes. A lot of that lives in digital workspaces like Notion these days, alongside the district-approved systems that hold grades and official student records. It's handy right up until someone walks in with your login.

And it's not only your own data at stake. Depending on your role, a compromised account might expose student contact details, classroom records, internal messages, or other sensitive school information. None of that is meant to leave the building, which is reason enough to treat your login like a key.

One reused password is often all it takes. The attacker doesn't need to break Notion or Google. They just log in as you, because credentials exposed in some unrelated breach were reused here too. Boring, but that's usually how it goes.


Building the reflex, not just the rule

Here's the part schools tend to get wrong. They send a memo, everyone nods, and nothing sticks. A policy you read once doesn't change what you do at 9pm with a full inbox.

What changes behavior is practice. The goal is a small reflex: a two-second pause before you click, where you look at who sent the thing and where the link really goes. That reflex is learnable, and it gets stronger the more it's used.

This is why a lot of districts have moved toward security awareness training that runs in the background all year instead of a single fall workshop. Some of it comes in the form of practice phishing emails, the safe kind sent by your own IT team, so staff can get caught by a fake before they get caught by a real one. That's the idea behind platforms like tartan.app, which pair phishing simulations with ongoing security awareness training built for K-12 staff and students rather than generic office workers. The point isn't the tool itself. It's that repetition, not paperwork, is what builds the habit.

Habits worth starting this week

You don't need a district rollout to get better at this. A few small moves cover most of the risk:

  1. Slow down on links. Hover first, read the actual address, then decide.

  2. Check the real sender, not just the display name. "Principal Reyes" can be anyone.

  3. Stop reusing passwords. A password manager makes this painless.

  4. Turn on two-factor wherever it's offered, especially email and your LMS.

  5. Report the weird ones. If it feels off, forward it to IT instead of deleting it quietly.

None of this takes special training. It's mostly about slowing down for the half-second where the mistake happens.

That last point matters more than it looks. When one teacher flags a phishing attempt, IT can warn everyone else before the next person clicks. Reporting is a team sport.

And honestly, most of this is the same mindset you already use to keep a classroom running. You build a system, you repeat it until it's automatic, you don't rely on remembering. Security is just another part of that system.

It's not all on you

Teachers shouldn't have to be the last line of defense. Good habits at the desk work best alongside a school that's doing its part: IT teams watching for threats, training that repeats, and a culture where reporting a mistake doesn't feel like confessing one.

The aim was never to make anyone paranoid about their inbox. It's just that little pause. Look before you click, and most of the trick stops working.

Enjoyed this blog? Share it with others!

Enjoyed this blog? Share it with others!

Still grading everything by hand?

EMStudio is a free teaching management app — manage your classes, students, lessons, and more!

Learn More

Still grading everything by hand?

EMStudio is a free teaching management app — manage your classes, students, lessons, and more!

Learn More

Table of Contents

share

share

share

All Posts

Continue Reading

Continue Reading

Notion for Teachers logo

Notion4Teachers

Notion templates to simplify administrative tasks and enhance your teaching experience.

Logo
Logo
Logo

2026 Notion4Teachers. All Rights Reserved.

Notion for Teachers logo

Notion4Teachers

Notion templates to simplify administrative tasks and enhance your teaching experience.

Logo
Logo
Logo

2026 Notion4Teachers. All Rights Reserved.

Notion for Teachers logo

Notion4Teachers

Notion templates to simplify administrative tasks and enhance your teaching experience.

Logo
Logo
Logo

2026 Notion4Teachers. All Rights Reserved.