The Educator Magazine U.K. Sept-Dec 2026 issue - Magazine - Page 15
2. Be cautious of urgency and
authority
AI phishing often relies on pressure
tactics such as:
• Urgency and deadlines
• Fear and threats
• Impersonating authority
These messages often arrive at already
pressured times, just before holidays or at
the end of the school day when staff are
busy and more likely to act quickly.
Pause and ask yourself:
• Does this really need doing now?
• Am I being pressured into acting?
• Can I verify this before responding?
3. Treat voice requests with caution
Voice cloning and AI-generated video
calls make impersonation more
convincing than ever.
If you receive a call requesting urgent
action:
• Keep in mind that the voice may not
be genuine.
• End the call politely.
• Call back using a trusted number from
school records.
For high-risk actions, such as authorising
payments, schools may also wish to
introduce a pre-agreed verification
passphrase known only to authorised
staff. This provides an additional
safeguard against sophisticated
impersonation attempts.
4. Be aware of your digital footprint
6. Use strong security habits every day
Attackers often gather information from:
Good habits that make a real difference:
• School websites
• Using strong, unique passwords.
• Social media profiles
• Enable multi-factor authentication
(MFA) wherever available.
• Public events and announcements
One area worth reviewing is how much
information schools publish about staff,
particularly names, photographs, job
titles and organisational structures.
While celebrating achievements is
important, limiting unnecessary personal
information makes it harder for attackers
to build convincing scams.
5. Report anything suspicious
immediately
If something feels unusual:
• Report it to your school's IT support or
network manager immediately.
• Follow your school's agreed cyber
incident reporting process.
• Log out of systems when not in use.
• Questioning unexpected requests,
even when they appear to come from
someone you know.
With Cybersecurity, as with safeguarding
or health and safety, everyone has a role
to play in protecting the school
community.
Conclusion
AI-powered phishing represents a major
shift in the cyber threats facing schools.
Because these scams are more realistic,
more personalised and increasingly use
trusted communication channels, the
traditional "spot the scam" approach no
longer offers the protection it once did.
• Mistakes happen and if you
accidentally
click a link, enter login details or dow
load a suspicious attachment, quick
reporting can make all the difference.
Instead, the strongest defence is a culture
of verification, where unusual requests
are routinely checked through another
communication channel, suspicious
activity is reported immediately and staff
feel confident questioning even
apparently genuine messages.
Rapid reporting allows IT teams to reset
passwords, revoke compromised devices,
investigate unusual logins and prevent
attackers from gaining further access.
This works best when there is a clearly
publicised reporting route so staff know
exactly who to contact.
In today's threat landscape, technology
is only part of the picture. The greatest
protection comes from well-informed
colleagues who stay alert, takes time
to verify before acting, and see
cybersecurity as something everyone
contributes to.
For more information please visit - https://lgfl.net/security