District Operations

Phishing Awareness Program

Test Your Exposure to Phishing

Phishing is the most common way attackers breach school districts. A single convincing email can steal staff credentials, expose sensitive data, or trigger ransomware that disrupts instruction. While security tools block many threats, the emails that get through rely on one thing: a human click.

  • 90%+ of breaches start with a phishing email.
  • 1 click is all it takes to expose credentials or data.
  • Days of lost instruction when ransomware hits a district.

That’s why trained staff are your strongest defense. The Learning Technology Center (LTC) offers phishing awareness campaigns to Illinois public school districts, funded by the Illinois State Board of Education (ISBE). Campaigns simulate phishing attacks to educate district employees on detecting and preventing these risks. Participating districts receive a detailed assessment of their susceptibility to phishing, enabling targeted improvements in cybersecurity training.

What Makes Our Campaigns Different

  • Free. One free campaign per year for every Illinois public K-12 district, with additional campaigns available at low cost.
  • Realistic. Emails are crafted like real phishing attempts, complete with persuasive text, graphics, and a tempting link. Completely safe.
  • Educational. The link leads to a teaching page, not a threat. Staff learn the red flags they missed.

How a Campaign Works

  1. Simulate. Simulated phishing emails go out to district employees.
  2. Educate. Clicking the link opens a lesson on spotting phishing.
  3. Report. Your district gets a report showing who clicked and where training is needed.

Eligibility and How to Get Started

This program is available to all public PK-12 school districts in Illinois, with each district eligible for one free phishing campaign per year. Free campaigns are offered on a first-come, first-serve basis, with the option to purchase additional campaigns at a low cost.

To request your district’s campaign:
  1. Request. Email dshaffer@ltcillinois.org to get on the schedule.
  2. Onboard. We send a guided link that walks you through setup.
  3. Set Up. Sync your directory read-only from Google Workspace or upload a CSV, then whitelist our sending IP addresses.
  4. Launch. We run the campaign and review the results with you within two weeks.

Powered by K12Smart Phish

Campaigns run on K12Smart Phish, a phishing simulation and security awareness platform built by the LTC specifically for K-12. It helps districts build a security-aware culture through safe practice and in-the-moment coaching, with clear reporting on your district’s human risk.

  • Realistic template library. True-to-life vendor and internal emails, kept current.
  • Smart Learn moments. Clickers see the exact red flags they missed, instantly.
  • Recurring campaigns. Safe simulations on a schedule, all year long.
  • Audiences and sync. Target schools, departments, or roles, synced from Google Workspace or manual import.
  • Click and report tracking. Know who opened, clicked, or reported.
  • Reporting and risk. Click rates, repeat clickers, and improvement over time.

K12Smart is made by the LTC and available for purchase by any district that wants phishing simulation year-round.

Learn more at k12smart.com/phish.