Trends · High urgency

School-Portal Phishing and Credential Theft

Fake school login pages, fake teacher emails, fake 'attendance' messages — teens trained to comply with school authority hand over credentials. Cascades into the family Google account.

A laptop screen showing a generic login form
Most affects
10–1213–1516–18
Teen profile
High Screen Time
Family context
Limited Tech LiteracyBusy Parents
Risk type
ScamsPrivacy
I.
What it is

The short version.

School-portal phishing has become a routine attack vector: emails or texts that look like they come from the school district route to a clone of the login page. Teens have been trained to comply quickly with school authority, so the success rate is high. Once a student account is compromised, the credentials are often reused across the family Google or Apple ID, the student's college applications, and any banking or payment accounts. Schools are slow to respond because the attacks come from outside the district network.

II.
Where it shows up

The platforms and contexts.

Email and SMS to school-issued addresses and personal phones. Some attacks come from compromised classmate accounts; some from external attacker domains designed to look like the district.

III.
How long it's been around

The timeline.

Credential phishing of student accounts has scaled rapidly since 2020, when COVID-era remote learning expanded the student-account surface area. Schools' security training rarely keeps up.

IV.
What to know

The core facts a parent needs.

V.
The dangers

What's actually at stake.

VI.
What to do

Concrete next steps.

VII.
Watch

See it for yourself.

FBI warns parents about new scam targeting teens
If your teen is in crisis

School IT and district security office immediately · Notify any accounts that shared the password · FBI ic3.gov if money was taken · Identity-theft hotline (FTC 1-877-438-4338) if SSN was exposed.

← Back to all trends