rapunzl logo green investing castle
Request Free DemoFree Demo
rapunzl mobile hamburger icon
Rapunzl
Educators
Districts
After-School
Parents
Courses
Investment Simulator
Teacher Portal
Integrated Curriculum
Real-Time Market Data
Certifications
Partners
About Us
Blog
Contact
Simulator Login
Educator Login
Get Free Demo
Fraud, Identity Theft & Data Privacy cover graphic for the Rapunzl AP Business with Personal Finance curriculum
Module 42

Fraud, Identity Theft & Data Privacy

This AP Business module teaches students to spot phishing, smishing, and other fraud from the target's point of view, and to see how free apps turn personal data into a product.
Students build a five-signal red-flag radar, learn mostly free habits like unique passwords, two-factor authentication, and credit freezes, then write a real fraud protection tip sheet for someone they want to protect.

Module At A Glance

Grade Levels:
9th - 12th
Est. Length:
1-2 Weeks (19 slides)
Activities:
5 Activities
Articles:
1 Articles
Languages:
English
Curriculum Fit:
AP Business with Personal Finance — Units 1–5
Standards Alignment:
Aligned to the College Board AP Business with Personal Finance CED and the CEE National Standards for Personal Financial Education
magnifying glass with stock chart

Guiding Questions

  • How is fraud different from identity theft, and why are teens targeted on purpose?
  • How can you spot a fake message even when it looks official?
  • How do fake jobs, gaming scams, and payment-app tricks actually work?
  • What does it mean that with free apps, “you are the product”?
  • Which mostly free habits block the large majority of fraud?

Enduring Understandings

  • Fraud runs on a small set of moves — pretend, panic, and rush you into one bad tap.
  • Judge a message by what it asks and how it makes you feel, not by how it looks.
  • Sharing less data starves identity theft of its raw material.
  • A few strong habits — unique passwords, 2FA, checking statements — do most of the defending.

Module Vocab & Key Topics

Fraud
Tricking someone out of money or information by lying to them. A "scam" is fraud dressed up to look real.
Identity theft
When someone steals your personal details (name, birthday, Social Security number, passwords) and pretends to be you — usually to spend money or open accounts in your name.
Phishing
A fake message that pretends to be someone you trust (a bank, a company, a friend) to get you to click a bad link, log in on a fake page, or hand over private information.
Smishing
Phishing that arrives as a text message (SMS). The same trick, delivered to your phone.
Vishing
Phishing done by voice — a phone call from a fake "representative" trying to pressure you into sharing information or a code.
Spoofing
Faking the "from" part so a scam looks like it comes from a real person, company, or phone number. The name on the screen is not proof it is real.
Personally identifiable information (PII)
The pieces of information that can identify you: full name, birthday, address, phone number, Social Security number, account logins. Guard these — they are the raw material for identity theft.
Data breach
When a company gets hacked and the personal information it stored about you leaks out to criminals. It is not your fault, but it puts your data at risk.
Two-factor authentication (2FA)
A second lock on an account. Even if someone steals your password, they still need a one-time code (usually from your phone or an app) to get in. Turn it on for your email first.
Password manager
An app that creates and remembers a long, random, different password for every account, all locked behind one master password. It is how people actually use a unique password everywhere.
Strong & unique password
Strong means long and hard to guess (a passphrase like PurpleTaco$RunFast19 beats Zoe2010). Unique means a different one for each important account, so one leak cannot unlock the rest.
Account takeover
When a thief gets into one of your accounts, locks you out, and uses it — often to scam your friends by messaging them as "you.".
Skimming
Stealing card information with a hidden device attached to a card reader (like at a gas pump or ATM), so a thief copies your card without touching it.
Malware
Harmful software (from a bad link, attachment, or download) that can spy on you, steal passwords, or lock your device. "Ransomware" is malware that locks your files until you pay.
Credit freeze
Locking your credit file so no one can open new credit (a card or loan) in your name. It is free, does not hurt your credit score, and you unfreeze it yourself when you want new credit.
Red flag
A warning sign that a message or deal is a scam: urgency, "too good to be true," a demand for gift cards or crypto, secrecy, or an unexpected link or request for a code. When you spot one: stop and check with the real source another way.

Try It

Spot The Scam

Four situations from Module 42 — read them the way a target has to, not the way a scammer wants you to.

Scenarios drawn from the module · September 2026

Phishing

Spot The Phish

You get this text. What actually gives it away as fake?

A text reads: "CHASE ALERT: Unusual activity on your card. Verify now or your account will be suspended in 1 hour: chse-verify.com/login." The name on the screen says "Chase." You don't even have an account there.

  • It has the bank's name and logo, so it must be real.A name or logo on a text proves nothing — spoofing fakes the "from" line so a scam looks official.
  • It threatens a 1-hour deadline, pushes a link, and you don't even bank there.Urgency, an unexpected link, and a mismatch with reality are the real signals — not how official the message looks.
  • It's fake simply because it's a text message.Real banks do send real texts. The fake is in what this one asks and how hard it rushes you, not the format.

3 of 4 red flags in this text

Judge a message by what it asks and how it makes you feel — not by how official it looks.

Scam anatomy

Pretend, Panic, Rush

You feel the rush building. What do you actually do?

Nearly every scam in this module moves the same way. A message pretends to be your bank, a friend, or a delivery service. It panics you with a threat or a prize. Then it rushes you to tap, click, or share a code before you have time to think.

  • Tap fast, before the deadline or offer runs out.Speed is exactly what the rush is built to trigger — it's the moment most people get caught.
  • Stop, then check with the real company or person a different, trusted way.Going straight to the source breaks the rush and costs you nothing if the message turns out to be real.
  • Ignore it completely and never check either way.If the alert happens to be real, ignoring it can cost you too — the safe move is to verify, not to guess.
  1. Pretendposes as trusted
  2. Panicurgent threat
  3. Rushno time to think
  4. Bad Tapclick or share
  5. Stop & Checkgo to the source

Every scam pretends, panics, and rushes you — stopping to check at the source breaks the pattern for free.

Data privacy

You Are The Product

Which of these does a free photo-editing app actually need?

A free photo-editing app asks for permission to your photo library, your exact location, your contacts list, and your microphone during setup. All it does is edit the photos you choose to open in it.

A photo-editing app only needs access to your photo library — location, contacts, and microphone are not necessary for editing photos, even though the app asks for them.
NeededNot needed
Photo library
Exact location
Contacts list
Microphone

If the app is free, your data is often the price — permissions beyond what the task needs are the tell.

Fraud habits

Lock The Doors

Five habits repeat across the module: a unique password for every account (kept in a password manager), two-factor authentication starting with your email, a weekly look at your statements, sharing less personal information, and knowing how a credit freeze works. Almost none of it costs money.

All five habits are free or nearly free; unique passwords and two-factor authentication block fraud outright, while statement checks, sharing less, and a credit freeze mainly limit the damage.
FreeBlocks fraud
Unique passwords
2FA on email
Weekly statement check
Share less data
Credit freeze

A short list of mostly free habits — not constant vigilance — does most of the defending against fraud.

Scenarios are illustrative and adapted from the Module 42 Teacher Guide, article, and activities ("Spot the Phish," "Radar Check," "Build a Fraud Protection Tip Sheet"); company examples are generic or, where the module itself uses a spoofed sender name, clearly marked as the module's own fictional example.