Section 00
What this unit is about
You will meet the cyber security industry, break a 2,000-year-old cipher, build a tool that cracks it, work out how two strangers can share a secret without ever meeting, and then find out why the most common four-digit PIN in the world is still 1234.
Know the field
Who works in cyber security, what a scam call centre actually looks like, and what happens to a company after a data breach.
The evolution of encryption
From a rotating paper wheel used by Roman generals to the key exchange that protects your banking app right now.
The weak link
Modern encryption is effectively unbreakable. Humans are not. Almost one in ten of us picks the same PIN.
What you hand in
| # | Task | Format | Where it lives |
|---|---|---|---|
| 1 | Data breach investigation | PowerPoint presented to the class | Section 01 |
| 2 | Caesar cipher quiz | PDF generated on this page, submitted online | Section 02 |
| 3 | Frequency analyser | Spreadsheet file + photo of workbook answers | Section 03 |
| 4 | Asymmetric encryption explainer | Animation, video or narrated slideshow | Section 04 |
| 5 | PINs and humans response | 100–150 words in your workbook | Section 05 |
Lesson sequence
Nine lessons. Bring your workbook every lesson — four of the five tasks start there.
| Lesson | Focus | You should finish with |
|---|---|---|
| 01 | Terms brainstorm, virtual job experience | A glossary page in your workbook |
| 02 | Scam call centres and the ethics of fighting back | Video notes and a written position |
| 03 | Data breach research | Research notes and a slide outline |
| 04 | Breach presentations to the class | Submitted PowerPoint |
| 05 | Caesar cipher, wheel practice, quiz | Submitted quiz PDF |
| 06 | Frequency analysis theory and Excel build | A working frequency analyser |
| 07 | Improving the analyser, cracking a cipher | Submitted spreadsheet |
| 08 | Public and private keys, planning your explainer | Storyboard for your animation |
| 09 | Explainer production, PINs and humans | Submitted explainer and written response |
Words you need to know
Copy these six into your workbook in lesson 1. The rest of the bank is in Section 01.
Cryptography — the science of encrypting and decrypting messages into cipher text.
Encryption — converting plain text into cipher text.
Decryption — converting cipher text into plain text.
Plain text — the original message that you can read normally.
Cipher text — the secret message that you cannot read normally.
Key — the algorithm or settings used to encrypt and decrypt.
Section 01
Know the field
Before you can defend anything you need the vocabulary, a sense of who does this work for a living, and a clear-eyed look at what attackers actually do all day.
Brainstorm: how many terms can you name?
In a group of three or four, list every cyber security term you can think of. Six minutes. Write a definition next to any term you can actually explain — a term you cannot explain does not count yet.
Type your group's terms below. Anything that matches the class term bank will light up.
0 terms — 0 matched the term bank.
Term bank — open after the class brainstorm
Click a card to reveal the definition. Add any you missed to your workbook.
Virtual job experience: cyber security specialist
Year13 runs a free virtual job experience that puts you in the role of a cyber security specialist. Work through it on your own, at your own pace.
Open the Year13 virtual job experience →
Record in your workbook as you go
- Three tasks a cyber security specialist does in a normal week.
- Two skills the module says you need — and where you could start building them this year.
- The pathway into the job: what do you study, and for how long?
- One thing that surprised you.
Inside a scam call centre
Scammer Payback is run by a cyber security professional who goes by Pierogi. He answers scam calls in character, keeps the scammer talking, and while they are distracted he gets into their systems: reading their files, watching their cameras, and sometimes deleting everything they have.
Watch one full video. Your teacher will choose, or pick from these.
Scammer Payback Answers Scam Questions (WIRED)How the scams work and how to shut them down. The most classroom-friendly starting point. How Pierogi took down a $65 million scam call centreThe investigation that ended with United States federal charges against 30 people. The Scammer Payback channelFor the full scam-baiting videos. Preview before you use one in class — some contain strong language.Notes to take in your book
- What is the scam? Write the script the scammer uses, step by step.
- Who is the target, and why were they chosen?
- What technology does the scammer rely on? What does Pierogi use against them?
- At what exact moment could the victim have stopped the scam?
Where do you stand?
Choose a position for each statement, then read the counter-argument. You will not agree with all of them, and you are not meant to.
Investigate a significant data breach
Choose one significant data breach from the last five years and research it properly. Then present it to the class in a PowerPoint.
Four questions your presentation must answer
- What happened? Who was attacked, when, how did the attacker get in, what data was taken, how many people were affected.
- What could have been done to prevent it? Name specific controls, not "better security" — multi-factor authentication, patching, least privilege, encryption of stored data, deleting data the organisation no longer needs.
- What are the long-term implications? For the organisation, for the individuals whose data was taken, and for the law.
- What would you have done differently? Your own judgement, argued from your research.
Leads to get you started
These are starting points only. Verify every detail against at least two independent sources before you put it on a slide — numbers reported in the first week of a breach are almost always wrong.
| Breach | When | Why it is worth studying |
|---|---|---|
| Optus | 2022 | Reported to have exposed millions of customer records through an interface that did not check who was asking. |
| Medibank | 2022 | Health data. Attackers used stolen contractor credentials; the stolen data was published when the ransom was refused. |
| Latitude Financial | 2023 | Millions of identity documents, including copies of licences held long after they were needed. |
| MediSecure | 2024 | Prescription data. The company later went into administration — a breach can end a business. |
| Ticketmaster | 2024 | A cloud storage account reached without multi-factor authentication. |
| Qantas | 2025 | Reported as social engineering against a call centre — people, not software, were the way in. |
Useful sources: the Office of the Australian Information Commissioner publishes a Notifiable Data Breaches report every six months, and the Australian Signals Directorate publishes an Annual Cyber Threat Report. ABC News and the Australian Financial Review cover major breaches in detail.
Presentation requirements
- Six to ten slides, presented in five minutes.
- A timeline slide: when the attacker got in, when it was detected, when customers were told. The gap between those dates is usually the story.
- Slides carry headings and images. You talk; you do not read paragraphs off the screen.
- A final slide listing your sources.
Rubric
| Criterion | Developing | Consolidating | Extending |
|---|---|---|---|
| Research K&U |
The basic facts of the breach are reported, mostly from a single source. | Facts are confirmed across several sources and the technical cause of the breach is explained accurately. | Sources are weighed against each other, including where early reporting turned out to be wrong, and official reports are used. |
| Analysis K&U |
Prevention is described in general terms. | Specific controls are named and linked to the way this attacker actually got in. | Long-term implications are argued across the organisation, the affected individuals and the law, with a defended judgement of your own. |
| Communication P&P |
Slides are readable and the presentation covers the four questions. | Slides are designed for an audience, and the delivery is clear and paced. | The presentation holds the room: strong visuals, a clear narrative line, and questions answered confidently. |
Section 02 · The evolution of encryption
The Caesar cipher
The first popular substitution cipher, used by Julius Caesar to send orders his enemies could not read. It held up for roughly 800 years. Then one mathematician worked out how to break it in an afternoon.
How it works
Every letter in the message is replaced by the letter a fixed number of places further along the alphabet. That fixed number is the key. With a key of 3, a becomes d, b becomes e, and z wraps around to c.
Because the same key both locks and unlocks the message, this is symmetric encryption: the sender and the receiver must both already know the key. Holding on to that shared secret is the whole problem, and it stays the problem for the next two thousand years — you will see how it was finally solved in Section 04.
The Caesar cipher — Khan AcademyFour minutes on where the cipher came from and how frequency analysis eventually broke it.Cipher wheel
The outer ring is your plain text, the inner ring is your cipher text. Turn the wheel to set the key, then type below.
Decode these
Work them out on the wheel, then check yourself. The first one does not tell you the key — you have to find it.
The four-wheel challenge
Now the hard one. This is close to how a real Enigma machine worked. Four wheels, with keys 2, 14, 4 and 6. Decode the first word with the first wheel, the second word with the second wheel, and so on. After the fourth word, go back to the first wheel.
Caesar cipher quiz
Use the Khan Academy cipher wheel or the wheel above. Short answers are marked instantly. The written answers are marked by your teacher, so take your time with them.
Section 03 · The evolution of encryption
Frequency fingerprint
You follow a pattern every time you write, without deciding to. That pattern is a fingerprint, and it is the reason the Caesar cipher stopped being safe in about the tenth century.
Has it happened to you?
- Have you ever been hacked? Have your parents or carers?
- Why is an adult more likely to be a victim than you are?
Have I Been Pwned is an Australian-run site that tells you which data breaches your email address turned up in. Try it with an address you use.
The theory
In English, e is the most common letter by a long way, followed by t, a, o, i and n. q, j, x and z barely show up. Write enough text and your letter counts will always land in roughly the same shape.
A Caesar cipher does not change that shape. It slides the whole thing sideways. If the tallest bar in your cipher text sits on h, then h is almost certainly a disguised e, and your key is 3. You do not have to try all 25 keys — the message tells you which one it is.
This was worked out by the Arab mathematician Al-Kindi in the ninth century, and it is why every serious cipher since has been designed to flatten that fingerprint.
Build your fingerprint
Type or paste at least a couple of sentences. Watch the shape settle.
Break a cipher with the fingerprint
Paste any Caesar cipher text. This tool compares the letter counts against the shape of ordinary English for all 25 keys and reports the closest match. No guessing, no trying every key by hand.
Questions
Heading: Frequency Analysis. Write neatly — this one gets collected.
- Why do we follow this pattern without thinking about it?
- Would the pattern be different in another language? Why?
- What tactics could a writer use to avoid leaving a normal fingerprint?
- Most importantly: how could this be used to break a simple encryption such as a Caesar cipher?
Build your own frequency analyser
You are going to build the tool you just used, from scratch, in a spreadsheet.
- Type a long sentence into cell
B2. Keep it simple to start with: no capital letters, no punctuation. - In
B4typea, inB5typeb, inB6typec, and keep going down tozinB29.Your sheet after step 2. Sentence in B2, letters starting in B4. - In
A30type(space), and inB30type a single space character.Row 30. B30 looks empty because a space is invisible - it is still there. - The magic formula. Put this in
C4, then fill it down toC30:
=LEN($B$2)-LEN(SUBSTITUTE($B$2,B4,""))
It measures the length of your sentence, removes every copy of the letter sitting to the left, measures again, and reports the difference. That difference is how many times the letter appeared. - Now add error checking, so you can prove the tally is right. In
E6typeAccuracy Check, inE7typeLength of sentence:, inE8typeTally of all characters:, and inE10typeSuccessful match? - Then the three formulas:
H7: =LEN($B$2),H8: =SUM(C4:C30),H10: =H7=H8The accuracy check working. Both counts read 25, so the match returns TRUE. - Test it. Add a full stop to the end of your sentence, or a capital letter. The match should flip to
FALSE, because neither is being counted. If it does not, your tally range is wrong. - Select
B4down toC29— letters only, no spaces. Insert menu, then a bar chart.Insert tab, then the column chart button. Any of the 2D column options will do. - Double-click the chart title and rename it
Frequency Fingerprint.The finished basic analyser. This is what you are aiming for.
Then improve it
Merge the cells holding the sentence so long text is readable.
Add borders and cell fill colour so the layout reads as a tool, not a pile of numbers.
Conditional formatting: green when the accuracy check passes, red when it fails.
- Conditional formatting on column
Cso the most frequent letters stand out on their own. - Handle capital letters and punctuation, so the tally still balances on real text.
Worked example files
Two finished versions: the basic build, and the improved one that copes with capitals and punctuation. Use them to check your own work after you have had a genuine attempt.
Hint: tomb + vowel + chart + ee
Unlocked.
Open with Excel or LibreOffice Calc. In Excel, use File → Open and choose the file directly.
Section 04 · The evolution of encryption
Asymmetric key encryption
Everything so far has one fatal flaw: the sender and receiver must already share a secret key. So how does your phone agree on a key with a bank it has never contacted before, over a network anyone can listen to?
The problem with one key
A Caesar cipher, Enigma, and the encryption on a password-protected zip file are all symmetric: one key locks and unlocks. That works fine until you have to get the key to the other person. Post it and it can be intercepted. Say it over the phone and it can be overheard. Meet in a park and you have to already be in the same city.
In the 1970s that problem was solved, and the solution looks impossible at first: give your locking key away to everybody.
The Internet: Encryption and Public KeysWatch this first. Seven minutes on how two strangers agree on a secret in public.Two keys, one pair
Every person gets two keys, generated together as a matched pair.
Published to the world. Put it on your website, hand it to strangers, print it on a t-shirt. Nothing is lost by everyone having it.
Never leaves your device. Never sent, never shared. If it leaks, everything protected by it is gone.
The pair has a special mathematical relationship. Whatever one key locks, only the other one can unlock. The same key cannot do both jobs. That single property does two very different things:
The second one is worth reading twice. It does not hide the message from anybody — everyone has your public key. What it proves is that the message could only have come from the holder of the matching private key. That is a digital signature, and it is how your device knows a software update really came from Apple or Google.
Use both at once and you get dual asymmetric encryption: encrypt with your private key first, then encrypt that cipher text again with the receiver's public key. Now only they can read it, and they know for certain it came from you.
Which key?
Alice and Bob are the names cryptographers have used for this since 1978. Each has a public key everyone knows, and a private key only they hold.
Where do the keys come from?
A key is only as good as the randomness used to create it. If an attacker can predict how your key was generated, they do not need to break the mathematics at all — they just generate the same key you did. Computers are terrible at being random, because they follow instructions, so the numbers they produce are only pseudo-random.
Which is why one of the companies carrying a large share of the world's web traffic points a camera at a wall of lava lamps.
The lava lamps that help keep the internet secure — Tom ScottFour minutes inside Cloudflare's wall of entropy.Optional extension: why prime numbers make this work
Multiplying two large prime numbers together is easy. Taking the answer and working out which two primes made it is, for numbers of the right size, effectively impossible with current computers. That gap between easy-one-way and near-impossible-the-other-way is what the key pair is built on.
Prime numbers keep your encrypted messages safe — here's how (ABC News). This gets deep. It is genuinely optional, and it is where the Extending band of the rubric below lives.
Explain dual asymmetric encryption
Using any software that produces time-based media, create a presentation or animation that explains the process of dual asymmetric key encryption. Change up the style from the video you watched — you are not remaking it. You do not need to re-explain the basics from the first video; start where it left off.
Graphics can be your own, sourced online, generated with AI, or edited in Photoshop. Extra marks for recorded narration.
Software options
- PowerPoint, with transitions, timings and recorded audio
- Adobe Animate
- CapCut, Premiere, or any video editor
- Blender, if you are feeling ambitious
Before you animate
Storyboard it. Six to ten frames, on paper. Every frame needs to answer: what is on screen, what moves, what is being said. Animation without a storyboard takes three times as long.
Rubric
| Criterion | Developing | Consolidating | Extending |
|---|---|---|---|
| Animation P&P |
A slideshow-style animation or similar has been created. | Motion or shape tweens show plain text being modified into cipher text. Video has been recorded and edited. | Interactive buttons control the animation, and advanced editing features have been used. |
| Communication P&P |
All information is conveyed as text, with some errors in spelling or structure. | Mostly text, with sound effects or recorded audio added. | Clear vocal explanation, timed to the specific points it describes on screen. |
| Explanation K&U |
Some components of encryption are explained, with errors. | Encrypting with both a private and a public key is explained accurately, including why you would do it. | The role of prime numbers in generating the key pair is explained, best handled on a separate slide or section. |
Section 05
The weak link in the chain
Modern encryption is, for practical purposes, unbreakable. So attackers stopped attacking it. They attack the person holding the key instead — and we make that easy.
29 million stolen codes
ABC News analysed 29 million four-digit codes that had leaked in data breaches, using data from Have I Been Pwned, to find out how people actually choose a PIN. There are 10,000 possible four-digit codes. They are nowhere near equally popular.
Read the article: Almost one in 10 people use the same four-digit PIN (ABC News, January 2025)
The ten most popular codes in that data
Share of the 29 million codes analysed. Source: ABC News analysis of Have I Been Pwned data.
Five guesses
Someone finds a lost phone, or watches a card go into an ATM. Most systems give an attacker around five attempts before locking. Pick the five codes you would try.
Your five guesses
Why we are like this
Look at what shows up in the popular codes and the reasons become obvious.
- Sequences and repeats. 1234, 1111, 0000, 4321, 2222 — fast to type, easy to remember, chosen by millions of other people.
- Birth years. A huge band of popular codes sits between 1970 and 2005, because people use the year they were born.
- Dates. Every valid day-month combination is over-represented. 2512 — Christmas Day — is a standout.
- Keypad shapes. 2580 is a straight line down the middle of a phone keypad. Your fingers chose it, not your memory.
All four have the same cause: a PIN has to be remembered by a human under pressure, so we reach for something already stored in our heads. The maths says 10,000 options. Human behaviour turns that into a few hundred.
What is the problem with PINs and humans?
Write a 100 to 150 word response in your workbook. Draft it here first if that helps — the counter keeps you honest.
Your response should deal with
- The gap between how many codes are possible and how many are actually used.
- At least one specific pattern from the data, with the number attached.
- Why people choose the way they do — memory, speed, habit.
- What follows from it: what does this mean for security systems built around a short code?
The workbook copy is what gets marked. The PDF is a backup, or for handing in online if your teacher asks for it.
So what actually helps?
You cannot fix human memory. You can stop relying on it.
- Length beats complexity. A four-word passphrase such as stapler-lemon-orbit-brick is easier to remember and far harder to guess than P@ssw0rd1.
- Multi-factor authentication. Even a perfectly guessed password fails without the second factor. Several of the breaches in Section 01 came down to an account without it.
- A password manager. Then every account gets a long random password and you only have to remember one.
- Never reuse. One reused password turns one company's breach into a break-in on every account you own.