AP Cybersecurity — Independent Practice

AI Power-Ups: Augmenting Cyberattacks

Work through this at your own pace. Talk to your neighbors, compare answers, help each other out — this isn't a solo silent-room activity. When you're done, generate your completion summary at the bottom and submit it to Google Classroom.

Part 1 — Generic voice synthesis
SIMULATION — no voice samples collected, no real person impersonated
Part 2 — Record and reshape your own voice
LOCAL ONLY — your recording never leaves this browser tab, and disappears when you refresh
Click "Start Recording" and allow microphone access when your browser asks.

Where this demo stops and a real attack starts

The "voice shift" above only speeds up or slows down your own recording — it can only ever say exactly what you recorded. A real voice-cloning attack collects samples of a specific person's actual voice and trains a model that generates brand-new sentences in that voice, including things they never said.

This demoSpeed/pitch-shifts audio you chose to record. Can only replay your own words.
Real attackTrained on someone else's voice without consent. Generates new speech they never said.
Part 3 — Five ways AI powers up an attack
Impersonation

Clones a voice, face, or writing style from just a few samples, so a message sounds like it's really from someone you trust.

AI-Written Phishing

Writes natural, error-free messages in any tone or language, so the old "bad grammar" red flag stops being reliable.

Data Extraction & Manipulation

Tricks an AI system into revealing information it shouldn't, or feeds it false information so it repeats that misinformation later.

AI-Powered Reconnaissance (OSINT)

Scans public posts and profiles fast, connecting names, routines, and relationships a human would take hours to piece together.

AI-Assisted Malware

Helps write or modify malicious code, or scan for weaknesses, without the attacker needing deep programming skill.

Part 4 — AI enhancements: see the scale for yourself
RULES: fictional targets only — no real classmates, teachers, or companies. No real working links — use something like http://example-fake-link.test. Nothing gets sent anywhere.
Task A — Phishing Email Blitz

Open your assigned AI chat tool in a new tab. Your goal: get it to produce as many different phishing email variations as you can in 5 minutes, aiming for 20. This is about experiencing the AI-Written Phishing power-up firsthand — speed and scale, not artistry.

Required elements to ask for: urgency, authority impersonation (IT, HR, a manager), a personalization placeholder like [First Name], and a clear call to action (a fake link or a reply request).

Starter prompt — copy it in, then ask for variations:

Write a phishing email pretending to be from a fictional company's IT department. Make it urgent, sound like it's from someone in authority, include a placeholder like [First Name], and end with a call to action like clicking a link or replying with information. Do not use a real link - use http://example-fake-link.test instead. Then generate 5 more variations using different urgency phrases and sign-offs.
0 / 15 words
0 / 20 words
0 / 20 words
0 / 20 words
0 / 20 words
Task B — Urgent Voicemail Script Blitz

Same idea, different power-up: this time you're generating short urgent voicemail-style scripts — the kind an impersonation attack might use. Same 5-minute window, same fictional-only rule.

Required elements to ask for: a claimed identity (who the caller is pretending to be), an urgency/fear trigger, a specific ask (money, info, or an action), and a plausible cover story.

Starter prompt — copy it in, then ask for variations:

Write a short, urgent voicemail script for a fictional scam where the caller pretends to be a family member in trouble and needs money sent quickly. Make it sound panicked and specific, but don't use any real names. Then generate 5 more versions using different fictional emergencies (a car accident, a lost passport while traveling, a mix-up with school security, etc.), each short enough to read aloud in under 20 seconds.
0 / 15 words
0 / 20 words
0 / 20 words
0 / 20 words
0 / 20 words

You won't find an "AI-Assisted Malware" version of this task — asking an AI tool to write or modify actual malicious code isn't something this class does, even fictionally. That power-up stays a discussion topic (Scenario 5), not a hands-on one.

Part 5 — How much can strangers piece together?

Check off anything that's true and easy to find about you online — a real post, a tagged photo, a public profile. Then see what it adds up to.

The checklist above is a simulation. These next two are real research tools — one measures how identifiable you are as a person, the other measures how identifiable your browser is as a device. Open each in a new tab and use it for real.

REAL TOOL — Harvard Data Privacy Lab

This tool is built on real research: with just your birth date, gender, and ZIP code — three facts plenty of people post or imply without thinking twice — it estimates how unique that combination makes you among everyone else. Nothing you enter gets saved.

0 / 10 words
0 / 20 words
REAL TOOL — University of Lille research project

You don't need to give a website your name for it to identify you. Your browser and device quietly hand over a combination of details — screen size, fonts, timezone, installed extensions — that can be unique enough to track without cookies. This tool shows your current fingerprint.

0 / 10 words
0 / 20 words
Part 6 — Scenarios: spot the power-up
Scenario 1 — Impersonation

Your grandmother gets a call that sounds exactly like your voice, panicked, saying you're stranded and need money sent to a link right away. She almost sends it — until your mom happens to text you and finds out you were in class the whole time, phone off.

0 / 20 words
0 / 20 words
Scenario 2 — AI-Written Phishing

A message shows up in the school's shared inbox, written in flawless, professional language, claiming to be from the district's IT office. It asks staff to "verify" their login by clicking a link before the end of the day or lose account access.

0 / 20 words
0 / 20 words
Scenario 3 — Data Extraction & Manipulation

A student finds that phrasing a question a certain way makes a school chatbot repeat a private policy document it was never supposed to share. Separately, someone posts fake "facts" about the school's wifi rules on a public forum, hoping a future AI tool trains on it and repeats the false claim as true.

0 / 20 words
0 / 20 words
Scenario 4 — AI-Powered Reconnaissance

An attacker spends ten minutes with an AI tool scanning a student's public accounts and their friends' accounts. Within minutes, they know the student's team schedule, favorite hangout spot, and best friend's name well enough to send a message that feels personal and believable.

0 / 20 words
0 / 20 words
Scenario 5 — AI-Assisted Malware

A low-skilled attacker with no real coding background uses an AI coding assistant to modify a piece of malware they downloaded, tweaking it just enough that the school's antivirus software no longer recognizes it.

0 / 20 words
0 / 20 words
Part 7 — Defending against AI-augmented attacks
On your own
  • Verify urgent requests through a channel you already trust — call the person back on a number you already have, not one from the message itself.
  • Stop trusting "it sounds/reads legitimate" as proof — polish is no longer a reliable signal.
  • Set a code word with close family for real emergencies.
  • Assume anything you post publicly could get scraped, and think about the people connected to you, not just yourself.
At an organization
  • Require independent verification before acting on any financial or account-access request.
  • Don't rely on authentication that itself depends on a single channel an attacker could fake, like voice.
  • Keep security training updated for AI-era threats, not just older phishing patterns.
  • Treat urgency and secrecy ("don't tell anyone else") as red flags on their own.
0 / 25 words
Part 8 — Completion summary

Your answers autosave in this browser as you type — refreshing won't lose your work. Nothing uploads until you print.

Sharing this computer with another class? Click "Clear My Answers" when you're done so the next student starts fresh.