Phishing defense · for K-12 districts

BlueHook

simulation · training · email threat removal

Staff report a suspicious email with one click. We pull it out of every inbox in the district.

Your staff are the target. We train them, and when something slips through we remove the real thing everywhere it landed — read, unread, forwarded or filed.

Outlook and GmailStaff and student trainingDistrict-wide removalBoard-ready evidence
Reported: “Updated remittance details”5 mailboxes
front.office@ reported itone click, OutlookInvestigating
accounts.payable@readRemoved
principal.north@unreadRemoved
hr@forwardedRemoved
transport@filedRemoved
What it isA managed phishing program: simulations, short training, one-click reporting, and analyst-led removal of real threats.
Who it is forAny district where staff have email. The bookkeeper, the substitute, the principal’s name being borrowed.
What you getFewer clicks, more reports, and a real phishing email gone from every mailbox in one action, with the record to prove it.

How it works

From reported to removed, usually before it spreads.

1Staff report

One button in Outlook or Gmail. No forwarding, nothing to remember. We ask whether they clicked or entered a password, without blame.

2We investigate

Headers, links, attachments, sender authentication and reputation. The verdict is evidence-based, not a guess.

3We find every copy

We search every mailbox in the district to establish the true blast radius. One report rarely means one recipient.

4We remove and close the loop

Quarantine or delete everywhere in one action, reversible if it turns out to be legitimate. The reporter is thanked. Your team is told.

Inside BlueHook

One reported email, start to finish.

Seven minutes on a Tuesday morning. The front office clicks one button; everything after that is us.

08:12 · Staff
Outlook · front.office@08:12
Inbox 3
Sent
Drafts
Archive
⚑ Reported
⚑ Report phishingone click
Quick favor — are you at your desk?Dan Mills <principal.mills.office@gmail.com>

I’m stuck in a meeting and need you to pick up four $100 gift cards for a staff appreciation thing today. I’ll reimburse you. Send me the codes when you have them.

✓ Reported. Thanks — an analyst is looking at it now.
She reports it

The button is in Outlook and Gmail. No forwarding, nothing to remember.

08:14 · Analyst
Analyst · investigation08:14
  • ×Sender domain is gmail.com, not the district. Display name borrowed from the principal.
  • ×Urgency, secrecy and gift cards: the three tells of a payroll-style scam.
  • ×Reply-to points at a second mailbox registered 3 days ago.
  • Search of every district mailbox: the same message reached 4 other people.
Malicious · remove everywhere Reporter told she did the right thing. No blame, no quiz.
We investigate it

Headers, sender, links, and a search of every mailbox to find the true blast radius.

08:19 · District
Removal · district-wide08:19
front.office@reportedRemoved
accounts.payable@readRemoved
principal.north@unreadRemoved
hr@forwardedRemoved
transport@filedRemoved
Sender blockedCase logged7 minutes, report to removal. Your team was told, not tasked.
We remove it everywhere

Read, unread, forwarded or filed. Reversible if it turns out to be legitimate.

Simulations · click rate by campaign2026–27
18% → 5%click rate, Sep to Jan
22% → 61%reported within 10 min
438staff enrolled
18%Sep · Payroll update
12%Oct · Vendor invoice
9%Nov · Principal favor
5%Jan · Benefits
Where the clicks areauto-assigned training
RoleClickedNow assigned
Substitutes5Spoofed principal
Business office3Bank-detail change
Coaches2Gift-card asks
Front office1Done

Whoever clicks gets the thirty-second lesson for that exact scam. The student academy runs separately, by grade.

What is included

A complete program, not a single tool.

Active threat manager

A live queue of everything your staff report, triaged and investigated by us, with a full audit trail.

District-wide remediation

Search every mailbox, quarantine or delete in one action, restore instantly if safe, block the sender going forward.

Phishing simulations

Realistic templates written for school roles, scheduled and run for you, with per-user and per-campaign results.

Staff training library

Forty-plus short, plain-English lessons on real district scenarios, with knowledge checks and completion tracking.

Student academy

Age-appropriate digital-safety lessons students actually engage with. Assign by class or grade.

Compliance and reporting

Training completion by staff member, trend reporting, highest-risk users, and board-ready PDF reports.

What you get to keep

Evidence your board and your insurer will accept.

Training records by name

Who completed what, when. Exportable for audits and insurance renewals.

Every action logged

Who did it, when, why, and how many inboxes were affected. Yours to keep.

Reporting for people who are not in IT

Risk down, reporting up, one page a month a superintendent can read.

Questions districts ask

Before you call

Does it work with Google Workspace?

Yes. BlueHook works with both Microsoft 365 and Google Workspace. The report button sits in Outlook or Gmail.

What does my technology team have to do?

Authorize the connection once. After that, nothing is required for the loop to run. They see every alert and can act themselves if they prefer.

How fast is a real threat removed?

Illustratively, minutes from report to removal. Timings are relative, not a contractual commitment.

Can training be assigned to substitutes and new hires?

Yes. Shareable links make onboarding and substitutes simple, and completion is tracked per person.

Get started

Tell us what you are being asked to prove.

An insurance renewal, a state review, a board question. We will tell you which program answers it, or that none of them do. Straight answer, fixed quote, from the engineer who would do the work.

1-888-528-8948

Reply within one business day. No sales sequence, no mailing list.