Youth

Digital Identity, Privacy & Scams: Keep Your Accounts (and Your Club’s) Safe

Between phishing emails, fake giveaways and deepfake audio, the internet’s a wild place. A few simple systems will protect you and your club — and they don’t require being “techy”.

Why this matters for lifesavers

You might run a patrol Instagram, hold spreadsheets with member contacts, or receive invoices/sponsor emails. That’s real data and real reputation on the line. Good hygiene protects young people’s privacy, keeps sponsors confident, and saves you hours of clean‑up if something goes wrong.

Five moves that do 80% of the security work

  1. Password manager → one long, unique password per site, stored securely. No more reusing the same 3 passwords.
  2. Multi‑factor authentication (MFA) → a one‑time code or prompt on your phone. Turn it on for email, banking, socials, cloud storage.
  3. Auto‑updates on → phones, laptops, browsers. Patches fix holes scammers actively exploit.
  4. Phishing filter → pause on anything “urgent”, “secret”, or “too good to be true”. Verify by calling a known number.
  5. Back‑ups → automatic cloud/back‑up drive of your most important files and photos.

Social media hygiene (personal & club)

  • Role‑based access: For club pages, use shared role emails (e.g., comms@) and Business Manager/Meta Roles, not one person’s private account.
  • Onboarding/offboarding: When a volunteer leaves, remove their access the same week.
  • Consent first: Youth images/videos need explicit consent; store approvals in one shared folder.
  • DM boundaries: Keep youth comms in official channels with another adult looped in where practical.

Spot the scam patterns (with examples)

  • “Change of bank details” email from a sponsor? Call the contact you already know (not the number in the email) before paying.
  • Prize messages asking for a “release fee”? Real prizes don’t require a payment.
  • Look‑alike domains: lifesavlng.com.au (with an “l” instead of an “i”). Check the address carefully.
  • QR code traps: If a QR takes you to a login page, navigate to the site manually instead.

Deepfakes and AI fakes

If you receive a voice note “from the President” asking for urgent gift cards or passwords, assume it’s fake until verified via a known channel. For official announcements, cross‑check on multiple club channels.

Data minimalism (collect less, store better)

  • Only keep what you need (name, email, phone). Delete old spreadsheets with personal info after the season.
  • Store sensitive docs in shared cloud folders with access controls — not on random USBs.
  • If your device with club data is lost/stolen, tell a committee lead quickly so they can revoke access and notify the right people.

Incident response: what to do if something feels off

  1. Stop and document: Take screenshots of the suspicious message/site.
  2. Change passwords to affected accounts; enable MFA immediately.
  3. Notify your Club Administrator/IT contact; log what happened and what data may be impacted.
  4. Inform any affected people with a calm, factual note and practical next steps (e.g., “change your password”).
  5. Review & learn: What control failed? Update a checklist so it doesn’t happen again.

Myth‑busting

  • “I’m too small to be targeted.” Scams are automated; anyone with an inbox is a target.
  • “It’s fine, we’ve never had a problem.” Past luck isn’t a control. Set up systems before you need them.
  • “Long passwords are impossible to remember.” Use a passphrase (four random words) and a password manager.

Takeaway: Small, boring habits prevent most disasters. Set them up once, and you’re ten times safer.