JHS Portal/Computing / ICT/Cybersecurity, Malware & Data Protection
All Topics
ICTJHS 1 • Term 3Topic 14Free Trial Lesson

Cybersecurity, Malware & Data Protection

Understand malware types (viruses, worms, trojans, spyware, ransomware), phishing scams, strong password construction, and data backup.

Curated Video Lesson

Visual explanation and practical step-by-step walk-through

Watch on YouTube

Comprehensive Study Notes

Aligned with Ghana NaCCA & WAEC BECE syllabus standards

Topic Introduction & Real-World Context:

As Ghana's economy becomes digitized through mobile money, online banking, social media, and digital school portals, cybercrime has emerged as a major national threat. Malicious software (malware), phishing scams, and identity theft cost individuals and businesses millions of cedis annually. Practicing cybersecurity, recognizing fraudulent scams, and safeguarding personal data protect our digital lives.

What You Will Master in This Lesson (NaCCA Objectives):

Define cybersecurity and analyze major types of malware: Viruses, Worms, Trojan Horses, Spyware, and Ransomware.
Identify social engineering and phishing tactics used by online scammers.
Formulate robust data protection habits: Strong passwords, two-factor authentication, firewalls, and regular backups.
Understand the legal and moral consequences of cyber fraud (sakawa) in Ghana.

1. What is Cybersecurity? The Threat of Malware

Cybersecurity is the discipline and practice of defending computer networks, devices, software programs, and electronic data from unauthorized access, digital attacks, theft, or damage. • What is Malware? (Malicious Software): Any software intentionally designed to cause damage to a computer, server, client, or computer network: 1. Computer Virus: - A malicious program that attaches itself to legitimate host files or executable software. It activates and replicates only when the infected host program is executed by the user, corrupting files and degrading system performance. 2. Computer Worm: - A standalone self-replicating malware program that spreads automatically across local networks and the Internet without needing to attach to a host file. Consumes network bandwidth and crashes servers. 3. Trojan Horse: - Malware disguised as a harmless, desirable software application (e.g. a free game, screensaver, or media player). Once downloaded and installed, it secretly opens backdoors allowing hackers to access the victim's computer. 4. Spyware & Keyloggers: - Software that secretly installs itself to monitor user activities, track browsing history, and record keystrokes (keylogger) to steal passwords and credit card credentials. 5. Ransomware: - Dangerous malware that encrypts all files on a computer, demanding an extortion payment (ransom) in cryptocurrency before providing a decryption key.
Key Takeaway: Viruses need a host file; Worms spread independently across networks; Trojans disguise as safe apps; Spyware steals passwords.
Real-World Application: Plugging an infected USB flash drive into a school lab PC can spread a shortcut virus that hides all documents.

2. Social Engineering and Phishing Scams

Not all cyber threats rely on complex code; many manipulate human psychology: • What is Phishing? A fraudulent technique where cybercriminals send deceptive SMS messages, emails, or fake web links impersonating trusted institutions (banks, MTN MoMo, WAEC) to trick victims into revealing sensitive personal data (PINs, passwords, Ghana Card numbers). • Telltale Signs of a Phishing Attempt: 1. False Urgency: Demands immediate action ('Account will be blocked in 1 hour!'). 2. Suspicious Web Links: Misspelled domain URLs (e.g. 'www.momo-gh-verify.com' instead of official telecom portals). 3. Requests for Confidential Credentials: Legitimate banks NEVER ask customers for secret PINs via phone calls, SMS, or emails! 4. Poor Grammar and Spelling: Scams often feature awkward English phrasing.
Key Takeaway: Phishing deceives victims into revealing secret PINs and passwords; legitimate banks never request PINs via SMS.
Real-World Application: Receiving a text: 'You have won GHS 50,000! Send your MoMo PIN to claim prize' is an obvious phishing scam.

3. Building Strong Passwords and Defensive Security

Defending personal digital accounts requires proactive security hygiene: • 1. Strong Password Construction: - Length: At least 8 to 12 characters. - Complexity: A robust mixture of UPPERCASE letters, lowercase letters, numbers (0–9), and special symbols (@, #, $, %, !). - Unpredictability: Never use personal names, birth years ('kofi2008'), or sequential numbers ('123456'). - Example of Strong Password: 'Tr0p!c@l#Accr@2026'. • 2. Two-Factor Authentication (2FA): - Requires two separate verification steps before logging in: 1. Password + 2. A temporary one-time SMS code (OTP) sent to your mobile phone. • 3. Antivirus Software & Firewalls: - Antivirus: Software that continuously scans hard drives, memory, and downloads to detect, quarantine, and eliminate malware (e.g. Windows Defender, Kaspersky). - Firewall: A security filter that monitors incoming and outgoing network traffic, blocking unauthorized hacking connections. • 4. Regular Data Backup: - Always maintain duplicate copies of essential files on an external hard drive or cloud storage (Google Drive). If ransomware attacks, files can be restored without paying a dime!
Key Takeaway: Use complex passwords with symbols, enable 2FA, keep antivirus updated, and maintain regular backups.
Real-World Application: Enabling two-factor authentication on a Google account blocks hackers even if they guess your password.

4. Legal and Ethical Responsibilities (Cybercrime Laws)

Under Ghana's Cybersecurity Act (Act 1038) and the Electronic Transactions Act: - Engaging in cyber fraud (sakawa), hacking computer systems, stealing data, or circulating non-consensual private imagery is a severe felony carrying heavy prison sentences. - Good Digital Citizenship: Respecting others' intellectual property, avoiding pirated software, and protecting national cyber infrastructure.
Key Takeaway: Cybercrime carries severe prison sentences under Ghanaian law; practice ethical digital citizenship.
Real-World Application: The Cyber Security Authority (CSA) of Ghana monitors online threats and coordinates the arrest of cyber fraud syndicates.
Common Mistakes Students Make in BECE Examinations:
⚠️Using the same simple password ('123456' or your name) across all social media and email accounts.
⚠️Believing that an antivirus program never needs updating (it must be updated regularly to recognize new virus definitions).
⚠️Sharing your secret MoMo or banking PIN with someone claiming to call from the telecom office.
⚠️Assuming computer worms and viruses are identical (worms replicate across networks without host files; viruses require a host file).
Teacher's BECE Exam Pro-Tips:
⭐In BECE Section A, contrast Virus (requires human action and host file) with Worm (replicates independently across networks).
⭐Name 3 types of malware: Virus, Worm, Trojan Horse, Spyware, Ransomware.
⭐List 3 components of a strong password: Uppercase letters, lowercase letters, numbers, and special symbols.
Quick Revision Summary Checklist:
Can define cybersecurity and differentiate viruses, worms, and trojans.
Understand phishing scams and recognize suspicious indicators.
Know how to construct a strong password and explain Two-Factor Authentication (2FA).
Can explain the importance of antivirus software, firewalls, and regular backups.

Step-by-Step Worked Examples (2)

Real BECE exam-standard problems with complete solution steps

Example 1: Recognizing a Phishing Scam
Problem StatementA student receives an SMS: "Urgent! Your MoMo account has been blocked. Click http://bit.ly/momo-fix to enter your 4-digit PIN immediately." Identify two indicators that this is a phishing scam.
Step-by-Step Solution:

Indicator 1: Creating false urgency and panic ('Urgent! Account blocked') to prompt hasty action without thinking.

Indicator 2: Requesting private security credentials (PIN). Legitimate financial institutions and telecommunication providers NEVER ask customers to provide secret PINs via web links.

💡
Key Takeaway / Exam Rule: Never share secret PINs or passwords through SMS or unsolicited web links.
Example 2: Designing a Strong Password
Problem StatementEvaluate the password 'kofi123' and explain how to transform it into a highly secure password.
Step-by-Step Solution:

Step 1 (Evaluation): 'kofi123' is extremely weak because it uses a common first name, predictable sequential numbers, and lacks uppercase letters or symbols.

Step 2 (Transformation): Apply complexity rules: combine uppercase, lowercase, numbers, and symbols: 'K0f!#Accr@2026'. This resists brute-force dictionary attacks.

💡
Key Takeaway / Exam Rule: Strong passwords combine uppercase, lowercase, numbers, and symbols without predictable names.
Mastery Diagnostic Quiz

Ready to test your knowledge on Cybersecurity, Malware & Data Protection?

Timed computerized test with instant feedback, scoring, and comprehensive question rationales.