Home Articles Get your free assessmentComing soon

Author: Mission Defend Staff

  • Your Pastor Won’t Text You for Gift Cards: The Impersonation Scam

    Your Pastor Won’t Text You for Gift Cards: The Impersonation Scam

    If you work at a church, you have probably already seen this one. If you haven’t, you will.

    A member of your congregation gets a text from an unfamiliar number:

    Hello, are you available? I need a favor. — Pastor Mike

    Or an email lands in a volunteer’s inbox. The sender name says Pastor Mike Adams, exactly as it appears in every other message from him. The subject line is Quick request. The body is two sentences.

    Are you free right now? I’m in a meeting and can’t talk on the phone, but I need something handled discreetly.

    Anyone who replies gets the ask. The church needs to buy gift cards — Apple, Google Play, Amazon, Target — for a member in the hospital, or for a benevolence case, or as thank-you gifts for volunteers. The pastor will reimburse them. It’s urgent, it’s a little sensitive, and could they please just scratch off the backs and send photos of the codes?

    This scam runs constantly, in every denomination, in churches of every size. It is worth understanding precisely, because the mechanics are simpler than most people assume — and so is the fix.

    Nobody hacked anything

    The most important thing to understand: in almost every version of this scam, the pastor’s account was never broken into.

    That surprises people, because the message looks like it came from him. But the attacker didn’t need access. They needed one of two very ordinary tricks.

    Trick one: display name spoofing

    Every email has two separate pieces of sender information, and your mail app shows you one of them.

    The display name is the friendly label — Pastor Mike Adams. The email address is the actual routing information — mike@yourchurch.org.

    Here’s the thing that makes this scam work: the display name is just text. Anyone can type anything they like into it. There is no verification, no check, no ownership requirement. I can create a free email account right now and set my display name to “Pastor Mike Adams,” and every message I send will show up in your inbox with that name on it.

    The real address underneath would be something like `pastormike.adams247@gmail.com` or `mike.adams.church@outlook.com` — plausible enough that if you did glance at it, it might not alarm you.

    And on a phone, you usually can’t glance at it. Mobile mail apps show the display name and hide the address entirely to save screen space. That is not a bug in your phone. It’s a design choice that this scam exploits, and it’s why these messages so often get read and answered on a phone rather than a desktop.

    Trick two: an unfamiliar phone number

    The text-message version is even simpler. There’s no spoofing at all. The attacker just texts from a number you’ve never seen and signs the message with the pastor’s name. Because a new number shows up with no contact photo and no history, and because plenty of people do change phones, “Hi, this is Pastor Mike, I got a new number” is not automatically suspicious.

    Where do they get the names and numbers? Nowhere clever. Your staff page lists who your pastor is. Your bulletin names your office administrator. Your Facebook page shows who volunteers. Church directories get shared. None of that is a security failure — it’s a church being findable, which is the point of a church. But it means an attacker can build a convincing message with fifteen minutes of public browsing.

    Why gift cards specifically

    This is the detail that gives the scam away, once you know it.

    Gift cards are, for a criminal, close to perfect. They are effectively untraceable — once the code is spent, there’s no account holder to subpoena and no transaction to reverse. They are instantly transferable — a photo of the scratched-off code is all that’s needed; the physical card is irrelevant. They are irreversible — unlike a credit card charge or even a wire transfer, there is no dispute process and no recall window. And they are available everywhere, which means a victim can complete the whole request in twenty minutes at a grocery store.

    Compare that to a bank transfer, which leaves a paper trail, involves an institution that can freeze funds, and requires the criminal to maintain an account somewhere.

    So here is the rule that flows from that, and it’s worth putting in bold in your bulletin:

    No legitimate church request will ever involve buying gift cards and sending photos of the codes. Not for benevolence. Not for a hospital visit. Not for volunteer appreciation. Not ever. There is no scenario in normal church operations where that is how money moves.

    That single sentence, taught once, immunizes most people permanently — because it doesn’t require anyone to evaluate whether a particular message looks legitimate. It just makes the ask itself the tell.

    The wider pattern

    Gift cards are the most common version, but the same impersonation gets used for other requests, and your team should recognize the family resemblance:

    A request to wire funds urgently for a deposit or a contractor, before end of business.

    A request to buy cryptocurrency and send it to a wallet address.

    A request for the staff list, the member directory, or W-2 information — no money at all, just data, which then gets used for the next attack or sold.

    A request to buy something on your personal card and be reimbursed later, which is really just gift cards with extra steps.

    The shape is always the same: authority, urgency, a reason you can’t verify by voice right now, and a request that moves value in a way that can’t be undone.

    What the FBI data says

    This isn’t folklore. Phishing and spoofing were the most-reported cybercrime in America in 2025, with 191,561 complaints filed with the FBI’s Internet Crime Complaint Center.

    The demographic detail matters for congregations. Victims aged 60 and over filed 201,266 complaints in 2025, losing $7.748 billion — a 59% increase over the previous year, averaging $38,500 per victim. Older members of your congregation are being targeted heavily, and a warning from their church may be the most credible one they receive.

    How to shut it down

    Four things. None of them take money, and the first two take an afternoon.

    Tell your congregation, in plain words, from the front. Not a technical bulletin insert nobody reads — a spoken sentence, from the platform or in the newsletter, in the pastor’s own voice: “I will never text or email you asking for gift cards, money, or a favor involving payment. If you get a message like that with my name on it, it isn’t me. Please don’t reply, and please tell the office.” Coming from the person being impersonated, this lands differently than a security notice.

    Teach the one habit that works on a phone. Before acting on any message asking for money or a favor, tap the sender’s name to reveal the actual email address. On a text, check whether the number matches the one already in your contacts. If it doesn’t, that’s your answer. This takes three seconds and doesn’t require anyone to be technical.

    Make verification impersonal and expected. Write down that any money-related request is confirmed by voice, using a number you already had — not a number in the message. Say explicitly that this applies to requests that appear to come from leadership, and that nobody will ever be thought disloyal for making the call. That last clause is doing real work: the reason these scams succeed in churches is that questioning the pastor feels wrong.

    Turn on the technical guardrails. Two settings help meaningfully. First, multi-factor authentication on every staff email account — the extra code or tap after the password — which protects you in the cases where an account really is compromised rather than merely imitated. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Second, ask whoever manages your email to enable external sender warnings, the banner that says “This message came from outside your organization.” When a message claims to be from your pastor and carries that banner, the contradiction is visible even on a phone.

    If you want to go further, the fuller fix is email authentication — the SPF, DKIM and DMARC records that stop strangers sending mail that claims to come from your domain at all. That’s a bigger topic, and it’s coming later in this series.

    If someone already bought the cards

    Move fast; there’s a narrow window.

    Call the gift card issuer’s fraud line immediately — the number is on the back of the card or on the retailer’s website — and report the cards as fraudulently obtained. Occasionally, if the codes haven’t been spent, funds can be frozen. Keep the physical cards and the receipts; they’re evidence and they’re required for any claim.

    Report it to the FBI at ic3.gov. This feels pointless for a few hundred dollars, and it isn’t: the aggregate reporting is what drives takedowns, and it’s how the pattern gets tracked.

    Then tell your congregation what happened, without naming the person who was fooled. Someone who admits they were scammed has done your whole community a service, and how you treat them determines whether the next person speaks up in twenty minutes or three days.

    What to do this week

    Write four sentences and send them to your congregation under your pastor’s name: I will never text or email you asking for gift cards or money. If you get a message like that with my name on it, it isn’t me. Don’t reply. Tell the office.

    That’s it. That’s the highest-value fifteen minutes available to most churches this month.

    When you’re ready to look at the whole picture rather than one scam at a time, MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts — then give you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.

  • Social Engineering: Why Attackers Target Your People, Not Your Firewall

    Social Engineering: Why Attackers Target Your People, Not Your Firewall

    The email arrived at 8:52 on a Tuesday morning. It was from the pastor — his name, right there in the sender line — and it was short.

    Are you at your desk? I need you to handle something for me. I’m in a meeting so I can’t take calls.

    The office administrator wrote back that yes, she was at her desk. What did he need?

    Nothing about that exchange involved breaking into anything. No password was cracked. No virus was installed. No firewall was bypassed. And yet, ninety minutes later, the church was out $1,800 in gift cards.

    This is social engineering, and it is the single most common way churches and nonprofits lose money and data. Not because your organization is careless. Because it is the way the overwhelming majority of attacks now work, everywhere, and because the things that make a ministry good at being a ministry are the same things that make social engineering effective.

    What “social engineering” actually means

    The phrase sounds like jargon, and it is — but the idea underneath it is simple.

    Social engineering is persuading a person to do something, rather than forcing a computer to do it.

    That’s the whole definition. An attacker who breaks encryption is doing technical work. An attacker who convinces your bookkeeper to change a vendor’s bank details is doing social work. The second is dramatically easier, dramatically cheaper, and requires no special skill beyond patience and a plausible story.

    It helps to think of it the way you’d think about a con artist in any other era. The technology is new. The technique is not. Someone is establishing a reason you should trust them, creating a situation where checking feels rude or slow, and asking for something that seems small in the moment.

    You’ll see a lot of specific names for these attacks, and the vocabulary can feel like a wall. Here is the map, in plain terms:

    Phishing is social engineering delivered by email — a message designed to get you to click, log in, or reply. The name is a play on “fishing,” because early versions cast a wide net and waited.

    Spear phishing is the same thing aimed at one specific person, using details about them. A spear instead of a net.

    Vishing is voice phishing — the scam arrives by phone call.

    Smishing is SMS phishing — it arrives by text message.

    Pretexting is the invented backstory that makes the request feel routine. “I’m calling from your insurance carrier about the annual audit” is a pretext.

    Business email compromise, usually shortened to BEC, is the category where someone impersonates a leader or a vendor to redirect a payment.

    Every one of those is a flavor of the same thing. Someone is talking to a human being and asking them to act.

    The numbers, and why they matter to a small office

    It’s tempting to read all this and assume it’s a problem for banks. The federal data says otherwise.

    The FBI’s Internet Crime Complaint Center — the government’s clearinghouse for reported cybercrime, usually called IC3 — logged 1,008,597 complaints in 2025, with just under $20.9 billion in reported losses. Within that, phishing and spoofing generated 191,561 complaints, making it the single most-reported crime type in the country.

    Business email compromise accounted for 24,768 complaints and more than $3 billion. Divide those out and the average reported loss per BEC report was about $123,005.

    Now hold that number against a church budget. For most congregations, a single successful impersonation email costs more than a quarter’s giving. And note what didn’t appear anywhere in that description: malware, hacking tools, technical sophistication. It required someone to believe an email.

    There’s one more figure worth sitting with, because it touches your congregation rather than your office. IC3 recorded 201,266 complaints from victims aged 60 and over in 2025, with $7.748 billion in losses — a 59% increase over the prior year, and an average loss of $38,500 per victim. The people in your pews are being targeted, and many of them will hear about it from you before they hear about it from anyone else.

    The six levers

    Every social engineering attack pulls on at least one of six psychological levers. Once you can name them, you start noticing them, and noticing is most of the defense.

    Authority. The request appears to come from someone you don’t question — the pastor, the executive director, the board chair, the bank, the IRS. Authority short-circuits the instinct to verify, because verifying feels like doubting your boss.

    Urgency. There’s a deadline, real or invented. Before noon. Before the wire cutoff. Before the account is suspended. Urgency exists to prevent you from doing the one thing that would defeat the attack: pausing.

    Familiarity. The message uses the right names, the right tone, the right details. It mentions the building project by name. It knows your treasurer is called Deb, not Deborah. Familiarity is why these messages feel real — and it’s cheap to manufacture, because your staff page, bulletin, Facebook posts, and public filings are all free research material.

    Fear. Something bad will happen. Your mailbox will be deleted. Your account is compromised. There’s a legal problem. Fear narrows attention to the threat and away from the oddities in the message.

    Curiosity. An unexpected invoice. A shared document. A photo from the retreat. Curiosity is the lever behind most malicious attachments, because opening something to find out what it is feels harmless.

    The wish to be helpful. This is the one that matters most in ministry, and the one nobody wants to hear. Churches and nonprofits are staffed by people whose whole disposition is to help quickly, assume the best, and not interrogate someone who asks for something. That disposition is a virtue. It is also, precisely, the surface an attacker aims at.

    That last point deserves care. The lesson is not that your team should become suspicious of everyone. A congregation that treats every request as a threat has lost something more valuable than the money. The lesson is narrower and much more manageable: for a very small number of specific actions, verification becomes automatic and impersonal — not a judgment about the person asking, just the way that particular thing is always done.

    Why small organizations get chosen

    Three structural facts make churches and nonprofits attractive, and none of them are about carelessness.

    You hold valuable, irreplaceable data. Donor giving histories, member contact lists, background check results, counseling notes, children’s ministry records. Some of it has resale value. Some of it is simply devastating if it becomes public.

    Your money moves in ways that are hard to verify. Offerings, designated gifts, benevolence funds, reimbursements, contractor payments during a building project. Transaction volume is low enough that one fraudulent payment doesn’t stand out, and approval processes are usually informal because the team is small and trusts each other.

    And your information is public by design. A business hides its org chart. A church publishes it — with photos, titles, email addresses, and often direct phone numbers — because that’s how people find their pastor. An attacker doesn’t need to breach anything to learn who your finance person reports to.

    What actually stops it

    Because the attack targets people, the defense has to work at the level of people. Three things carry most of the weight, and none cost money.

    One rule, written down, about money. Any request to move funds, change bank details, or buy gift cards is verified by voice, using a phone number you already had — not a number in the message. Not by replying to the email. The attacker controls the email thread; they do not control the number in your directory. Write this rule down, tell everyone who touches money, and state plainly that nobody will ever be criticized for following it. The failure this prevents is a bookkeeper who feels too junior to question leadership.

    Permission to be wrong. The most expensive incidents are not the ones where someone got fooled. They’re the ones where someone got fooled and then waited three days to say so, hoping it would resolve itself. A misdirected payment caught in twenty minutes is often recoverable — the FBI’s Recovery Asset Team froze over $507 million across 3,574 domestic cases in 2025, and that process depends almost entirely on speed. The same mistake caught on Friday afternoon usually is not. Tell your team, in words, that reporting a mistake immediately is the desired behavior and will never be held against them.

    Fifteen minutes, twice a year, on real examples. Not an hour-long generic video. Show your actual staff the actual scams aimed at churches: the gift card request, the fake invoice from a vendor you really use, the “your mailbox is full” notice. Recognition is trainable. Familiarity with the specific shape of these messages is what makes someone pause.

    The rest of this series

    Over the coming weeks we’re going to take these apart one at a time — the gift card scam, business email compromise, payroll diversion, phone and text scams, AI voice cloning, and the rest. Each post explains one attack in plain language, shows what the message actually looks like, and ends with what to do about it.

    The goal isn’t to make you afraid of your inbox. It’s to make these attacks boring — familiar enough that when one arrives, someone on your team recognizes the shape of it and doesn’t have to guess.

    What to do this week

    Pick one thing. Write down the verify-by-voice rule for money requests, send it to everyone who touches a payment, and say explicitly that following it is never rude. That single paragraph, circulated once, closes the most expensive category of attack aimed at organizations like yours.

    MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts, then give you a baseline score and a ranked list of what to fix first. It’s launching soon — leave your email and we’ll tell you the moment it opens.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • How to Protect Member and Donor Information at Your Church

    How to Protect Member and Donor Information at Your Church

    When someone fills out a visitor card, gives online, signs their child into the nursery, or sits down with a pastor for a difficult conversation, they are handing your organization something. Not just information — trust. They are assuming that what they shared stays where they put it.

    That assumption is doing a lot of quiet work. It is why people give, why they volunteer, and why they tell you things they have not told anyone else. A breach does not just cost money. It spends down the one asset a church cannot replace.

    The good news is that protecting this information is mostly about a handful of decisions, not about buying technology. Here is how to work through them.

    Start by knowing what you actually hold

    Almost no church can answer the question what personal information do we have, and where is it? Not because anyone is careless, but because the data accumulated over years, across systems, added by different people.

    Spend an hour making a list. Not a formal data inventory — a list. Walk through it in categories.

    Your church management system holds names, addresses, phone numbers, family relationships, attendance, and often giving history. Your accounting system holds giving records, and possibly bank account details for recurring givers and staff. Your online giving platform holds payment information, though ideally your organization never sees full card numbers. Email holds everything anyone has ever sent, which in practice is the most sensitive collection you own. Shared drives hold spreadsheets — and these are the ones that surprise people, because someone exported the full member list to a spreadsheet in 2023 for a mailing and it is still sitting in a folder. Children’s ministry check-in holds minors’ names, guardians, allergies, and photo permissions. Background check results and personnel files may be in a filing cabinet, an email attachment, or both. And pastoral care notes, if they exist in writing anywhere, are the most sensitive records in the organization.

    Write down where each lives and who can get to it. This list is the foundation for everything else, and making it usually surfaces at least one thing that should not exist anymore.

    Decide who should see what — then enforce it

    The most common serious problem is not hackers. It is that far too many people inside the organization can see far more than their role requires.

    This happens innocently. A volunteer needed admin rights for one project three years ago. A staff member changed roles but kept old permissions. The database was set up by someone who gave everyone full access because it was simpler.

    Work through it role by role rather than person by person. Ask what a nursery volunteer genuinely needs: the children and guardians they are checking in that morning, and nothing else — certainly not giving history. A small group leader needs contact details for their group. The finance team needs giving records. The senior pastor may need broad access, but “may” is worth examining. Most administrative tasks do not require seeing what individual families give.

    Then apply two principles that carry most of the weight. Give the least access that lets someone do their job, and give it for as long as they hold that role, not permanently. And treat giving records as a separate, tighter category than contact information — in most churches, far more people can see giving history than have any business seeing it, and members would be startled to learn who.

    Put a recurring calendar reminder every quarter to review the user list in your church management system, your email admin console, and your accounting software. Ten minutes, four times a year.

    Protect the accounts that open the doors

    All the access control in the world does not help if someone simply logs in as your administrator.

    Email is the master key, because it resets every other password — protect it first and hardest. Every staff member and every volunteer with access to member data should have multi-factor authentication enabled. This is the highest-value change available to you, it is free on both Microsoft 365 and Google Workspace, and it takes an afternoon.

    Get rid of shared logins. One password to the database that six people know means you cannot revoke one person’s access, cannot tell who exported what, and cannot investigate anything. Give people individual accounts. Where a shared credential genuinely cannot be avoided, put it in a password manager with proper sharing so at least it can be rotated when someone leaves.

    And close the door behind people who go. The most common way former volunteers retain access to member data is that nobody remembered to turn the account off. Add it to whatever departure process already exists.

    Stop collecting what you do not need

    Every piece of information you hold is a piece you have to protect. The cheapest security measure in existence is not having the data.

    Look at your visitor card and your event registration forms. Are you asking for a date of birth you never use? A Social Security number you have no business collecting? A home address for an event that does not need one?

    Then look backward. That 2019 mailing list export, the old volunteer applications, the spreadsheet of every attendee from a conference you hosted — if it has no current purpose, deleting it removes risk permanently. Write down a simple retention rule so this does not require judgment every time. Something as plain as contact records are kept while someone is connected to the church and for three years after; giving records are kept as long as tax rules require; visitor cards are entered into the database and then shredded is enough. Confirm the financial retention periods with your accountant, since those are set by tax and audit requirements rather than by preference.

    Handle the most sensitive records differently

    Some categories deserve stricter treatment than the general membership database, and it is worth being deliberate about them.

    Counseling and pastoral care notes. If these exist in writing, they should be the most tightly held records you have — accessible to the minister involved and essentially nobody else, and never stored in a shared drive or general email folder. Confidentiality expectations here are both ethical and, in many states, legally significant. Talk to counsel about how privilege applies in your jurisdiction before deciding where these live.

    Children’s ministry records. Minors’ information, guardian details, allergies, photo permissions, and check-in history. Access should be limited to current children’s ministry leadership, reviewed every term as volunteers rotate, and separated from the general directory.

    Background checks. These frequently end up as email attachments, which is the worst possible place for them. They belong in a restricted personnel file with access limited to the one or two people responsible for screening.

    Anything about giving. Members generally assume their giving is known to a very small number of people. Make that assumption true.

    Make sure your vendors are holding up their end

    Most of your member data is not on your premises. It is on servers belonging to your church management software company, your giving platform, your email provider, and your backup service. Their security is your security.

    You are entitled to ask, and a good vendor will answer without evasion. Ask whether they support multi-factor authentication and role-based permissions, whether data is encrypted at rest and in transit, whether they have a current third-party security report such as a SOC 2, what their notification commitment is if they are breached, and how you would get a full export of your data if you left. That last question matters more than it sounds — your ability to leave is your leverage.

    If a vendor cannot answer these questions, that is itself an answer.

    Get backups right

    Protecting information means protecting its availability, not just its confidentiality. A member database that has been encrypted by ransomware or deleted by accident is a data protection failure too.

    Your church management system, financial records, and shared documents should be backed up automatically, retain several weeks of history, and keep at least one copy that someone with your password cannot reach or delete. Cloud platforms are resilient but they are not backups on their own — a deleted file syncs its deletion everywhere.

    Then restore one file. Pick something from a month ago and bring it back. Untested backups fail at exactly the moment you need them.

    Say what you do, and do what you say

    If you publish a privacy statement — and you should — keep it short and truthful. Members appreciate knowing what you collect, what you use it for, that you do not sell or trade donor lists, who can see giving records, and how to ask for their information to be corrected or removed.

    Do not copy an enterprise privacy policy off the internet. A promise you do not keep is worse than no promise, and a plain paragraph that is accurate does more for trust than three pages of legalese that is not.

    Be aware, too, that data privacy law is expanding and several state laws now reach some nonprofits. This is worth a conversation with counsel rather than a guess, particularly if you operate across state lines or collect information from people outside the United States.

    Train the people who touch the data

    The most likely way member information leaves your organization is not a sophisticated intrusion. It is an email sent to the wrong address, a spreadsheet attached in error, a directory forwarded to someone who asked nicely, or a staff member who fell for an impersonation email.

    Twice a year, spend fifteen minutes with everyone who touches member data on the specific things that go wrong. Check the recipient before sending anything with personal information attached. Never email a full member export — share a link with permissions instead. Verify by phone before acting on any request to change bank details or send money. And report mistakes immediately, because a misdirected email caught in ten minutes is a very different event than one caught in ten days.

    That last point deserves emphasis. Build a culture where people report their own errors without fear. The organizations that get hurt badly are almost always the ones where somebody was too embarrassed to speak up.

    A realistic place to begin

    You will not do all of this in a week, and you do not need to.

    Start with three things. Turn on multi-factor authentication for everyone with access to member data. Pull the user list from your church management system and remove anyone who should not be there. And find out who can currently see giving records, then decide whether that list is right.

    Those three actions, done in a single afternoon, close the gaps most likely to hurt you.

    When you want the full picture — including the parts of this that are easy to miss — MissionDefend’s free assessment will walk you through plain-English questions about how your organization stores member and donor information, who has access, how donations are processed, and how accounts are managed. You get a baseline score and a ranked list of what to fix first, with each fix explained in language you can hand to a volunteer or an outside IT helper.

    It’s launching soon. Leave your email and we’ll tell you the moment it’s ready.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification. Consult qualified legal counsel regarding the privacy and records-retention laws that apply to your organization.

  • Why Your Church or Nonprofit Needs a Cybersecurity Incident Response Plan

    Why Your Church or Nonprofit Needs a Cybersecurity Incident Response Plan

    Ask a church administrator what they would do if they discovered someone had been reading the church email account for three weeks, and you will usually get a thoughtful pause followed by an honest answer: I’d call our IT guy, I guess. And tell the pastor.

    That is not a plan. That is a reasonable first instinct, and it is what almost every small organization has.

    The problem is not that the instinct is wrong. The problem is that the moment you discover a breach is the single worst moment to be making decisions. You will be frightened, you will be short on facts, and you will be under pressure to do something immediately. People make expensive mistakes in that state — deleting evidence, paying an invoice that was never real, telling a congregation something that turns out to be untrue, or quietly hoping it resolves itself.

    A written plan does not make you a security expert. It makes the decisions in advance, while you are calm.

    What actually happens without one

    Consider a realistic sequence. On a Tuesday, your bookkeeper notices that a vendor payment for the roof project went to an account nobody recognizes. Forty thousand dollars.

    Without a plan, the next four hours look like this. The bookkeeper is not sure whether it is a mistake or a crime, and is afraid of being blamed, so she spends an hour checking her own work. Then she tells the executive director, who forwards the email chain to three people, one of whom replies to the attacker’s address asking for clarification. Someone changes the email password, which alerts the attacker that they have been noticed. Nobody calls the bank, because nobody is certain it is really fraud yet. By the time someone does call, it is 5:15 p.m. and the recall window on the transfer has effectively closed.

    Every one of those steps is a reasonable human response. Together they cost the organization the money.

    With a plan, the same Tuesday looks different. The bookkeeper knows that suspected financial fraud is reported immediately to a named person with no requirement to be certain first. That person knows the bank’s fraud line is the first call, not the fourth, because the number is on the plan. Nobody replies to the suspect email chain because the plan says so. The email account is preserved rather than scrubbed. And the organization has a real chance at recovering funds, because the first hour was spent on the right things.

    The difference is not expertise. It is a page of paper.

    Why small organizations put it off

    The objections are all understandable, and all worth answering directly.

    “We’re too small for something that formal.” Formality is not the point. A one-page plan for a five-person office is complete. The enterprise version — with severity tiers and escalation matrices — exists because those organizations have hundreds of people who need to coordinate. You have four, and they can be named individually.

    “Nothing has ever happened to us.” This is genuinely good news, and it is also the reason to write the plan now. You cannot write a plan during an incident. The only time you can write it is when nothing is wrong.

    “We wouldn’t know what to put in it.” This is the honest one, and it is the easiest to fix. The content is not technical. It is mostly phone numbers and decisions about who is allowed to say what.

    “We’d just call our IT person.” Good — write that down, with the number, and with what to do if they do not answer. Also note that most incidents at churches are not technical problems. A wire fraud, a leaked donor list, and an impersonation scam are not things your IT volunteer can fix. They need a bank, a board, and possibly a lawyer.

    What goes in a plan that fits on one page

    You need six things. None of them require a security background.

    Who to tell, and how fast. One named person is the first call for anything suspicious, with a named backup for when they are on vacation. State plainly that staff and volunteers report suspicions immediately and are never required to be sure first. This single sentence does more work than the rest of the document, because the most common failure in small organizations is delay caused by embarrassment.

    The contact list. Bank fraud line. Payment processor’s fraud contact. IT support. Insurance carrier and policy number. Church management software vendor’s support line. Board chair. An attorney, if you have one. Local FBI field office and the IC3 reporting site at ic3.gov. Gather these once and you never have to search for them under pressure.

    The first-hour instructions. Keep this short and specific. Do not reply to the suspicious message. Do not delete anything — preserve the mailbox as evidence. Disconnect an infected computer from the network but do not wipe it. If money moved, call the bank before anything else. If an account is compromised, change the password from a different device and revoke active sessions rather than just changing the password.

    Who decides and who speaks. Name the person authorized to shut down a system, take the giving page offline, or engage outside help. Name the one person who talks to the congregation, the press, or donors — and state that nobody else does. Uncoordinated communication turns a manageable incident into a credibility problem.

    When you have to notify people. Every state has a data breach notification law, and they differ on timing and thresholds. You do not need to memorize them. You need a line in the plan that says notification requirements are checked with counsel or your insurer before you decide to stay quiet, because “we didn’t realize we had to tell anyone” is not a defense anyone accepts afterward.

    What you do afterward. A short note that within thirty days the organization writes down what happened, what allowed it, and what changed as a result — and that this goes to the board. Incidents are the most persuasive argument for the security budget you have been asking for.

    That is the whole plan. Print it. Put a copy somewhere that does not require logging into the network you may have just lost access to.

    Practice it once

    A plan nobody has read is a document, not a capability. Once a year, take forty-five minutes at a staff meeting and walk through one scenario out loud. Someone reads a situation — “the treasurer just told you a $12,000 transfer went to the wrong account” — and the group talks through who does what.

    You will find gaps every time. The bank’s fraud number turns out to be the general customer service line. Nobody knows the insurance policy number. Two people think the other one is authorized to take the website down. Finding those in a conference room costs you nothing. Finding them on a Tuesday afternoon costs you the incident.

    What your board should know

    Boards are increasingly asking about cyber risk, and they are right to. Directors of a nonprofit have a duty of care, and “we had no plan” is an uncomfortable position to defend to an insurer, a major donor, or a regulator after the fact.

    The reassuring news is that this is a question you can answer well cheaply. A board that hears “we have a written incident response plan, these are the people responsible, we tested it in March, and here are the three things we fixed as a result” is a board that stops worrying. That answer costs an afternoon of writing and forty-five minutes a year of practice.

    It also matters for insurance. Cyber liability policies increasingly ask about incident response procedures on the application, and answering accurately is part of keeping the coverage valid when you need it.

    Start with the phone numbers

    If a full plan feels like too much to sit down and write, start smaller. Open a document and write down the bank’s fraud line, your insurer, your IT contact, and the name of the one person everything gets reported to. That takes fifteen minutes and it is genuinely the most valuable part.

    The rest can follow.

    If you would like help figuring out what your plan should cover — and what else your organization should shore up first — MissionDefend’s free assessment will ask plain-English questions about how you handle email, donations, member data, and accounts, then give you a baseline score and a ranked list of priorities. Paid plans will include a policy generator that drafts an incident response plan tailored to your organization, along with the other essential policies.

    It’s launching soon. Leave your email and we’ll let you know when it opens.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service. Consult qualified legal counsel regarding breach notification obligations in your state.

  • Church Cybersecurity: A Practical Guide for Ministries Without an IT Department

    Church Cybersecurity: A Practical Guide for Ministries Without an IT Department

    Nobody went into ministry to manage firewalls. You took the job to serve people, and somewhere along the way you also became the person who resets passwords, keeps the member database, and gets the email that says the online giving page is down.

    So when someone tells you that your church needs a cybersecurity program, the honest reaction is exhaustion. You do not have an IT department. You may not have an IT person. You have a volunteer who is good with computers and a budget that has other plans.

    Here is the encouraging part: the handful of things that actually protect a church are not expensive, and most of them are not technical. Attackers who target congregations are not breaking encryption. They are sending an email that looks like it came from your pastor. The defenses that stop them are ordinary, learnable, and largely free.

    This guide walks through what those defenses are, in the order that matters most.

    Why churches and nonprofits get targeted

    There is a persistent belief in small organizations that attackers only care about banks and hospitals. The opposite is closer to the truth. Attackers are running a numbers game, and they optimize for effort, not prestige. A church that holds bank account details, donor records, and a trusted mailing list — with no security staff and no mandatory training — is a far cheaper target than a bank.

    The FBI’s Internet Crime Complaint Center logged over a million complaints in 2025 and just under $20.9 billion in reported losses. Business email compromise alone — the category that covers fake invoices and impersonated leaders — accounted for 24,768 complaints and more than $3 billion. Phishing and spoofing generated 191,561 complaints, making it the single most-reported crime type. Almost none of that required technical sophistication. It required someone to believe an email.

    Three things make faith-based and nonprofit organizations particularly attractive.

    You hold data that is worth money and impossible to replace. Donor giving histories, member contact lists, background check results, counseling notes, children’s ministry records. Some of it is financially valuable. Some of it is simply devastating if it leaks.

    Your culture runs on trust and responsiveness. The instinct that makes a church good — assume the best, help quickly, do not interrogate the person asking — is precisely the instinct a social engineer exploits. An email that says “I’m in a meeting, can you handle this discreetly” works far better on a ministry team than on a procurement department.

    Money moves in ways that are hard to verify. Offerings, designated gifts, reimbursements, benevolence funds, vendor payments for a building project. Volume is low enough that a single fraudulent transfer does not look out of place, and controls are usually informal.

    None of this is a character flaw in your organization. It is a structural reality, and it is fixable.

    The order of operations

    If you do nothing else in this guide, do these things in this order. They are ranked by how much risk they remove per hour of effort, which is a very different ranking than what a security vendor will give you.

    1. Turn on multi-factor authentication everywhere

    Multi-factor authentication — the code from an app or a tap on your phone after you enter your password — is the single highest-value change available to you. Microsoft’s own research finds that MFA blocks more than 99.2% of account compromise attacks, which is why the company began enforcing it by default across its admin portals in 2024.

    Turn it on for email first, because email is the master key that resets every other password. Then online banking and your payment processor. Then the church management system and the donation platform. Then the domain registrar and website host, which are the accounts nobody thinks about until someone redirects the giving page.

    Expect friction. Staff and volunteers will find it annoying for about two weeks and then stop noticing. Roll it out to leadership first so the complaints land on people who understand why.

    2. Find out who has access to what

    Almost every organization we talk to has at least one surprise here: a former employee whose account is still active, a volunteer with full administrative rights they were given three years ago for one project, a shared login that half the office knows.

    Open your email admin console and list every account. Open your donor database and list every user. For each one, ask whether that person still serves in that role and still needs that level of access. Turn off what is no longer needed. This costs an afternoon and nothing else, and it routinely removes more risk than any product you could buy.

    While you are there, write down the answer to a question you should be able to answer instantly: who can see the donor database? If that list is longer than you expected, you have found your next project.

    3. Make impersonation hard to act on

    Since fake requests are the primary attack, build one rule that neutralizes them: any request to move money, change bank details, or buy gift cards is verified by voice before it is acted on. Not by replying to the email — by calling a number you already had.

    Write the rule down. Tell everyone who touches money, including volunteers. Tell them explicitly that they will never be criticized for verifying, even if the request really did come from the pastor. The failure mode you are protecting against is a bookkeeper who feels too junior to question leadership.

    This rule costs nothing and stops the most expensive category of attack outright.

    4. Get your backups right, then test one

    Ransomware is not the most common thing that will happen to you, but it is the one that stops a church cold. The recovery plan is backups, and backups only count if you have restored from them.

    Your member database, financial records, and shared documents should back up automatically, keep several weeks of history, and store at least one copy somewhere an attacker with your password cannot reach. Cloud platforms like Microsoft 365 and Google Workspace are more resilient than a server in the closet, but they are not a backup by themselves — a deleted or encrypted file syncs its deletion everywhere.

    Then do the part everyone skips: pick one file from a month ago and restore it. If you cannot, you do not have backups. You have hope.

    5. Train people on the specific scams aimed at them

    Generic security awareness training bores people and does not stick. What works is showing your team the actual scams that hit churches: the gift card request from the pastor’s name but the wrong address, the fake invoice from a vendor you really do use, the “your mailbox is full, click here” notice, the urgent wire change from a contractor mid-building-project.

    Fifteen minutes at a staff meeting, twice a year, focused on real examples beats an annual hour-long video. And make the point that matters most: the goal is not to never be fooled. The goal is to tell someone immediately when you think you might have been.

    6. Write down the few policies that matter

    You do not need a policy library. You need a small number of decisions recorded so they survive staff turnover: what devices may access church data, how passwords are handled, who may approve payments and at what threshold, what happens when someone leaves, and what you do if you suspect a breach.

    Five pages is plenty. The value is not the document. The value is that the decision has been made once, in calm conditions, rather than improvised during an incident.

    What tends to get skipped — and shouldn’t

    A few gaps show up again and again, and each is easy to close once you notice it.

    The domain registrar. Whoever controls your domain name controls your email and your website. This account is often registered to a volunteer’s personal address, secured with a password from 2017, and forgotten. Find it, secure it with MFA, and make sure at least two current leaders can access it.

    Shared logins. One password for the office computer, one for the giving platform, known to everyone who has ever worked there. Shared credentials mean you can never revoke access for one person and can never tell who did what. A password manager with proper sharing solves this for a small monthly cost, and several offer nonprofit pricing.

    Your church management software vendor. Your donor and member data lives on their servers. You are entitled to ask how it is protected, whether they support MFA, what happens if they are breached, and how you would get your data back. If the answer is evasive, that is information.

    Personal devices. Half your ministry runs from personal phones. That is not going to change, and forbidding it will only push it underground. Instead, require a screen lock and require that church email is accessed through the official app rather than forwarded to a personal Gmail account.

    Departures. The most common serious gap in small organizations is that nobody turns off accounts when someone leaves. Make it a line item on whatever checklist already exists for a departure.

    What a realistic first year looks like

    You are not going to do all of this at once, and you should not try.

    A reasonable first ninety days is MFA on email and financial accounts, an access review, the verify-by-voice rule written down and communicated, and one tested restore from backup. That is achievable by one person with a few afternoons, and it removes a large majority of the practical risk.

    The rest of the first year is the slower work: policies written, training delivered, vendors reviewed, an incident plan drafted, offboarding fixed. Then you are in the maintenance rhythm — a quarterly access review, twice-yearly training, an annual reassessment — which is what “having a security program” actually means for an organization your size.

    The goal is not perfection. The goal is that you know where you stand, you have fixed the things that matter most, and you can tell your board what has been done.

    Being honest about limits

    An assessment and a plan will not make you unbreachable. Nothing does. Organizations with enormous security teams still have incidents.

    What this work buys you is threefold. It removes the easy attacks, which are the overwhelming majority of what will actually be aimed at you. It means that when something does happen, you find out quickly and recover from a backup instead of a catastrophe. And it means you can demonstrate to a board, an insurer, or a grantmaker that you took reasonable care — which is a meaningfully different position to be in, legally and practically, than having done nothing.

    If your organization ever needs a formal audit or a penetration test — for a grant, an insurer, or a regulator — this groundwork is what makes that a manageable exercise instead of a painful one.

    Where to start this week

    Pick the smallest real thing. Turn on multi-factor authentication for your own email account today. Then list who has access to the donor database. Those two actions, done this week, put you ahead of most organizations your size.

    When you are ready to see the whole picture rather than one piece at a time, MissionDefend’s free assessment will walk you through plain-English questions about how your organization uses email, handles donations, stores member data, and manages accounts — then give you a baseline score and a ranked list of what to fix first. It takes about thirty minutes and requires no technical knowledge.

    We’re finishing it now. Leave your email and we’ll tell you the moment it opens.

    No spam and no sales calls — just one email when it’s live, plus a short list of steps you can take in the meantime.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.