Home Articles Get your free assessmentComing soon

Category: Threats & Scams

Plain-English breakdowns of the specific attacks aimed at churches and nonprofits — how each one works, what the message actually looks like, and the control that stops it.

  • The Scam Your Congregation Won’t Tell You About

    The Scam Your Congregation Won’t Tell You About

    Marian has not missed a Sunday in nineteen years. She runs the prayer chain. She was married forty-one years and widowed four years ago.

    In February she stopped putting anything in the offering plate. In April she took out a home equity loan. In June she asked the treasurer, oddly, whether wire transfers to Hong Kong were normal.

    Nobody put it together, because nobody was looking, and because Marian had told no one about the man she’d spoken with every day since January — a widowed contractor working overseas, a believer, someone she prayed with most nights before bed. By August she had sent him everything she had, and she still didn’t believe he was a fraud when her son sat her down with the evidence.

    Some version of this is happening in your congregation right now, and the reason you haven’t heard about it is the most important fact in this article.

    What we’re actually talking about

    The FBI calls it confidence fraudconfidence/romance fraud in its annual crime report. Its definition covers anyone who believes they are in a relationship — romantic, friendly, or familial — and is tricked into sending money or information. Romance is only one flavor. A friendship works, and so does a fake grandchild in trouble.

    In 2025 the FBI’s Internet Crime Complaint Center logged 23,159 confidence and romance fraud complaints, with reported losses of $929,287,469 — of which 10,188 complaints and $584,032,745 came from people aged 60 and over. Those figures understate the problem badly, because most victims never report. This is the crime people are most ashamed of, and shame keeps it off the ledger.

    You may also have heard the phrase “pig butchering” — the operators’ own term for fattening a target with attention and small wins before taking everything. It’s an ugly thing to say about a member of your church; the honest description is confidence fraud with an investment ending.

    How it actually works

    The shape is remarkably consistent, and the shape is what you can hand your congregation.

    It starts sideways. Often with a text to the wrong number — “Hi David, are we still on for lunch Thursday?” — then a polite reply, a warm apology, and a conversation. The FTC lists “‘wrong number’ texts that aren’t” among the top reported text scams and describes what follows exactly: “These scammers strike up a fake friendship, often with romantic undertones.” It also begins in dating apps, Facebook groups, and comment threads under Christian pages.

    Money is not mentioned for a long time. Weeks, frequently months. This is what everyone gets wrong: they picture a stranger asking for money on day three. What happens instead is a hundred days of good-morning texts and how did the appointment go and remembering the anniversary of a spouse’s death. By the time money appears there is a real relationship, real on one side, and real relationships are where guards are down by design.

    There’s always a reason you can never meet. Working overseas, on an oil rig, in the military. Video calls don’t work, or are brief and strange, or lately synthetic — the FBI notes that scammers promise to meet and then cancel, and increasingly use deepfakes.

    The ending has two forms. Either a crisis — a medical emergency, a customs fee, a frozen account — or, increasingly, an investment. He’s done well trading cryptocurrency and offers to teach her. She puts a small amount into a platform that looks entirely professional, watches it grow, and withdraws a little successfully — the moment the trap closes. Then she puts in more, and when she tries to withdraw there are taxes to pay first. The FBI is blunt: “This is a trap.”

    Faith is used as the lever, deliberately

    This is the part that will make you angry.

    Scripts written for churchgoing targets include church. He was raised in the faith. He’s been looking for a congregation since he moved. He asks what she’s been reading and sends a verse in the morning. He prays with her on the phone — at length, and well, because someone in the operation has studied the vocabulary.

    It works for a specific reason: in a faith community, shared belief is a legitimate accelerant for trust. That is not a flaw in your people — it’s why a church can care for its members in a way a subdivision cannot. The fraud borrows that instinct, which is why the usual advice, don’t trust strangers online, lands wrong. He isn’t a stranger. He’s a brother in Christ who calls every night.

    Why they defend him

    By the time anyone notices, it isn’t about money. She is not defending an investment. She is defending a relationship — and the person telling her it isn’t real is telling her that the best thing in her life since her husband died was a fiction built by strangers. Admitting that means accepting, all at once, that the money is gone, that eight months were invented, that everyone will find out, and that she participated. The mind does not take all of that on a Tuesday afternoon in a kitchen. It resists, and resistance looks like stubbornness from outside.

    The scammer prepared the ground months ago. Operators inoculate against interference early: your children won’t understand. Your church will judge us. People will say I’m after your money. So the son arrives with his printouts having already been predicted — which makes the scammer look right and the son look like the thing foretold.

    Confrontation therefore backfires. Pressing harder, producing more evidence, gathering the family: all of it deepens the commitment, because every concession costs more than the last. What helps is slower — staying in relationship, asking questions rather than issuing verdicts, and being there when the belief cracks. It usually cracks on its own, when a withdrawal fails or the demands turn cold.

    One more fact belongs in your teaching. The person typing those messages is very often not a criminal in any sense your church would recognize. The FBI has warned that fake job advertisements lure people to Southeast Asia, where they are “held against their will, intimidated, and forced to commit international cryptocurrency investment fraud schemes” — passports taken, violence threatened, debts manufactured and raised each time they’re moved between compounds. The man praying with Marian at eleven at night may be someone who answered an ad for a customer service job and is beaten if he misses his numbers. That reduces the harm to Marian by nothing, but it moves the anger away from a caricature and toward an industry destroying people at both ends.

    What a leader can actually do

    Talk about it from the front, before it happens to anyone. Five minutes on a Sunday, and the highest-value thing on this page. Say plainly that this happens to church people, that it is not a stupidity problem, and that anyone caught in it can say so without being ashamed. Silence is the environment the fraud requires.

    Name the patterns out loud. Vague warnings don’t help. These do:

    • Someone you have never met in person who talks about faith early and often.
    • A “wrong number” text that turns into a friendship.
    • Moving quickly from a dating app or Facebook to WhatsApp, Telegram, or private texting.
    • Video calls that never quite happen.
    • Any investment introduced by a romantic interest — no exceptions, however well it’s going.
    • Being told your family and your church will not understand.
    • Any request to receive money and pass it along — that is money laundering.

    Give your people one rule to hold onto: before you send money to someone you have never met, tell one other human being. Not for permission — just say it out loud. Isolation is the load-bearing wall of the scheme.

    Tell your finance volunteers what to watch for. A long-standing giver who stops abruptly. Unusual questions about wire transfers, cryptocurrency, or gift cards. A member who suddenly needs benevolence help and won’t say why. None is proof; each is worth a gentle conversation.

    Build your older-adult ministry with this in mind. In 2025 the FBI logged 201,266 complaints from people aged 60 and over, totalling $7.748 billion — complaints up 37% and losses up 59% in a single year, average loss $38,500. Loneliness is the underlying vulnerability, and it is the one thing a church is unusually equipped to address.

    When someone tells you

    Assume it took weeks to work up to it, and that they arrived braced for your disappointment.

    Believe them and don’t flinch. The first thirty seconds set everything. Thank you for telling me. You’re not the first person I’ve talked to about this.

    Never ask how they could have fallen for it — not once, not as a joke, not months later. That question closes the door for good. And don’t demand they accept it’s fake all at once. Ask questions instead: has he ever been able to video call? What happened when you tried to take money out? Let the contradictions do their own work.

    Move to practical steps quickly, because action helps a person in shock more than reassurance does. Stop sending money today. Report it at ic3.gov with dates, amounts, account numbers, wallet addresses, and transaction IDs. Call the bank or platform that sent it and ask about a recall. If personal information was shared, go to identitytheft.gov. Keep everything — the messages, the photos, the app.

    Be honest that recovery is rare. Where money is still in transit the FBI’s Recovery Asset Team can act — 3,574 domestic incidents and $507,042,623 frozen in 2025 — but that depends on speed, and this is usually found months late.

    Then warn them about the second scam, by name. Victims get re-targeted, often within weeks, by “recovery services” offering to retrieve the stolen funds for an upfront fee. The FBI has repeatedly warned about fictitious law firms contacting cryptocurrency fraud victims with exactly this offer, and about criminals impersonating the IC3 itself. Say it plainly: nobody who contacts you first can get your money back.

    Then the part that is actually your work. When you sit with someone in the weeks afterward, you’ll find the money — even a devastating amount of it — is not what they cry about. They cry because he’s gone. Because the person who texted good morning every day for eleven months, who prayed with them, who knew their late husband’s birthday, did not exist.

    That is a bereavement and deserves to be treated as one. They lost a relationship and are expected to feel foolish for having had it, which is exactly why so many never tell anyone.

    Your job is not to explain how the fraud worked; they’ll learn that. Your job is to make sure they aren’t alone in the kitchen, and to say more than once that the love they gave was real even though the person receiving it wasn’t. Both are true. Only one of them is a crime.

    What to do this week

    Say it from the front on Sunday. Two minutes: This is happening to church people. It starts as a friendship, often with someone who talks about faith. It takes months. If you’re in it, come talk to me and nobody will make you feel foolish.

    Then four lines in the newsletter: never send money to someone you have never met; never invest on the advice of a romantic interest; tell one other person before you send anything; report it at ic3.gov.

    Two minutes on a Sunday and one call to your communications volunteer, and you’ve removed the shame that keeps this crime invisible.

    MissionDefend’s free assessment covers the organization’s own posture — email, donations, member data, and accounts — and returns a baseline score with a ranked list of what to fix first. A good companion to the work of protecting the people in the pews.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; FBI, Cryptocurrency Investment Fraud; FBI Internet Crime Complaint Center, The FBI Warns of False Job Advertisements Linked to Labor Trafficking at Scam Compounds; FBI Internet Crime Complaint Center, Fictitious Law Firms Targeting Cryptocurrency Scam Victims Combine Multiple Exploitation Tactics While Offering to Recover Funds; FBI Internet Crime Complaint Center, FBI Warns of Scammers Impersonating the IC3; Federal Trade Commission, Top text scams of 2024.

  • When the Breach Isn’t Yours

    When the Breach Isn’t Yours

    The email arrives on a Thursday morning, and the subject line is careful in a way that tells you something before you open it: An important update regarding your account.

    Your church management system — the one holding your directory, your attendance records, your kids’ check-in data, and every pledge for the last six years — has had what the letter calls a security incident. A third party accessed portions of its environment. The company is working with outside experts and law enforcement. It takes the security of your data very seriously.

    You read it twice. You didn’t click anything. Nobody on staff did anything wrong. Your passwords were fine.

    And you still have to do something about it, today, because eleven thousand names in that database belong to people who trusted your church with them.

    What the words mean, and whether the notice is real

    A breach means someone got into a system and reached information they weren’t supposed to reach. That’s all. It doesn’t necessarily mean a movie-style intrusion or a ransom note. Very often it’s a stolen password used on an ordinary login screen.

    The important part is whose system. When the breach is at a company you buy software from rather than in your own building, security people call it third-party risk — sometimes supply-chain risk. Both terms describe the same simple, uncomfortable fact: the data you’re responsible for lives on computers you don’t control, run by people you’ll never meet.

    You accepted that trade the day you stopped keeping the directory in a filing cabinet, and it was almost certainly the right trade. A cloud giving platform is more secure than a spreadsheet on the office computer, by a wide margin. But it moves the risk rather than removing it, and once every three or four years the bill for that comes due in your inbox.

    This is not hypothetical for churches. In 2020 the fundraising and donor-management company Blackbaud — which the FTC described as serving more than 45,000 organizations including nonprofits, foundations, schools, and healthcare providers — was breached by an attacker who used stolen credentials and stayed inside for three months. Tens of thousands of customer organizations were affected, and millions of individual people. Not one of them did anything to cause it.

    Which brings us to the step everybody skips. Before you act on the notice at all, confirm it’s real.

    Breach notification emails are one of the most effective phishing pretexts in existence. They arrive when you’re rattled. They carry a plausible reason to log in immediately. And they can be sent by anyone — including, routinely, by attackers who read the same news story you did and mailed a counterfeit version to every customer of the breached company they could find.

    So do not click the link in the email — not the one saying Secure your account, not the one offering credit monitoring.

    Instead, open a browser and go to the vendor the way you normally do, from your bookmark or by typing the address you already know, and log in. A real vendor in the middle of a breach response will have a notice on the dashboard, a status page, and a support article. If there’s nothing there, call the support number from your contract or a past invoice, not from the email.

    The FTC gives the same advice about any message claiming your information has been exposed: don’t use a link or a phone number from the message itself.

    What usually gets taken, and what “no financial data” actually means

    Not all exposed data is equal, and vendor notices are often written to blur that. Three broad categories:

    Contact and profile data. Names, addresses, email addresses, phone numbers, birthdays, family relationships, giving history, notes fields. This is what almost always goes, and vendors tend to describe it in the mildest available language. It is not harmless. Your member directory is a targeting list — see below.

    Passwords. The notice may say passwords were hashed. Hashing turns a password into a scrambled string that can’t be reversed directly, which is genuinely better than storing the plain text. But hashes can be attacked by guessing at industrial speed, and a short or common password will fall. Treat “hashed passwords were exposed” as “passwords were exposed, and you have some time.”

    Payment and identity data. Card numbers, bank account and routing numbers, Social Security numbers. Reputable giving platforms generally don’t hold full card numbers — they hand that to a payment processor and keep a token instead. That’s real protection, and it’s why “no card data was involved” is often true.

    Now the caution, and it comes with a documented example.

    “No financial data was affected” is not the same as “nothing was affected.” It is a statement about one category, made early, on incomplete information — and sometimes it is simply wrong.

    Blackbaud told customers in July 2020 that the attacker “did not access credit card information, bank account information, or social security numbers.” According to the FTC, the attacker had in fact taken bank account numbers and Social Security numbers. The SEC, in a separate action, found the company’s own staff learned this within days and that senior management responsible for public disclosures wasn’t told. Customers weren’t corrected until October — three months in which affected people didn’t know they had reason to watch their credit.

    The lesson isn’t that vendors lie. It’s that early breach statements are provisional. Respond to what a breach could plausibly have exposed, not to the most reassuring sentence in the notice, and read the follow-up letters instead of filing them.

    The first forty-eight hours

    Once you’ve confirmed the notice is genuine, this is the whole list.

    Change the password on that service, and stop reusing it. If the same password protects your email, your bank, or your giving platform, change it everywhere it was used. Reuse is what turns one company’s breach into your problem: attackers take the leaked list and try those pairs against every major service. That technique has a name — credential stuffing — and it only works on reused passwords.

    Turn on multi-factor authentication. This is the second step after your password: a code, a tap on your phone, a security key. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Turn it on for the breached service and, while you’re thinking about it, for staff email — that’s the account that unlocks everything else.

    Check for things that shouldn’t be there. In the affected system and in your email: mail rules or forwarding you didn’t create, connected or authorized apps you don’t recognize, user accounts belonging to people who left, and any API keys or integrations. Attackers who get in leave doors open behind them, and this is the step most organizations skip after resetting a password.

    Look at who still has access. A breach is a good excuse to do the review you’ve been meaning to do. Remove the volunteer from 2019. Downgrade the three people with full administrator rights who don’t need them.

    Write down what you did and when. A dated page in a notebook. If this becomes a conversation with your insurer, your board, or a lawyer, “we don’t remember exactly” is a bad answer and the notebook is a good one.

    The second wave is aimed at your people

    Here’s what gets underestimated. The most damaging consequence of a member-data breach usually isn’t the breach. It’s the phishing that comes six weeks later, built out of the details.

    Someone now knows that Helen Ortiz gives $150 on the fifteenth of the month by automatic transfer, attends the Tuesday women’s study, and has a granddaughter named Kayla. An email that uses those specifics doesn’t read like a scam. It reads like church.

    So tell your congregation something concrete, and do it before the calls start:

    Our church management provider had a security incident. Some of your contact and giving information may have been included. Because of that, expect more convincing-looking messages over the next few months. Our church will never email or text you asking for gift cards, a wire transfer, or your login details, and we will never change our giving instructions by email. If anything claiming to be from us asks for money in a new way, call the office at the number you’ve always used.

    That paragraph, in the newsletter and said out loud on a Sunday, prevents more harm than anything else on this page.

    What to ask the vendor, in writing

    Email support and keep the thread. You’re entitled to answers, and the written record matters later.

    • What specific categories of data about our organization and our members were involved?
    • Were passwords included, and were they hashed?
    • When did this happen, when was it discovered, and when were we told?
    • What has been fixed, and how do you know the attacker no longer has access?
    • Are you notifying affected individuals directly, or is that our responsibility?
    • Will you provide written notice we can share with our board and our insurer?

    That last one is not a formality. Your board will ask, and so may your insurance carrier.

    And two more for the next vendor, asked before you sign:

    “Do you support multi-factor authentication, and can we require it for every user?” Supporting it isn’t enough — you want to enforce it, including for volunteers.

    “If you have a security incident, what will you tell us, and how fast?” You’re listening for a specific commitment rather than reassurance. A vendor who has thought about this has an answer ready.

    Your own duty to notify

    This part needs care, and it needs a professional.

    Every state, plus the District of Columbia, Guam, Puerto Rico, and the Virgin Islands, has a law requiring notification when personal information is exposed. Those laws differ substantially — in what counts as covered information, in deadlines, in whether a state agency or attorney general must be told, and in what the notice has to say. Some reach nonprofits squarely; some don’t. And because your members may live in several states, more than one law can apply to a single incident.

    The general shape is this: a breach at your vendor may still create a notification obligation for you, because in most of these laws the duty follows whoever owns the relationship with the individual. The vendor may handle it. It may not. “They said they’d take care of it” is not a legal analysis.

    So do two things. Get the vendor’s position in writing, and ask a lawyer licensed in your state — one hour of somebody’s time, early. Your denomination, your insurance carrier, or your board may already have someone. This is not a place to guess, and it’s not something this article can decide for you.

    What to do this week

    Pick your two most sensitive systems — almost certainly your church management software and your giving platform. Log in to each, turn on multi-factor authentication, and look at the user list. Remove anyone who no longer serves, and reduce anyone with administrator rights who doesn’t need them.

    Then write down, on the same page as your other vendors, who to call at each company if something goes wrong.

    Twenty minutes per system, and you’ll have done more than most organizations do after an actual breach.

    MissionDefend’s free assessment covers exactly this ground — who has access to what, which accounts have a second factor, and how member data is handled — in plain English, and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, FTC says Blackbaud’s lax security allowed hacker to steal sensitive data; U.S. Securities and Exchange Commission, SEC Charges Software Company Blackbaud Inc. for Misleading Disclosures About Ransomware Attack; Federal Trade Commission, Data Breach Response: A Guide for Business; Federal Trade Commission, Did you get an email saying your personal info is for sale on the dark web?; Microsoft, mandatory multifactor authentication guidance.

  • Anatomy of a Phishing Email: Eight Tells and What They Look Like

    Anatomy of a Phishing Email: Eight Tells and What They Look Like

    Phishing — the fake email built to make you click, log in, or pay — was the most-reported cybercrime in America again in 2025: 191,561 complaints to the FBI’s Internet Crime Complaint Center, more than any other category. It holds that title year after year for a boring reason: it keeps working.

    It keeps working partly because the training most people got is out of date. The old advice was “look for bad grammar and obvious typos.” CISA — the federal cybersecurity agency — now says plainly that generative AI has made well-written phishing routine. The clumsy Nigerian-prince era is over; the fakes are fluent now.

    What hasn’t changed is the structure. A phishing email has a job to do — create trust, create pressure, deliver a click — and the machinery for doing that job leaves the same fingerprints it always has. Here are eight of them, each shown the way it actually lands in a church office inbox. The examples are composites, not real messages, but every pattern in them is drawn from the attacks this series has already decoded.

    1. The display name that doesn’t match the address

    From: Pastor David Reeves ‹pastordavid.stmarks@gmail‑mail‑secure.com›
    Are you available? I need a favor handled discreetly.

    Email lets anyone put any name in the “From” line — the display name is decoration, chosen by the sender. The tell is the actual address behind it. On a phone, that address is hidden by default, which is exactly why so much phishing succeeds on phones: tap the sender’s name and read the real address before you believe anything else about the message. Your pastor’s real address you know. Everything else is a costume.

    2. Urgency with a deadline measured in hours

    Your mailbox will be deactivated in 4 hours. Verify now to avoid interruption.

    Legitimate organizations almost never need you to act within the hour, because nothing real works that way. Manufactured deadlines exist to keep you from doing the one thing that kills every scam: pausing to check. CISA lists urgent, consequence-laden language as the leading sign of phishing. When an email makes your chest tighten, that feeling is the payload.

    3. The mismatched link

    www.churchgivingportal.com/login

    The words of a link and its destination are two separate things — the blue text can say anything while pointing anywhere. On a computer, hover over the link without clicking and read the true address in the corner of the window. On a phone, press and hold to preview it. Watch for near-misses built to survive a glance: `rnicrosoft.com` (r-n masquerading as m), `yourchurch-give.com` instead of `yourchurch.org/give`, or a real brand name buried in front of an unrelated domain: `microsoft.security-check-portal.com`. The only part that matters is the last two pieces before the first slash.

    4. The login page you didn’t navigate to

    Your document is ready: OfferingReport_Q2.pdf — Sign in to view.

    The fake login page is where credentials actually get stolen. The email is just the ride there. The rule that beats it: a link you clicked in an email never gets a password. If a message says a document, invoice or voicemail is waiting behind a sign-in, close it and go to the service directly — type the address or use the app. If the document is real, it’s there. This habit also defeats attacks good enough to beat inspection, which some now are.

    5. A request that switches channels or demands secrecy

    Don’t call me, I’m going into the service. Just reply here.

    Real requests survive verification; fake ones must prevent it. So the message forbids exactly the act that would expose it — “don’t call,” “keep this between us,” “I’m unreachable.” We’ve seen this lever in the gift card scam, in payroll diversion, and in voice cloning. Treat any instruction not to verify as the confession it is.

    6. The attachment that needs something extra

    Invoice attached. If the document appears blank, click Enable Content to view.

    An attachment that requires you to click a button, enable macros, or install “a viewer” to read it isn’t a document with a problem — it’s a program wearing a document’s clothes. Modern office software disables that machinery by default precisely because it was the most common way malware got run. The email is asking you to overrule your own safety equipment.

    7. The reply-to that goes somewhere else

    From: finance@yourdenomination.org
    Reply-To: finance.office.desk@outlook.com

    Some phishing genuinely spoofs a trusted address in the “From” line — but the conversation has to route back to the attacker, and the hidden Reply-To field is where that happens. If you hit reply and the address in the compose window isn’t the one you thought you were talking to, stop. This is also why continuing an email thread is not verification: in business email compromise, the thread itself is the stolen property.

    8. Almost right, at the wrong moment

    Following up on the invoice from last month’s roof repair — updated remittance details attached.

    The most dangerous phishing contains no visible mistakes, because it’s built from real information: your actual roofer, a real project, plausible timing. The tell isn’t in the text — it’s in the event: money or credentials being requested with any change from the established pattern (new bank details, new payment method, new address, unusual quiet urgency). At that point the email’s quality is irrelevant, because your procedure — confirm changes by phone on a number you already have — doesn’t care how good the writing is.

    What to do this week

    Print these eight, tape them by the office computer, and spend ten minutes at the next staff meeting reading the examples aloud — people recognize patterns far faster from specimens than from rules. Then set the reporting habit: CISA’s guidance is recognize, resist, delete — and in an organization, “resist” means report it to whoever handles your email before deleting, so one alert reader protects everyone. Make the report thank-worthy, never eye-roll-worthy; the person who forwards a false alarm is your early-warning system working.

    And keep the fallback that underlies this whole series: when an email requests money, credentials, or account changes, the email itself is never the proof. Verification travels on a different channel — a phone number you already had, an address you typed yourself.

    The MissionDefend assessment checks whether your organization has these habits in place — reporting culture, verification rules, MFA — and gives you a prioritized plan for what’s missing. Join the launch list.


    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report (phishing/spoofing complaint count); Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing.

  • The Bill That Looks Official and Isn’t

    The Bill That Looks Official and Isn’t

    The mail comes in on a Tuesday and the administrator sorts it on the counter the way she does every week. Bills in one pile, everything else in the other.

    One envelope has a window, a barcode, and a due date. Inside is a single page headed DOMAIN NAME EXPIRATION NOTICE, with the church’s actual web address printed across the top, an amount — $289.00 — a date sixteen days out, and a line near the bottom:

    Failure to renew your domain name by the expiration date may result in the loss of your online identity, your email service, and your search engine placement.

    It goes in the bills pile. Of course it does. It has the church’s web address on it, and nobody in the building is entirely sure who handles the website since Dave moved to Ohio.

    The church is not going to lose its website, and it doesn’t owe $289.00 to anyone. What’s on the counter is an advertisement dressed as an invoice, and it will succeed against a meaningful share of the organizations that receive it — not because they’re careless, but because it was designed by people who understand exactly how a small office approves a small bill.

    Two words worth decoding first

    A domain is your web address — the yourchurch.org part. It isn’t something you buy once and own forever, like a pew. It’s rented, usually a year at a time.

    A registrar is the company you rent it from — GoDaddy, Namecheap, Network Solutions, or, very often in a church, whatever company the volunteer who built the site in 2014 happened to use. The registrar is the only organization on earth that can renew your domain, and the only one you can owe money to for it.

    That’s the entire trick. The notice on your counter is almost never from your registrar. It’s from a company that looked up your domain in a public database, printed a page resembling a renewal bill, and mailed it hoping you don’t remember who your registrar is.

    Most people don’t. That’s not a character flaw. It’s a detail that comes up once a year at most, usually handled by automatic payment, often set up by someone who has since left.

    The line in the fine print that names it

    Here’s the part almost nobody reads, and the most useful thing in this article.

    Many of these mailings are not illegal. They’re legally structured as solicitations — offers to sell you a service — and they say so, in the smallest type on the page, because federal law requires it. Under the postal statute governing nonmailable matter, a solicitation sent in the guise of a bill or invoice must carry a conspicuous notice to the effect that:

    “This is a solicitation for the order of goods or services, or both, and not a bill, invoice, or statement of account due. You are under no obligation to make any payments on account of this offer unless you accept this offer.”

    When the Federal Trade Commission and the Florida Attorney General sued a company for mailing small businesses official-looking demands for $84 labor law posters, the mailers did carry a disclaimer — buried, phrased as “this offer serves as a solicitation and not to be intended as a bill due.” The FTC’s position was that the rest of the page — the form-style layout, the invented compliance language, the warning about fines — overwhelmed it.

    So teach your staff one habit: before paying any invoice nobody recognizes, read the smallest type on the page. If there’s a sentence saying this is a solicitation and not a bill, you have your answer, and you can throw it away without another thought. If there is no such sentence, you still don’t pay it — you check. But finding that line settles it in ten seconds.

    The rest of the family

    Domain renewal is the most common version aimed at churches. It isn’t the only one.

    Website or search engine “listing” fees. An invoice for a directory listing, a business profile, or search engine submission. The FTC has shut down operations that mailed exactly this to small businesses and nonprofits — in one case, deceptive invoices that listed the recipient’s real domain name or a near-copy of it, with the .com swapped for .org, to create the impression of an existing relationship. Google does not send invoices for appearing in Google.

    Business registry and compliance filings. Notices about annual reports, certificates of good standing, charity registration renewals, or required labor law posters. Your state may genuinely require some of these filings. It will bill you directly and at a lower price, and it will not use a private mailbox in another state.

    Trademark renewals. These arrive after any trademark filing, from official-sounding entities with names built out of the words patent, trademark, registry, and international.

    Copier and toner invoices. The classic. A call establishes your copier model, cartridges arrive, and an invoice follows. Under federal law, merchandise you never ordered may be treated as a gift — you may “retain, use, discard, or dispose of it in any manner” with no obligation to the sender. But an office administrator holding a box of toner and a bill rarely knows that.

    The price is the whole design

    Look again at the amount: $289.00, not $2,890.00.

    That number is not an accident. It sits below the threshold where anyone stops to think. Most churches have an unwritten rule — the treasurer signs off on anything over a thousand dollars, the administrator handles the rest — and these mailings are priced deliberately to land underneath it.

    A $289 charge doesn’t go to the board or get a second look at the finance meeting. It shows up as a line item that reads like a web expense, next to eleven other line items that also read like web expenses, and it renews quietly next year. The other half of the design is fear: every one of these pages implies that something you depend on is about to be switched off, and that the deadline is close. Deadline plus small amount equals paid.

    As for why you’re on the list — there’s no breach here and nothing was stolen. Churches and nonprofits receive these precisely because they are public in ways for-profit companies aren’t. Your domain’s registration record, including which registrar holds it and when it expires, is queryable by anyone. Your charity registration with the state is a public filing. If you file an IRS Form 990, it’s published, with your address and principal officer’s name on it. Your own website lists your staff and your mailing address, because it’s supposed to.

    Every one of those is a legitimate reason to be findable. Together they make a very clean mailing list, and the people who buy it know the organization at the other end has a small office, an approving signature, and a strong instinct not to let anything lapse.

    The rule that closes the whole category

    You cannot train people to recognize every variant; new ones get printed every year. So don’t train recognition — train a procedure.

    An invoice is only paid if someone in the building can name the person who ordered it.

    Not “it looks like something we use.” Not “we probably have that.” A name. Pastor Ellis signed the copier lease. Marcy set up the newsletter service. The website is registered with Namecheap and Dave set it up.

    If nobody can produce a name, the invoice does not get paid this week. It goes in a folder and waits. Nothing bad happens to an organization that pays a real bill three days late. Something bad happens every time it pays a fake one on time.

    That rule fails only when nobody knows what the organization actually subscribes to — which, in most churches, is the real underlying problem. So fix that too. Sit down for half an hour and write a single sheet, one row per recurring service:

    What it is · Who the real vendor is · What it costs · What month it renews · Who set it up · Which card or account pays for it.

    Domain. Website hosting. Email (Microsoft 365 or Google Workspace). The church management system. Giving platform. Email newsletter tool. Livestream service. Accounting software. Copier lease. Alarm monitoring.

    Print it. Put it in the finance folder and give a copy to the treasurer. From then on, every invoice can be checked against it in fifteen seconds — and it’s the single most useful document you can hand to whoever takes over the office after you.

    While you’re there, remove the panic lever on the domain specifically:

    Turn on auto-renew at your real registrar, and register the domain for several years at once if you can. A domain that renews itself automatically cannot be scared into an emergency payment.

    Turn on the registrar lock. This is a setting — usually called domain lock, transfer lock, or registrar lock — that blocks the domain from being moved to another company without your explicit action. Some of these mailings aren’t merely selling an overpriced service — historically, paying certain ones has authorized a transfer of the domain to the sender. The lock stops that.

    Fix the contact email on the domain record. If renewal notices go to a personal address belonging to a volunteer who left, real warnings vanish and fake ones look like the only ones you get. Point it at an address two current people can see.

    Name one person who approves new vendors. Not new invoices — new vendors. Adding a company to the list of organizations you pay money to should be a decision, made once, by a specific person.

    If one already got paid

    This happens, and it is not worth anyone’s embarrassment. Some of these mailings fool accountants.

    Stop the recurrence first. Check whether it was set up as a subscription on a card or as a recurring bank debit, and cancel it at the bank or card issuer. The one-time loss is small; the annual one isn’t.

    Try to reverse it. If it was paid by credit card in the last couple of months, call the card issuer and dispute it. Card networks are reasonably receptive to “we were billed for a service we never ordered.” A mailed check is harder, but if it hasn’t cleared, ask your bank about a stop payment.

    Confirm nothing actually moved. If it was a domain notice, log in to your real registrar and confirm the domain is still there, still yours, still locked, and still set to renew.

    Report it. Mailed fraud goes to the U.S. Postal Inspection Service at uspis.gov, and to the FBI at ic3.gov. Neither will get your money back, but these cases get built out of complaint volume — the FTC’s actions in this area came from exactly that.

    Then add the vendor list to the file, and let the loss buy you the control.

    What to do this week

    Make the recurring-services sheet. One page, one row per service, real vendor name and renewal month. Half an hour at the kitchen table with your bank statement and last year’s card charges in front of you.

    Then log in to your registrar, confirm auto-renew and the domain lock are both on, and check that the contact email is one a current staff member reads.

    That’s under an hour, and it retires a category of scam that has been running by mail since before most of us had email.

    If you’d like a wider read on where the gaps are, MissionDefend’s free assessment asks straightforward questions about how your organization handles email, donations, member data, and accounts, and hands back a baseline score with a ranked list of what to address first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, FTC, Florida AG to small business: Scrutinize “o-fishy-al” invoices; Federal Trade Commission, FTC Halts Cross Border Domain Name Registration Scam; U.S. Code, 39 U.S.C. § 3001, Nonmailable matter and 39 U.S.C. § 3009, Mailing of unordered merchandise; ICANN, FAQs for Registrants: Domain Name Renewals and Expiration.

  • QR Codes in the Bulletin: The Giving Scam Nobody Sees Coming

    QR Codes in the Bulletin: The Giving Scam Nobody Sees Coming

    The giving QR code is on the back of the bulletin, on the screen during announcements, on the laminated card in each pew rack, and on the poster by the door — because it works. Point a phone at the square, the giving page opens, and the awkwardness of passing a plate past a visitor is gone.

    Now consider what that square actually is. A QR code — the name stands for quick response — is a web address printed as a pattern a camera can read. That’s all. And its defining feature is the problem: a human being cannot read it. You can proofread every word of the bulletin, but you cannot proofread the code. A square that sends the congregation to your giving platform and a square that sends them to a scammer’s copy of it look identical from across the room, and nearly identical from six inches.

    The FBI warned about exactly this in a public service announcement back in January 2022: criminals “tamper with both digital and physical QR codes,” swapping legitimate ones for their own to steal credentials and payments. The FTC followed in December 2023 with the consumer version, describing the physical trick already common on parking meters — a scam sticker printed and stuck over the real code.

    A parking meter and a pew card have a lot in common. Both sit unattended in a public place. Both are trusted by the person scanning. And both are asking for money.

    The two directions the swap happens

    On paper, with a sticker. Someone prints their own code on adhesive labels — a task that takes ten minutes and costs nothing — and applies them to the lobby poster, the pew cards, the yard sign for the capital campaign. The fake destination is a page that looks like your giving platform: same logo, lifted from your website; same colors; a form that takes card numbers. Sunday’s gifts flow to an account you’ve never heard of, and the failure is invisible until someone asks why online giving dipped.

    Upstream, in the file. The subtler version never touches your building. It compromises the source of the code: the shared Canva account a volunteer uses for slides, the email thread where the bulletin file gets passed around, the church email account of whoever assembles it. Change the code in the master file once, and the church then prints, projects and distributes the fraud itself, every week, with its own hands.

    And to complete the picture: this scam also arrives at the church from outside — unsolicited packages with “scan to see who sent you this gift” cards, which we covered in the brushing scam. Same square, opposite direction. Today’s post is about the codes you publish.

    Why nobody notices

    Nobody checks the destination. On a phone, the preview that appears when you scan shows a URL for a moment — but giving platforms have long, forgettable addresses full of subdomains ( `yourchurch.givingvendor.com`, `app.vendor.com/give/12345` ), so the congregation has no memory of what the right address looks like. The FTC’s advice — inspect the URL for misspellings before opening — assumes you know what correct is. Most givers don’t.

    That’s not a reason to abandon the codes. It’s the design constraint: the safeguards have to live with the people who publish the code, because the people who scan it can’t be expected to catch anything.

    What to do this week

    Put the giving address into human memory. Pick the shortest true form of your giving URL and print it next to every code, every time: “Scan, or visit yourchurch.org/give.” That one habit does three jobs: givers who prefer typing never scan at all; anyone who scans can compare what opened against what’s printed; and a swapped sticker now has to fake two things that must agree. A code with no readable address beside it is asking the congregation to trust ink they can’t read.

    Make one person the owner of the square. Not a committee — a name. That person generates the code (directly from the giving platform, not from free third-party QR generator sites, which can route through tracking domains you don’t control), keeps the master graphic in one place, and is the only source others copy from. Every “just grab the code from last month’s file” is a link in a chain nobody is watching.

    Add the codes to a monthly walk-through. First Sunday of the month, someone scans every published code in the building — pew cards, posters, yard signs, the slide deck — on their own phone and confirms each lands on the real page. It takes five minutes. While they’re at it: run a fingernail over printed codes. A sticker over ink has an edge you can feel. That’s the FBI’s tampering warning turned into a chore anyone can do.

    Watch the money like a control, not a report. Whoever reconciles giving should treat an unexplained dip in online gifts as a security signal worth a same-week look, not a trend to discuss at the quarterly meeting. In the sticker version of this scam, the finance spreadsheet is the only alarm that ever goes off.

    Tell givers the one rule that survives everything. In the bulletin, once a season: our giving page is yourchurch.org/give — if a code ever takes you anywhere else, close it and tell the office. You’re not teaching the congregation to distrust the plate. You’re giving them the same gift every post in this series comes down to: a known-good channel to fall back on.

    The QR code turned your congregation’s generosity into a single point of failure. It can stay — it should stay — but it graduates from decoration to infrastructure. Infrastructure gets an owner, a checklist, and an alarm.

    The MissionDefend assessment asks who owns your giving links, who can edit what gets printed, and whether anyone would notice a swap — along with the rest of your baseline. Join the launch list.


    Sources: FBI Internet Crime Complaint Center, Cybercriminals Tampering with QR Codes to Steal Victim Funds, Alert I-011822-PSA (January 18, 2022); Federal Trade Commission, Scammers hide harmful links in QR codes to steal your information (December 6, 2023).

  • “Your Subscription Renewed for $499.” There’s No Link — That’s the Point.

    “Your Subscription Renewed for $499.” There’s No Link — That’s the Point.

    The email lands at 8:20 on a Tuesday, near the top of the administrator’s inbox, between a facilities quote and a note about the flowers.

    Order Confirmation — Auto-Renewal Processed Thank you. Your annual subscription has been renewed. The charge will appear on your statement within 24–48 hours. Plan: Total Device Security — 5 devices Amount: $499.00 USD Order ID: 7734-2210-9861 If you did not authorize this renewal, you must cancel within 24 hours to receive a full refund. Call our billing department at (888) 555-0142.

    There is no link to click. Nothing to download. No misspelled sender name, no urgent all-caps subject line, none of the things anyone has ever been trained to look for.

    And the administrator’s first honest reaction is not suspicion. It’s: do we pay for that?

    She’s worked here three years. There are maybe forty things the church pays for. The last administrator set most of them up — some on the church card, some on the pastor’s card, some auto-drafting from checking. She genuinely does not know whether the church subscribes to Total Device Security, and $499 is real money out of a tight budget.

    So she calls. That was the entire objective of the email.

    Callback phishing, decoded

    Callback phishing is a scam that uses an email to make you dial a phone number, where the actual attack happens. You may also see it called TOAD, for telephone-oriented attack delivery — the same thing in acronym form.

    The name describes the structure precisely. The email is not the attack. It’s bait for a phone call, and the attack is a person talking to you.

    That inversion is why it defeats a decade of security training. Everything your staff has been told about email — don’t click the link, don’t open the attachment — is about a message that contains something dangerous. This message contains nothing dangerous at all. It’s an invoice with a phone number on it, which describes roughly half the legitimate mail your office receives.

    Why your spam filter waves it through

    Spam filters catch things. A malicious attachment, a link to a known-bad domain, a login page pretending to be Microsoft, a sender whose address doesn’t match the domain it claims — a filter can inspect all of that and score it. A plain-text invoice with a phone number offers nothing to inspect.

    The State of Wyoming’s technology agency puts the mechanics plainly in its guidance on this scam: since these emails “do not contain malicious links or attachments, they can bypass email spam filters.” No payload to detonate, no URL to check against a blocklist. The message is just words and ten digits, sent from an address that hasn’t done anything wrong yet.

    Say this to your staff plainly. The assumption underneath most office email habits is that the filter is a wall. It isn’t — it catches what can be caught, and this message is built specifically not to be one of those things.

    The FTC has documented the exact template: “scammers send notices about automatic renewals for tech support subscriptions. You might get an email or text message that says you were charged hundreds of dollars to renew your tech support subscription.”

    What happens on the call

    The person who answers is pleasant, unhurried, and competent. There is no pressure in the first two minutes — the opposite, in fact. He is sorry about the confusion. He can absolutely cancel that and process the refund. It’ll take just a moment.

    Then, gently, comes the ask. To process the refund he needs to connect to the computer — so the credit lands on the right device, or so the software can be removed. He gives her a website to visit and a short code to type in.

    That’s a remote access tool — software that lets someone else see and control your computer as if they were sitting at it. There are entirely legitimate versions; your real IT provider probably uses one. In this call, it’s the whole objective. The FTC describes the pattern directly: “they ask for remote access to your computer and pretend to scan it for viruses.”

    From there it goes one of two ways.

    He takes the machine. With control of the computer he installs something that keeps his access after the call ends, harvests saved passwords from the browser, and looks for anything worth having — banking access, the donor database, the mailbox. Some of these are the front door for a ransomware attack weeks later.

    He fakes an overpayment. This is the version that takes money the same day. The FTC describes it step by step: “They take you to a spoofed website that looks real and tell you to enter your bank or credit card information to process the refund. After you do that, they claim there was an error in the amount entered. They say they refunded you too much money and insist you pay them back with gift cards, a wire transfer, a bank transfer, cryptocurrency, or a payment app.”

    With remote control of the screen, he can make the numbers appear to move. A refund of $499 seems to arrive as $4,990. He is distraught — his mistake, he’ll lose his job, can she please just send back the difference? The balance she is looking at was edited in front of her. Nothing was ever refunded, and the money she sends is entirely real.

    The sympathy is engineered. He has spent fifteen minutes being helpful, and now he needs help. Most people, especially people who work at a church, find that very hard to refuse.

    The church-shaped version

    Every element of this lands harder in a small ministry office, and none of it is because anyone was careless.

    Nobody knows the full list of subscriptions. This is the real vulnerability, and it is almost universal. Software was set up by a departed staff member, a volunteer, or a contractor. Renewals auto-draft. The bookkeeper sees a charge and assumes someone approved it. The scam works because “do we pay for that?” is a genuinely open question.

    There’s no IT helpdesk to check with. At a company, this call gets forwarded to the technology team in thirty seconds. In a church office, the administrator is the technology team, and she has a bulletin to finish.

    Payment cards are shared. When the pastor’s card, the church card, and a reimbursement arrangement are all in play, an unrecognized charge doesn’t read as fraud. It reads as something somebody else did.

    The instinct is to be helpful. Front desk coverage rotates, and church offices are staffed by people whose actual job is to be kind to whoever is on the phone.

    None of this is negligence. It’s what a five-person organization looks like, and it can be closed with about an hour of work.

    The rule, and the list

    One sentence, and it covers the entire category:

    Nobody at this organization installs software or grants remote access to a computer because of an incoming email or an incoming call. Ever, for any reason.

    Every legitimate remote support session starts with a relationship you initiated — your IT provider, whom you called, at a number you already had. No refund requires access to your computer. No cancellation requires it. No bank requires it. If someone on a call needs to see your screen and you did not start that relationship, the answer is no.

    The second half is what makes the rule easy to follow: write down what you actually pay for.

    One page or one spreadsheet. Four columns: the service, what it’s for, roughly what it costs and when it renews, and — most importantly — who owns it. Include everything: Microsoft 365 or Google Workspace, the church management system, the giving platform, the website host, the domain registration, the streaming service, accounting software, online backup, alarm monitoring, the copier contract. Pull the last three months of bank and card statements and work through the recurring charges line by line. That is the whole exercise, and it takes an hour the first time.

    Two things come out of it. The security control: when a renewal notice arrives, “do we pay for that?” takes eight seconds instead of being unanswerable. And the money — nearly every organization that does this finds something it’s been paying for and hasn’t used in two years.

    Then one habit on top, which also covers the versions that arrive by text or voicemail: never verify a charge using contact details supplied by the message telling you about the charge. Open your bank or card account the way you normally do — your own bookmark, your own app — and look at the actual transactions. If the charge isn’t there, there’s nothing to cancel. If it is, call the number printed on the back of your card.

    That’s the same money rule that runs through the rest of this blog — verified by voice, on a number you already had — pointed at a different target. The direction of contact is the control.

    And give your staff explicit permission to be unhelpful. Say it out loud: you will never be in trouble for hanging up, or for saying “I’ll have to check on that and call you back.” Without that permission, a polite person facing a polite stranger will stay on the line.

    If it already happened

    If someone granted access or sent money, move today. This is recoverable more often than people expect, and much less often after a week.

    Disconnect that computer from the network — unplug the cable, turn off the Wi-Fi. Do not wipe it, and do not “just reinstall.” Someone technical needs to see what was installed before it goes back into use, and wiping destroys the only record of what happened.

    Call the bank immediately if money moved or if banking details were entered during the call. Say the words fraud and unauthorized, and ask about recalling the transfer. If a card was involved, cancel it.

    Change the passwords for anything that computer could reach — email, the giving platform, the church management system, the accounting software — from a different device, and sign out all active sessions. Turn on multi-factor authentication anywhere it isn’t already on, and check the mailbox for forwarding rules nobody remembers creating. The FTC’s guidance is the same: if you gave a username and password to a tech support scammer, change your password right away.

    Report it. File with the FBI at ic3.gov. If money moved, go to ic3.gov first and quickly — the FBI’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process depends almost entirely on speed.

    And tell someone in the office immediately. The pattern that turns a contained mistake into a serious loss is always the same: someone embarrassed, waiting until Monday.

    What to do this week

    Build the subscription list. Pull three months of statements, write down every recurring charge with an owner’s name beside it, and put the file where the administrator and the treasurer can both reach it. That’s the hour, and it’s the only part of this that takes real time.

    Then send one sentence to everyone who answers the phone or the office email: we never install software or allow remote access because someone contacted us — if you’re asked to, hang up and tell me, and you will never be in trouble for it.

    For a wider look at where a determined caller could get traction, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, payments, vendor accounts, and member data, then returns a baseline score and a ranked list of what to fix first — including the gaps, like an unmanaged pile of subscriptions, that don’t look like security problems until they are.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, How To Spot, Avoid, and Report Tech Support Scams; State of Wyoming Enterprise Technology Services, Callback Phishing; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Tailgating and the Unlocked Door: Social Engineering in Person

    Tailgating and the Unlocked Door: Social Engineering in Person

    On Tuesday morning the side door by the kitchen is propped open with a folding chair, because the food pantry delivery comes on Tuesdays and the volunteers got tired of walking around to let the driver in.

    At 9:40, a man in a polo shirt with a lanyard and a toolbox walks through it. He nods at the volunteer sorting cans — she nods back — and heads down the hall toward the office with the unhurried walk of a man who has been here before. He has never been here. In the next eleven minutes he will be alone with the office computer, the top drawer where the spare key lives, and the filing cabinet with last year’s giving statements.

    Everything this series has covered so far arrives through a screen or a phone. This one walks in. Tailgating is the physical version of social engineering: following someone through a door they unlocked, or being let in because you look like you belong. Security people also call the polite variant piggybacking — where the victim actually holds the door — but the distinction doesn’t matter much in practice. The attack is the same: skip the lock by borrowing someone else’s trust.

    Why a church is the easiest building in town

    It’s worth being honest about this: a church is designed to be walked into. That is the point of the building. The signage says welcome, the culture says welcome, and on any given day the people inside include members, visitors, contractors, delivery drivers, twelve-step groups, tutoring programs, and someone’s cousin picking up folding tables. Nobody can say who “belongs,” because the honest answer is almost everyone.

    CISA — the federal Cybersecurity and Infrastructure Security Agency, which runs a program specifically for houses of worship — frames the problem exactly this way: security planning for congregations has to work with “a congregation’s desire for openness and access,” not against it. The goal is not a church that interrogates strangers. The goal is a church where openness is a decision, not an accident.

    And notice what the intruder in the polo shirt was actually after. Not the sound equipment. The office — because in 2026 the valuable thing in your building is data and access: the computer that’s still logged in, the passwords in the drawer, the donor records, the blank checks, the network jack behind the desk. Physical entry is how an attacker with no technical skills gets everything a hacker wants.

    The four moves, so your team can name them

    The borrowed opening. The propped door, the loading dock during an event, the stream of people arriving for a funeral. No deception needed — just timing. Big, emotional gatherings are ideal cover; nobody checks faces at a funeral.

    The full hands. Boxes, coffee cycles, a ladder — anything that makes a decent person hold the door. The costume does the arguing: florist during a wedding week, HVAC in summer, “the piano tuner” any time.

    The confident walk. No interaction at all. Enter during office hours, move like you have an appointment, know that the person who might ask questions will assume someone else already did. This is pretexting performed with posture instead of a phone call.

    The advance call. The strongest version pairs both: a phone call Monday — “we’ll have a tech out Thursday for the fire panel inspection” — so that Thursday’s visitor is expected. Expected strangers get escorted to the electrical room and left alone.

    What to do this week

    Retire the propped door; give the regulars a better path. A door held open by a chair is an unlocked building with extra steps. Solve the reason it was propped: a doorbell at the delivery entrance that actually rings where volunteers are, a posted delivery window when someone staffs that door, or a keypad code for the food-pantry team that changes each season. People prop doors when the secure path is annoying. Make the secure path the easy one.

    Draw the one line that matters. Most of the building can stay gloriously open. Pick the two or three spaces that can’t — the office, wherever records and money live, the room with the network equipment — and treat those doors as the perimeter: locked when unoccupied, every time, even for ten minutes. “Locked office, open building” preserves the welcome and removes the prize. Pair it with the screen-lock habit: an office computer left logged in behind an unlocked door is the whole breach, pre-assembled.

    Replace suspicion with hospitality — literally. Train everyone on one move: greet the stranger. “Hi! Can I help you find something?” Warm, natural, entirely on-brand for a church — and devastating to a tailgater, whose whole method is moving unquestioned. A legitimate visitor gets directions. An intruder gets a decision point. Add the escort norm for anyone doing work in a restricted area: contractors are expected visitors with company, not wanderers.

    Verify the advance call like any other pretext. “We’re sending a tech Thursday” gets the same treatment as every unsolicited contact in this series: call the company back on the number from your contract, not the number that called you. And keep a plain sign-in sheet for non-Sunday visitors and workers — not as bureaucracy, but so that “who was in the building Tuesday?” has an answer.

    One more thing worth knowing exists: CISA offers houses of worship a free self-assessment guide and access to regional Protective Security Advisors who will walk your building with you, and FEMA runs a Nonprofit Security Grant Program that has funded exactly these kinds of improvements. You do not have to invent this from scratch.

    The doors of the church should be open. That line is theology, and nothing here argues with it. But open should describe the sanctuary and the welcome — not the filing cabinet, the finance computer, and the drawer with the spare keys. Lock the three doors that matter, greet everyone else, and you’ve kept both promises.

    The MissionDefend assessment covers the physical side of data protection — where records live, who can reach them, what’s locked — alongside the digital. Join the launch list for first access when it opens.


    Sources: Cybersecurity and Infrastructure Security Agency, Protecting Houses of Worship; FEMA, Nonprofit Security Grant Program; Federal Trade Commission, FTC Announces Impersonation Rule Goes into Effect Today (April 1, 2024).

  • The Board Member on the Call Wasn’t Real

    The Board Member on the Call Wasn’t Real

    The finance committee meets at seven on Thursday, on video, the way it has since 2020. Four squares on the screen. The treasurer joins eight minutes late, apologises, says the audio on his end is bad, and keeps his camera on anyway.

    He’s brief. The contractor for the roof project needs the deposit moved tonight to hold the crew for next month — the account details came through this afternoon and he’s forwarded them to the administrator. He asks whether anyone objects. Nobody does. His camera freezes twice while he’s talking, which is completely normal on a church Wi-Fi connection, and which is also the reason nobody looks too closely.

    The treasurer was at his daughter’s recital that evening and did not attend the meeting.

    What a deepfake actually is

    Deepfake is a plain word wearing a technical costume. It means a fake image, video, or audio recording generated by software that has studied real recordings of a person until it can produce new ones — a video of someone saying something they never said, or a voice speaking words the person never spoke.

    There’s no mystery in it and nothing exotic. The software needs examples of the person, and it produces convincing new material from them. The more examples it has, the better the result.

    The two forms that matter to a church are different in maturity, and it’s worth being precise about which is which, because the difference determines how you should think about the risk.

    Where the technology actually is

    Synthetic voice is here, it is cheap, and it is fast. This is the mature threat. Software that clones a voice from a short sample is widely available and requires no skill to operate. The FBI’s public warning on generative AI fraud describes criminals using AI-generated audio to impersonate people — a relative in a crisis asking for immediate financial help, or an account holder calling their own bank — in order to extract funds or gain access to accounts. If a caller’s voice sounds exactly like your finance chair, that no longer tells you anything.

    We’ll cover voice cloning on its own in a later post, because it deserves the room.

    Live synthetic video on a call is real but harder. This is where it’s easy to overstate, so here are the actual facts of the best-documented case.

    In January 2024, an employee at Arup — a London-headquartered engineering and design firm — joined a video conference at the company’s Hong Kong office with people who appeared to be the chief financial officer and other colleagues. They were digital recreations. Over the following week the employee made fifteen transfers totalling HK$200 million, roughly US$25 million. Hong Kong police disclosed the case in February 2024, and Arup confirmed in May 2024 that it had been the victim, with a spokesperson saying the firm notified police in January.

    That is one very large fraud against a global firm with thousands of employees, and it should be read as a demonstration rather than as a description of what happens on a typical Tuesday. The everyday version of this attack is still a plain email or a phone call. But the Arup case establishes something that is no longer arguable: a video call is not proof of who you are talking to.

    The FBI’s guidance reflects the same conclusion, noting that criminals generate AI video to depict executives and authority figures in real-time chats or to lend credibility in private communication.

    Why a church is unusually exposed

    Voice cloning needs reference material. Consider what your organization publishes, on purpose, every single week.

    Sermons. Livestreamed services, archived and public. Podcast episodes. Announcement videos. Staff introduction clips on the website. A capital campaign video with the board chair speaking directly to camera for three minutes.

    Most small businesses have almost nothing like this. A church typically has hours of clean, well-recorded audio of its most authoritative voices, freely downloadable, indexed and organized by name.

    None of that is a reason to stop. The livestream is ministry, and taking it down to prevent a hypothetical fraud would be trading something real for something speculative. The right response is not to publish less. It is to stop treating a familiar voice as identification — because for your organization specifically, a familiar voice is public information.

    The rest of the reference material is public too. Your board members are listed on your website or in your 990 filing. Your bank is on your checks. Your building project is in the newsletter. A fraudster does not need to research you; they need to read you.

    The rule that works no matter how good the fake is

    Everything above is about how convincing the impersonation can be. The control below doesn’t care.

    A decision to move money is never made on a call. It is confirmed on a channel the requester did not choose.

    Sit with that second sentence, because it’s the load-bearing part. If the request came in on a video call, confirmation happens by phone. If it came by phone, confirmation happens by a text to the number in your records, or in person, or on a second call you place. The attacker controls the channel they contacted you through — that’s the one thing you can be certain of. So verification has to happen somewhere else.

    This is the same money rule that runs through everything else on this blog: any change to payment details is verified by voice, on a number you already had, before the payment goes out. The deepfake era changes exactly one thing about it. Voice alone is no longer sufficient confirmation. The channel is doing the verifying now, not the sound of the person.

    Three specific mechanisms make that rule practical.

    A shared verbal passphrase for leadership. Agree on a word or short phrase, in person, among the small group of people who can authorize payments — pastor, treasurer, board chair, administrator. It is never written in email, never stored in a shared drive, never said on a video call. When a request to move money arrives from a person rather than a process, the recipient asks for it. The FBI recommends exactly this technique for families targeted by AI voice fraud: “Create a secret word or phrase with your family to verify their identity.” A leadership team is the same idea with a different roster.

    Pick something unguessable and unGoogleable. Not the church’s founding year, not the pastor’s dog. A random pair of words is ideal, and you should agree in advance that anyone may ask for it without it being awkward, including from the senior person in the room.

    A callback rule. No payment instruction is executed on the strength of the call it arrived on. The administrator hangs up, dials the number already in the personnel file or the vendor contract, and confirms. It adds ten minutes and defeats the entire category.

    Dual approval above a threshold. Pick a dollar figure appropriate to your budget and require two named people to approve anything above it — with the second approval given through a channel other than the one the request came in on. This is the control that survives even when the first person is completely fooled, and it’s why it belongs in your written policy rather than in someone’s habits.

    Write all three down. A control that lives only in the treasurer’s head disappears the moment the treasurer is on vacation, which is the week the request will arrive.

    Tells on a live call, and why they expire

    If you find yourself on a call and something is off, there are things worth trying.

    Ask the person to turn their head fully to one side, or to stand up and step back from the camera. Current systems handle a straight-on face far better than a sharp profile or an unusual angle, and artifacts often appear at the edges — around the ears, the jawline, the hairline, or where hair meets background.

    Ask them to hold a hand up beside their face. Hands are still difficult.

    Better than either: ask something only the real person would know, and make it specific and recent. Not “what’s our budget” — anything published is available. Ask what they ordered at lunch on Tuesday, or what the sanctuary thermostat has been doing, or the name of the person who fixed the parking lot lights. A synthetic impersonation is usually driven by someone reading from research, and research does not include last Tuesday’s lunch.

    Now the honest caveat, which matters more than the tips: these tells are expiring. Every one of them exists because the technology has a current limitation, and current limitations do not stay current. Head turns will get better. Hands will get better. The list above may be substantially useless in two years, and there is no version of it that stays reliable.

    That’s not a reason to skip them. It’s the reason the procedure matters more than the perception. A passphrase and a callback rule work identically whether the fake is crude or flawless, because they never ask anyone to judge how real something looks. They’re the only part of this article with a shelf life.

    If it already happened

    Move fast; recovery is a race measured in hours.

    Call your bank’s fraud line first, before anything else, and ask them to attempt a recall. Wire transfers are hardest to reverse and ACH transfers sometimes possible — either way, the first hour matters more than everything you do afterward.

    Report to the FBI at ic3.gov, and say business email compromise even if the request arrived by video, because that’s the category the Bureau’s recovery process runs on. The FBI’s Recovery Asset Team ran 3,574 domestic cases in 2025 and froze $507,042,623, and that process works dramatically better inside the first 24 to 72 hours.

    Tell your board and your insurer the same day. Many policies have prompt-notice requirements, and a delay can affect coverage.

    Then look at the mailbox. These attacks are frequently preceded by someone reading email inside your organization for weeks. Change passwords from a different device, sign out all sessions, enable multi-factor authentication if it isn’t on, and check every mailbox for forwarding rules nobody remembers creating.

    For scale: the FBI logged 24,768 business email compromise complaints in 2025, with losses of $3,046,598,558 — an average of about $123,005 per report. This is where the money in fraud actually goes, and a synthetic voice or face is simply a new way to open the same door.

    What to do this week

    Choose a passphrase with your leadership team — pastor, treasurer, board chair, administrator — in person or on a call where you can see each other, and agree it is never written down or emailed. Then send one message to whoever executes payments, in your own words: no payment or change of payment details goes out on the strength of a call, however convincing. Hang up, call the number we already have, confirm.

    That’s twenty minutes, and unlike every visual tell in this article, it doesn’t stop working next year.

    Procedures are what hold up when the technology stops helping you tell real from fake. MissionDefend’s free assessment asks plain-English questions about how your organization approves payments, handles email, and manages accounts, then returns a baseline score and a ranked list of what to fix first — including whether your money controls depend on someone recognizing a voice.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud; South China Morning Post, UK multinational Arup confirmed as victim of HK$200 million deepfake scam; CNN, Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Pretexting: The Fake IT Guy and the Vendor Who Isn’t

    Pretexting: The Fake IT Guy and the Vendor Who Isn’t

    The call comes in on a Wednesday around 10 a.m., which is not an accident — late enough that the office is busy, early enough that nobody’s left for lunch.

    “Hi, this is Marcus from TechServe — we handle the copier contract? We’re pushing a security update to all our units this week and I need someone to read me the numbers off the admin sticker on the back. Should take two minutes. Sorry for the hassle — half the churches in the county are on my list today.”

    There is no Marcus. There is no update. But notice everything that call already got right: a plausible company, a plausible task, an apology, a time limit, and a detail — half the churches in the county — that makes the whole thing feel routine. By the time an ask arrives, it doesn’t feel like a request from a stranger. It feels like step three of a process that started before you picked up.

    That manufactured backstory has a name: pretexting. The pretext is the invented situation — the role, the reason, the paperwork — that makes the eventual request seem normal. If phishing is a fake message, pretexting is a fake context. It’s the con artist’s stage set, and it’s the engine inside most of the attacks this series has covered: the fake invoice works because “vendor billing you” is a pretext, and the phone scam works because “your bank’s fraud department” is one.

    The costumes that get worn at churches

    Attackers pick pretexts the target already expects to encounter. For a church or small nonprofit, four costumes come up over and over.

    The IT technician. “We’re doing maintenance on your email this afternoon — I’ll need someone to confirm the login so accounts don’t lock out.” Small congregations rarely have in-house IT, so someone external who handles computer things is entirely believable — most churches genuinely do have a guy. The test is simple: real technicians you actually pay never need your password. Anyone who asks for one is not your technician, whatever the caller ID says.

    The vendor with an account problem. The copier company, the payroll processor, the giving platform, the alarm monitoring service. The caller knows which one you use — often because it’s visible on your website, in a bulletin PDF, or on a sticker by the door — and the “problem” needs an account number, a card update, or remote access to fix.

    The authority up the chain. The diocese, the district office, the denomination’s insurance program, an “auditor” doing an annual review. Hierarchical organizations are trained to respond to the level above them, and attackers borrow that reflex. A folder of official-looking paperwork, a confident tone, and a Friday-afternoon deadline can move remarkable amounts of information.

    The government caller. The IRS about your exempt status, a “grant administrator” about funds you’re eligible for, a court officer about a missed jury summons for your pastor. Impersonating agencies and businesses is now squarely illegal under a rule the Federal Trade Commission put into force on April 1, 2024 — a rule created precisely because the FTC logged over $1.1 billion in reported impersonation-scam losses in 2023, more than triple the 2020 figure. A rule after the fact, of course, only helps you if you didn’t comply during the call.

    Why good people hold the door open

    Pretexting exploits the two instincts churches deliberately cultivate: helpfulness and trust. The volunteer at the desk wants to be useful to the nice technician. The bookkeeper doesn’t want to make the diocese wait. Nobody wants to be the suspicious one — it feels rude, and ministry culture prizes warmth.

    So the fix cannot be “make everyone suspicious.” It won’t take, and it would cost you something real. The fix is to make verification feel like procedure instead of accusation — the same shift that makes a bank teller checking ID feel professional rather than hostile.

    What to do this week

    Give the front desk a script that isn’t rude. One laminated card: “Happy to help with that — our process is to call you back through the main number we have on file for your company. What’s your name and extension?” A real vendor hears bookkeeping hygiene. A pretexter hears the con failing. The power of the callback is that it routes around everything the attacker controls — their number, their story, their urgency — to a channel you already trusted before the call existed.

    Keep a one-page vendor sheet. Every company that can plausibly call you — copier, payroll, giving platform, insurance, IT, alarm — with the phone number from your contract or a bill you’ve paid, not from the internet. Verification only works if the real number takes ten seconds to find. Update it when contracts change, and note who your actual account rep is.

    Decide what the “sticker information” is worth. Serial numbers, account numbers, staff direct lines, which software you use — none of it is secret, exactly, but each piece makes the next pretext more convincing. The attacker who knows your copier model and your administrator’s first name sounds like Marcus. Trim what’s published where you can, and treat unsolicited requests for those details as the reconnaissance they are.

    Rehearse the two-question test. Before acting on any unsolicited contact, staff ask: Did I have a way to expect this? and Am I being given a reason not to verify? A real vendor’s real update survives a callback tomorrow. Only the fake one needs it done on this call, today, before lunch.

    Pretexting is patient, polite, and completely dependent on one thing: the target acting inside the story the attacker built. A callback steps outside the story. Nothing inside it survives that.

    MissionDefend’s free assessment includes the unglamorous controls that stop pretexting — callback rules, vendor verification, front-desk procedure — and shows you which ones your organization is missing. Get on the launch list.


    Sources: Federal Trade Commission, FTC Announces Impersonation Rule Goes into Effect Today (April 1, 2024); Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • The Blackmail Email Every Pastor Eventually Gets

    The Blackmail Email Every Pastor Eventually Gets

    It arrives at 11:40 on a Tuesday night, which is not an accident.

    The subject line is your own old password. Not a password you use now — one you recognize, from years ago, from an account you’d half forgotten. Seeing it sitting there in a subject line does something physical.

    The message says the sender has had access to your devices for months. It says a program on your computer turned on your camera and recorded you. It says there is a list of your contacts — your congregation, your board, your family — and that everything will go to all of them unless a payment in cryptocurrency arrives within 48 hours.

    If you are a pastor, an executive director, or a board chair, there is a good chance you have already received one of these, or will. And there is a very good chance you told no one.

    This article exists mostly for that second part.

    What the message actually is

    These emails are sent by the million. They are not written for you. Nobody selected you, studied you, or sat outside your house. A list of email addresses was purchased, a template was filled in automatically, and the send button was pressed on all of it at once.

    A typical one reads something like this:

    I know [password] is your password. I placed malware on an adult site you visited and it recorded you through your camera. I also copied your contact list. You have 48 hours to send $1,900 in Bitcoin to the address below. If you pay, I delete everything. If you tell anyone, I send it immediately.

    The FBI has been warning about this family of scam since at least 2016, when it published an alert on extortion emails tied to high-profile data breaches. A later alert describes the same tactic directly — messages claiming “I have a recorded video of you,” made more convincing by including “the recipient’s user name or password” taken from a breach.

    The New York State Police, warning residents about the same automated campaigns, stated the bottom line without hedging: despite these claims, the scammer does not have access to the victim’s device or personal information.

    Where the password came from

    This is the detail that makes the email feel real, and it has a boring explanation.

    A data breach is what happens when a company that stored your information gets broken into and that information is taken. Not your computer — theirs. A retailer, a forum, a fitness app, a hotel chain, a professional association, a church management platform. If you made an account there years ago, your email address and password were sitting in their database, and when that database was stolen, yours went with it.

    Those stolen databases get combined, resold, and eventually circulated freely. Millions of email-and-password pairs, sitting in files anyone can obtain.

    So the scammer’s software takes a line from one of those files, drops the password into a template next to the matching email address, and sends. That’s it. The password in your subject line is evidence of one thing only: that a company you once did business with was breached, probably a long time ago, possibly before you were in your current role.

    It is not evidence of a camera, or malware, or anyone watching anything.

    Some versions include your home address instead, or as well. Same explanation — addresses are in those same breached records, and in a hundred commercial marketing databases besides.

    The version with a photo of your house

    A newer variant, which the New York State Police specifically flagged, includes a photo of the recipient’s home.

    It is startling by design. It is also nothing more than an address run through publicly available street-level map imagery — the same pictures anyone can pull up of any address in the country, automatically, at scale. The photo proves the sender has your address. Your address is in the breached data. The chain ends there.

    Knowing that in advance takes most of the force out of it. That is the entire reason this section exists.

    What to actually do, in order

    Do not reply. Not to argue, not to deny, not to ask what they have. Any response tells an automated system that a live human read the message, and moves your address onto a much more valuable list.

    Do not pay, and do not negotiate. The FBI’s guidance on these schemes is explicit: do not communicate with the perpetrators, and do not pay the ransom, because the funds go on to finance further criminal activity. Payment also marks you as someone who pays, which is followed by another demand.

    Check the password. Go to haveibeenpwned.com — a free, long-established service that lets you enter an email address and see which known breaches it has appeared in. It will usually name the company and the year, which turns an unnerving mystery into a mundane fact you can look at.

    Change that password anywhere it is still in use. This is the one genuine action item in the whole episode. If the password in that email is still protecting your church email, your bank, your donor database, or anything else, change it today. Different password for every account — which in practice means a password manager, because nobody can hold forty of them in their head.

    Turn on multi-factor authentication on your email and anything financial. That’s the extra code or phone tap after the password. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. It means a stolen password on its own is no longer enough to get into anything, which is exactly the situation you want to be in the next time a database somewhere is breached — and there will be a next time.

    Report it. File at ic3.gov. The FBI asks that you include the email with its header information and the cryptocurrency address, and use the keyword “Extortion E-mail Scheme.” Your report takes five minutes and joins thousands of others that let investigators trace where the payments go.

    Then delete it and block the sender.

    The part that matters most: tell someone

    Here is the thing the scam is actually built on. Not malware. Not surveillance. The fear of being seen.

    The message is engineered around a specific instruction — don’t tell anyone — because isolation is the mechanism. A person who forwards the email to a colleague within ten minutes almost never pays. A person who sits with it alone at midnight sometimes does.

    For church and nonprofit leaders this pressure lands harder than it does on most people, and it’s worth saying why. Your role is bound up with your reputation in a way that an accountant’s isn’t. You have a congregation, a board, a family, and a sense that the position requires you to be beyond question. That’s precisely the leverage the sender is counting on — and they’re counting on it without knowing a single thing about you.

    So say it plainly, in a staff meeting or an elders’ meeting, before anyone receives one:

    If you get one of these, forward it to me or to [name] the same day. Nobody who receives one of these has done anything wrong. Everyone gets them.

    Say the last part out loud, because it is true and because the person who eventually needs it will not be in a state to work it out for themselves. Receiving a threatening email is not a moral event. It means an address of yours is on a list, along with tens of millions of others.

    If you lead an organization, receiving one yourself is a gift of a teaching moment. Mentioning it — briefly, matter-of-factly, without drama — at the next staff meeting does more to protect your people than any policy document. It tells them this happens to leaders too, and that the response here is a shrug and a report, not shame.

    If a threat is ever genuinely credible

    Almost all of these are bluffs. Not all threats are.

    If someone contacts you with something specific and real — an actual image, an actual private message, knowledge that could only come from an actual relationship — that is a different situation, and it is not one to handle alone or by paying.

    It is a matter for law enforcement, and for one trusted colleague or board member you tell immediately. Contact your local FBI field office or file at ic3.gov, and preserve everything: the messages, the account names, the timestamps. Do not delete, and do not pay. Paying an extortionist who genuinely holds something has never once ended the demands.

    And if the person being threatened is a minor, or if a minor is involved in any way, that goes to law enforcement immediately — not to an internal conversation first.

    The instinct in all of these cases is silence, and silence is the one thing that reliably makes it worse. Whatever the circumstances, a leader facing this should have at least one other person in the room.

    What to do this week

    Take the ten minutes: put your work email address into haveibeenpwned.com, see which breaches it turns up, and change any password from that list still in use. While you’re there, turn on multi-factor authentication for your email account if it isn’t already on.

    Then, at your next staff or board meeting, spend sixty seconds saying the sentence out loud — if you ever get a threatening email demanding payment, forward it to me the same day; everybody gets these and nobody is in trouble. That sentence is the whole defense, and it has to be said before it is needed.

    MissionDefend’s free assessment walks through the basics in plain English — how your organization handles email, donations, member data, and accounts — and hands back a baseline score with a ranked list of what to fix first. Password reuse and missing multi-factor authentication are usually near the top of that list, and they are usually the cheapest things on it to fix.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Extortion E-mail Schemes Tied to Recent High-Profile Data Breaches; FBI Internet Crime Complaint Center, Online Extortion Scams Increasing During The Covid-19 Crisis; New York State Police, New York State Police warns of nationwide automated sextortion scams; Microsoft, mandatory multifactor authentication guidance.