Home Articles Get your free assessmentComing soon

Category: Threats & Scams

Plain-English breakdowns of the specific attacks aimed at churches and nonprofits — how each one works, what the message actually looks like, and the control that stops it.

  • AI Voice Cloning: When the Caller Sounds Exactly Like Your Director

    AI Voice Cloning: When the Caller Sounds Exactly Like Your Director

    The bookkeeper answers on the second ring, and it’s the executive director’s voice. Not a voice like hers — her voice. The slight rasp. The way she says “listen” at the start of a sentence when she’s stressed.

    Listen — I’m about to get on a flight and the auction deposit didn’t go through. I need you to send it again before we lose the venue. I’ll text you the details. Don’t call back, I’m boarding.

    It’s her voice. It is not her.

    This is voice cloning — using artificial intelligence to generate speech that sounds like a specific, real person. The software behind it is cheap, legal, widely available, and needs surprisingly little to work with: a short sample of someone talking is enough to produce a convincing copy saying anything an attacker types. The FBI warned about exactly this in a December 2024 public service announcement: criminals are generating “short audio clips containing a loved one’s voice” to fake a crisis and demand immediate money. The Federal Trade Commission issued the same warning back in March 2023 — all a scammer needs is “a short audio clip of your family member’s voice,” which, the FTC notes, “he could get from content posted online.”

    Read that last part again, and then think about where your pastor’s voice lives.

    Churches are uniquely exposed, and it’s worth saying plainly

    For most small organizations, the boss’s voice isn’t on the internet. For a church, the entire leadership team is on the internet, every single week, in high-quality audio, saying thousands of words in every register — calm, urgent, warm, commanding. The livestream. The sermon podcast. The YouTube archive going back years.

    None of that is a mistake, and the answer is absolutely not to stop. Public preaching is the work. But it changes the math your staff should carry in their heads: for your organization, “it sounded exactly like him” is not evidence of anything. Not anymore. A scammer targeting your church has a better voice sample of your senior pastor than most attackers have of a Fortune 500 CEO.

    How the scam is actually run

    Voice cloning didn’t invent a new con. It upgraded three old ones we’ve already covered in this series.

    The urgent-request call. The gift card scam — “I need you to handle something quietly” — has historically arrived by email or text, where the impersonation is only a display name. A cloned voice moves it to the phone, where the impersonation is your ears telling you it’s really him. The structure is identical: urgency, secrecy, an odd payment method.

    The family emergency. A grandparent gets a call from a grandchild — the grandchild’s actual voice — in trouble, needing bail or a hospital deposit, begging them not to tell mom and dad. This is the version the FTC’s alert describes, and it targets exactly the older adults a church is best positioned to warn.

    The verification call. The FBI’s PSA notes criminals also use AI-generated audio of a victim’s own voice to get past phone-based identity checks at banks. That one you can’t train away — but it’s a reason to prefer app-based verification over “we’ll call you” security wherever your financial institutions offer a choice.

    One more thing makes the phone version stronger than it should be: the number on the screen can lie. Caller ID spoofing — displaying a number the caller doesn’t own — remains routine, as the FCC documents, and the STIR/SHAKEN verification system that carriers use confirms which network a call came from, not whether the person speaking is honest. A familiar voice from a familiar number can still be neither.

    Why “listen carefully” is not a defense

    You’ll find advice suggesting you listen for robotic cadence or odd pauses. The FBI’s own PSA suggests paying attention to tone and word choice — and that’s worth doing — but treat it as a tripwire, not a wall. The technology improves monthly, the clips are short by design, and a stressed listener on a bad connection hears what they expect to hear. Any defense that requires your bookkeeper to out-listen a machine on the worst morning of her month is not a defense.

    The defense that works is procedural, and it’s the same one that stops every impersonation scam regardless of how good the impersonation is: the request and the verification must travel on different channels.

    What to do this week

    Set the callback rule for money and credentials. Any request to move money, buy gift cards, change banking details, or share a password — no matter who it comes from, no matter how it arrives, no matter how real the voice sounds — is confirmed by hanging up and calling the person back on the number already in your contacts. Not the number that just called. Not a number from the message. The clone can call you; it cannot answer the real person’s phone.

    Agree on a family-style code word for leadership. Pick a phrase the executive team knows and would never appear in a sermon. If a “boarding a plane right now” call ever demands money and can’t take a callback, ask for the word. It’s thirty seconds of setup for a control no voice model can generate. Encourage staff to set the same thing up with their own aging parents — this scam reaches homes before it reaches offices.

    Kill the secrecy lever in policy. Write it down: no financial request at this organization is ever confidential from the treasurer or bookkeeper’s normal verification steps. “Don’t tell anyone” or “don’t call back” is not a request a real leader here will ever make — which converts the scammer’s favorite pressure line into an alarm.

    Tell the congregation about the grandparent version. One announcement, one bulletin line: if a family member calls in crisis asking for money, hang up and call them back on their own number — a voice can be faked. The FTC’s guidance is exactly that — don’t trust the voice, verify through a known channel — and older members are far more likely to hear it from you than from a federal agency’s blog.

    The voice on the phone used to be proof. It’s now just another sender name, as forgeable as the “From” line on an email. The organizations that handle this well won’t be the ones with the sharpest ears — they’ll be the ones where calling back is so routine that nobody even feels awkward doing it.

    The free MissionDefend assessment checks whether verification rules like these actually exist at your church — not just in someone’s head — along with the rest of your security baseline. Join the launch list to get first access.


    Sources: FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, Alert I-120324-PSA (December 3, 2024); Federal Trade Commission, Scammers use AI to enhance their family emergency schemes (March 20, 2023); Federal Communications Commission, Caller ID Spoofing.

  • The Job Opening You Never Posted

    The Job Opening You Never Posted

    The first voicemail comes in on a Monday. A woman named Denise, polite and a little apprehensive, asking when her start date is and whether she should bring anything on the first day. She mentions she already deposited the check.

    Nobody at the church knows who she is.

    By Thursday there have been four more calls, one email with a scanned driver’s license attached, and a message from a man who is no longer polite at all, because his bank has just reversed a $3,200 deposit and told him he owes them the money. He has an offer letter with the church’s logo on it. He has text messages from someone who signed off as the church’s “HR coordinator.” He does not have a job, and the church does not have an HR coordinator.

    No one at the church did anything wrong. No system was broken into. Someone simply took the name of a trusted local institution, put it on a job posting, and let the name do the work.

    The posting you never wrote

    The scam is straightforward. A fraudster creates a job listing on a recruitment site, a community Facebook group, or a job board — “remote personal assistant,” “part-time bookkeeper,” “youth ministry coordinator.” The employer name is a real church. Sometimes the logo is lifted from the church website. Sometimes the posting copies the mission statement word for word, because that language is right there to copy.

    The FBI has warned about exactly this pattern, describing how criminals “spoof legitimate companies to post fraudulent job postings on commonly used employment-oriented networking sites,” directing applicants to spoofed websites, email addresses, and phone numbers that the scammers control.

    What follows is fast, and the speed is deliberate. The applicant is contacted within hours. The interview happens entirely over text message, WhatsApp, Signal, or a chat window — never a video call, never in person, occasionally a brief phone call from a number that never answers again. The applicant is hired, usually within two days.

    Then comes the part that actually makes money.

    The check is the whole point

    The new hire is told the organization will provide equipment — a laptop, a monitor, software for the ministry’s donor database. A check arrives, or an image of one, for more than the equipment costs. Deposit it, buy the equipment from “our approved vendor,” and send the balance on to the vendor by wire, payment app, or gift card.

    The check is counterfeit. The money the applicant sends is real.

    The Federal Trade Commission puts it about as plainly as it can be put: “The check is fake and will bounce, and the bank will want you to repay the full amount of the fake check, while the scammer keeps the real money you sent them.”

    The trap is a piece of banking mechanics almost nobody outside of banking knows. Your bank may make a deposited check’s funds available to you well before it knows whether the check is any good. Seeing the balance in your account is not the same as the check having cleared. When it is finally identified as counterfeit, the deposit is reversed — and the person who deposited it is the one holding the loss.

    That’s why the FTC’s rule for job seekers is absolute: “if you get an offer that includes depositing a check and then using some of the money for any reason, that’s a scam.”

    The quieter version: the onboarding packet

    Not every variant involves a check. In some, the “hire” goes smoothly and the only ask is paperwork — a direct deposit authorization, a tax form, a copy of a driver’s license, a Social Security number “for the background check.”

    That packet is the product. It is enough to open accounts, file a fraudulent tax return, or take out credit in the applicant’s name. The FTC’s guidance on remote job scams describes scammers asking targets to “fill out direct deposit and tax forms with your bank account and other personal information.”

    This version is harder to spot because nothing about it feels like a scam. Onboarding paperwork is exactly what a new job involves. The only thing wrong is that the employer doesn’t exist.

    Why churches and nonprofits get picked

    The name buys instant trust. A job seeker who sees “First Baptist” or “Habitat affiliate” or a hospice’s name on a listing relaxes in a way they would not for an unknown LLC. That trust was built over decades by people doing good work, and it is being spent by someone else.

    The brand is sympathetic. Ministry work attracts applicants who are motivated by more than a paycheck, and who are therefore more inclined to give the organization the benefit of the doubt when something is slightly odd.

    There is no HR department to call and check. This is the structural reason, and it is not a failing — it is what a small organization looks like. At a company with 4,000 employees, a suspicious applicant calls recruiting. At a church with a pastor, an administrator, and a part-time music director, there is no recruiting line to call, and the main number goes to voicemail on Wednesday afternoons.

    Your staff page tells the scammer everything. Names, titles, email format, the pastor’s photo. All of it is public on purpose, because a church website that hides its people would be a strange church website. None of that should change.

    And here is what it costs you, even though no money left your accounts.

    You inherit a stream of confused and increasingly angry people, some of whom are out thousands of dollars they did not have. They are not wrong to be upset, and the first person they reach is whoever answers your phone. That is a hard morning for an office administrator who had no warning.

    Then there is the reputational damage, which is slower and more corrosive. The FBI has noted that job seekers “who are unaware they have been scammed may write negative reviews of the victim company; thus, adversely impacting the company’s ratings.” Some people will never learn the church wasn’t involved. They will simply remember the name attached to the worst financial week of their year.

    What actually closes it

    Publish every real opening in one place, on your own website. One page — /jobs or /employment — that is the single source of truth. If there are no openings, the page should say so in a sentence. This is the whole defense in one move, and it works because it gives every applicant, and every reporter, and every skeptical spouse a place to check. The FBI’s advice to job seekers is precisely this: verify job postings found on networking and third-party sites on the hiring company’s own website.

    Put a short standing notice on that page. Say the things you’d otherwise have to say fifty times on the phone:

    All open positions are listed on this page. We do not conduct interviews only by text or chat. We never send money, checks, or equipment funds to an applicant, and we never ask an applicant to purchase anything on our behalf. If you have been contacted by someone claiming to hire on our behalf and this page does not list the role, it is not us — please contact us at [number].

    The rule to state and never bend: every real opening is listed on our own website, and no legitimate hire of ours ever begins with a check.

    Search for yourself once a quarter. Ten minutes. Put your organization’s name into a job board search, into Facebook, into a plain web search alongside the word “hiring.” The FBI specifically recommends that businesses proactively search for fraudulent postings under their own name. If you find one, report it to the platform — every major job site and social network has a report link on the listing itself — and ask for it to be removed.

    Respond publicly when it happens. A short post on your website and social accounts, and a line in the newsletter. Not defensive, not lengthy. We’ve learned that someone is posting fake job openings using our name. We are not hiring for these roles. Our real openings are always here. If you were contacted, here’s what to do. Silence lets the story be told by people who are furious and misinformed.

    Report it. Send the details to the FBI at ic3.gov, and to the FTC at reportfraud.ftc.gov. Include screenshots of the posting, the account that posted it, and any messages applicants forwarded to you. Encourage the applicants to file their own reports — theirs carry the financial loss, which is what drives a case.

    If you’re the applicant reading this

    Some of you found this page because you searched the church’s name at eleven at night with a bad feeling. Here is the short version.

    You are not gullible. This scam is engineered to feel normal, and it borrows the credibility of an institution that spent years earning it.

    Call the organization at a number you found yourself, on their own website — not one from the offer letter or the messages. Ask whether the role exists. That one call resolves most of these.

    If you already deposited a check and sent money on, call your bank immediately and say the words fake check scam. Speed genuinely matters. Then report it at ic3.gov.

    If you handed over a Social Security number, bank details, or a copy of your ID, go to identitytheft.gov. It is the FTC’s official site, it is free, and it will generate a specific recovery plan for you — freezing credit, disputing accounts, the whole sequence — rather than leaving you to figure it out. The FTC directs job scam victims there for exactly this reason.

    And tell someone in your life today rather than next week. The single thing that turns this from a bad experience into a long one is the silence people keep out of embarrassment.

    What to do this week

    Create or update one page on your website listing every current opening — including a plain sentence when there are none — and add the standing notice above. Then spend ten minutes searching your organization’s name on a job board and on Facebook to see whether anything is already out there.

    That’s about thirty minutes, and it turns a scam you can’t prevent into one you can answer in a single sentence.

    If you want to know what else about your organization is easy for a stranger to borrow, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — including the public-facing gaps like this one that most security checklists skip entirely.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Scammers Exploit Security Weaknesses on Job Recruitment Websites to Impersonate Legitimate Businesses; Federal Trade Commission, Job Scams; Federal Trade Commission, Searching for a job to work remotely? Avoid scams and identity theft.

  • Smishing: Text-Message Scams Aimed at Church Staff

    Smishing: Text-Message Scams Aimed at Church Staff

    The text arrives on a Saturday, while the office is closed and the administrator is in the grocery store checkout line.

    USPS: Your package could not be delivered due to an incomplete address. Update your information within 24 hours: [link]

    She is expecting a package — the new children’s ministry curriculum, ordered Tuesday. The link looks vaguely official. She’s holding a phone in one hand and a gallon of milk in the other. This is precisely the moment the message was designed for.

    This is smishing — phishing carried out by text message. The name is a mash-up of SMS (the technical name for a text message) and phishing (tricking someone into clicking a link or giving up information by pretending to be someone they trust). Same con as the fake email, different doorway. And the doorway matters, because the phone in your pocket gets a level of trust and speed of response that email never did.

    Why texts work when emails fail

    Your email has a spam filter that has been learning for twenty years. Your text messages, for the most part, do not. A scam that would never survive the trip to your inbox lands on your lock screen untouched.

    The behavior around texts is different too. People answer texts fast — usually within minutes, often mid-task, standing up, one-handed. Nobody prints a text out and walks it down the hall to ask the treasurer if it looks right. And on a phone, the single best defense you have on a computer — hovering over a link to see where it really goes — mostly isn’t available. The screen is small, the address is shortened, and the browser hides the details.

    The scale of the problem is not small. The Federal Trade Commission reported that Americans lost $470 million to text-message scams in 2024 — five times the losses reported in 2020, even though the number of reports went down. Fewer people are falling for it; the ones who do are losing more.

    The five texts your staff will actually receive

    The FTC’s data names the five most common text scams by reported losses. Every one of them maps cleanly onto a week in a church office.

    The fake package notice. The most common of all. “Your delivery could not be completed.” A church office receives packages constantly — curriculum, supplies, communion cups, things five different volunteers ordered — so someone is always expecting a delivery. That’s what makes it work. The link leads to a page that harvests your address, your card number, or your login.

    The bogus job offer. Recruiting texts for part-time, work-from-home positions — sometimes called task scams, because they pay small amounts for trivial online tasks before demanding a deposit to “unlock” larger earnings. These circulate through congregations, and they sometimes borrow a real ministry’s name to look credible.

    The fake fraud alert. “Did you attempt a purchase of $487.23 at Best Buy? Reply NO to dispute.” There was no purchase. The reply — or the phone call that follows — is the scam. It ends with the “bank” walking the victim through moving money to a “safe account” that belongs to the attacker.

    The unpaid toll. A small, plausible amount — a few dollars — with a payment link and a late-fee threat. Small enough to pay without thinking, which is the entire design.

    The wrong number. “Hi, is this Jennifer? We’re still on for Tuesday?” It looks like a misdial. Replying politely starts a friendly conversation that, over weeks, becomes a relationship — and eventually an investment opportunity. This one costs its victims the most, and it targets exactly the demographic most churches serve.

    The church-office wrinkle

    For a business, smishing is a consumer problem that occasionally reaches payroll. For a church, it’s stickier, for one structural reason: the phone that receives the scam is almost never a device the organization controls. It’s the administrator’s personal phone, the volunteer treasurer’s personal phone, the youth director’s personal phone — carrying church email, the giving platform app, and the group chat with every leader in it.

    That means you cannot solve this with software. There is no filter you can buy for a phone you don’t own. What you can change is the procedure — what a person does in the ten seconds after the message lands.

    What to do this week

    Adopt the two-line text policy. Say it at the next staff meeting, put it in the volunteer handbook, and have leadership repeat it until it’s folklore: We never handle money, passwords, or account changes by text. If a text asks for any of those, it’s fake until proven otherwise by a phone call to a number we already have. That single rule defeats every scam on the FTC’s list, because every one of them needs the text itself to carry the action.

    Teach the app-not-the-link habit. If a text claims to be your bank, the postal service, or a toll authority, the response is never the link in the message — it’s opening the official app, or typing the address you already know. If the alert is real, it will be waiting there.

    Report, then delete. Forward scam texts to 7726 — that spells SPAM on a keypad — which helps carriers block similar messages for everyone. Then report it at ReportFraud.ftc.gov, and delete it. Don’t reply, not even “STOP,” to a message you believe is a scam; a reply confirms the number is live.

    Warn the congregation once a season. A single line in the bulletin or newsletter — the church will never text you asking for gift cards, payments, or personal information — protects the people your staff can’t. The wrong-number romance scam in particular preys on older adults, and a warning from a trusted pulpit lands where a news story doesn’t.

    Smishing is the same social engineering we covered on day one of this series — persuasion instead of hacking — squeezed into 160 characters. The persuasion doesn’t survive a pause and a phone call. Build the pause into the routine.

    Want to know where your organization actually stands? MissionDefend’s free assessment asks plain-English questions about how your church handles email, texts, donations and member data, then gives you a prioritized plan. Join the launch list and be first in line.


    Sources: Federal Trade Commission, New FTC Data Show Top Text Message Scams of 2024; Overall Losses to Text Scams Hit $470 Million (April 16, 2025); Federal Trade Commission, How To Recognize and Report Spam Text Messages; Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing.

  • The Check Cleared. Two Weeks Later It Didn’t.

    The Check Cleared. Two Weeks Later It Didn’t.

    A woman calls about renting the fellowship hall for her niece’s wedding reception in October. She’s pleasant, organized, and slightly apologetic about being out of state. She asks good questions about parking.

    The rental fee is $600. The check arrives four days later, made out to the church, for $3,850.

    She’s mortified when she calls. Her event coordinator handles the deposits for the caterer and the rental company and put the whole thing on one check by mistake. Would the church mind depositing it and sending the difference — $3,250 — on to the coordinator? She’ll text the details. The wedding is in nine weeks and the caterer wants the deposit by Friday.

    The treasurer deposits the check on Monday. It clears. On Wednesday, she wires $3,250 to the coordinator.

    Seventeen days later the bank calls. The check was counterfeit. The $3,850 is being pulled back out of the church’s account, and the $3,250 is gone.

    The one thing to understand about checks

    Everything in this article follows from a single fact that almost nobody has been told plainly:

    A check clearing does not mean the check is good.

    Those feel like the same sentence. They are not.

    When you deposit a check, federal law requires your bank to make the money available to you quickly — generally within a day or two for most deposits. That’s a consumer-protection rule, and it exists for good reasons: people shouldn’t wait two weeks to spend their own paycheck. The Office of the Comptroller of the Currency puts it directly: “funds may become available to you before the bank has been able to verify the check.”

    Verification is a separate, slower process. The check has to travel back through the system to the bank it was drawn on, and that bank decides whether it’s real. Forgeries, counterfeits, and checks drawn on closed accounts can be discovered weeks after the money appeared in your account. The FTC’s summary: “Fake checks can take weeks to be discovered and untangled.”

    When the forgery surfaces, the money comes back out of your account. Not the scammer’s — yours. The FTC again: “the scammer has any money you sent, and you’re stuck paying the money back to the bank.”

    Cashier’s checks are not an exception, despite their reputation. The OCC states it explicitly, answering that exact question: “If the check is fraudulent, the bank may charge it back against your account (in other words, deduct the funds from your account) or obtain a refund from you.”

    So when your treasurer says “it cleared,” what she means is “the bank has let us spend it.” She has not learned anything at all about whether it’s real. That gap — days of apparent certainty followed by weeks of actual risk — is the entire attack surface.

    The rental deposit that’s too big

    The scene above is the most common church-shaped version, and it comes in several outfits.

    A wedding reception. A family reunion. A conference that needs the sanctuary for a Saturday. A film production wanting the building for two days. A group renting the gym for a season. What they share: an out-of-state contact, unusual smoothness about the price, and an overpayment with a reason attached.

    The reason is always reasonable. An accounting error. A combined payment. A deposit from a third party who paid the wrong amount. Sometimes the overpayment is explained before the check arrives, which makes it feel disclosed rather than suspicious.

    And the ask is always the same shape: deposit this, then send part of it somewhere else, soon.

    That structure is the tell, independent of everything else. The money coming in is fake and slow to be discovered. The money going out is real and fast. The scam is nothing but the difference between those two speeds.

    The benevolence applicant who needs it passed along

    The version aimed at your compassion rather than your calendar.

    Someone approaches the benevolence fund. Their story involves a check they’ve received but can’t cash — no bank account, an account frozen, a check made out to a name their bank won’t accept, a settlement or back-pay check from an employer. Could the church deposit it and give them the cash, or wire part of it to a landlord, a bus company, a relative, a hospital?

    Sometimes there’s a variation in which the applicant has already been “helped” by someone else who sent them a check, and just needs the church to convert it.

    Everything about the request is calibrated to make a policy feel cruel. The person is in genuine-sounding distress, the amount is modest, and refusing seems to punish someone for not having a bank account — which is a real hardship affecting real people.

    But a church is not a check-cashing service, and there is no version of this that is safe. Not because the person in front of you is necessarily lying — occasionally they are also a victim, passed a fake check by someone else — but because the church absorbs the entire loss either way.

    The compassionate answer is not “no.” It’s: we don’t cash or deposit checks for anyone, but let’s talk about what you actually need and what we can pay directly. Paying a landlord or a utility directly, from your account to theirs, helps the person more than cash does and cannot be used against you.

    The donation with a request attached

    The third version wears the most flattering costume.

    A generous, unsolicited donation arrives from someone with no history with your organization — a large check, sometimes with a warm letter about your mission. Then a follow-up: the donor intended part of it for a partner ministry, a missionary, a scholarship recipient, a family they support, and would the church please forward that portion along?

    Or: they’ve changed their mind about the amount and would like a partial refund.

    Or, in the version that arrives with a fabricated story: a donor’s estate is disbursing funds and the church has been named, with a handling fee or a portion to be forwarded to another beneficiary.

    Same structure, dressed in gratitude. Money in, part of it out, and a reason to hurry.

    A genuine donor who wanted a partner ministry to receive money would send that money to the partner ministry.

    The three rules that close all of it

    You don’t need to evaluate stories. You need three rules that don’t require anyone to be a good judge of character.

    One: never refund, forward, or disburse any portion of a payment until the originating bank confirms the check is good, in writing. Not “the funds are available.” Not “it cleared.” Written confirmation that the check is legitimate and final. Your bank can tell you how to request it, and how long it takes for that specific check. If a payer objects to waiting for that, you have your answer.

    Give your staff the sentence so nobody has to invent it under pressure:

    “Our policy is that we don’t return any part of an overpayment until our bank confirms the original check is final. That usually takes a few weeks. The simplest fix is to void this one and send a new check for the correct amount — happy to do that today.”

    That offer is the perfect filter. A real customer is relieved. A fraudster will not accept it, because the correct amount is not the point.

    Two: impose a mandatory waiting period on outgoing money that depends on incoming money. Thirty days is a reasonable default, and worth writing into your facility rental agreement so it’s disclosed up front rather than negotiated in the moment: overpayments are refunded thirty days after the funds are received. Legitimate renters do not care. The scam has a shelf life measured in days and cannot survive the wait.

    Three: one person approves outgoing money, and it isn’t the person who took the call. Separating the relationship from the authorization is the oldest control in accounting and still the best. The person feeling the social pressure — the sympathy, the deadline, the mortified bride’s aunt — is not the person who signs. It is remarkably easy to say no to a request you did not personally receive.

    Two smaller habits worth adding. Only accept checks made out to the organization, never to an individual on staff. And look at the check itself — a business check with no perforated edge, a mismatch between the bank named on the check and the routing information, a check drawn on a bank in a state unrelated to everyone involved, or an amount that seems oddly specific are all worth a second look. None of these are proof, and a good forgery passes all of them, which is why the rules above don’t depend on inspection.

    If it already happened

    Call your bank first, today. If the outgoing payment hasn’t settled, it may be stoppable. This is genuinely a matter of hours.

    Report it to the FBI at ic3.gov, and use the phrase fake check scam along with the method the money left by. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic incidents in 2025, and that process works far better inside the first 24 to 72 hours than after.

    Report it to the FTC and to your state attorney general’s office, which is how patterns become cases.

    Then tell your board promptly and without spin. The instinct to quietly absorb a loss and mention it at the next quarterly meeting is understandable and always wrong. A treasurer who reports it the same day is doing the job correctly; the delay is what turns a loss into a governance problem.

    And be clear inside the organization about who was at fault: the person who deposited the check followed a completely ordinary procedure and was told by their own bank that the money was there. That’s not carelessness. It’s a gap in how the banking system communicates, which is exactly why it needs a rule rather than better judgment.

    What to do this week

    Write one sentence and give it to whoever handles deposits and rentals:

    We never send money back out of an overpayment, a donation, or a benevolence check until our bank confirms the original check is final — and refunds go out thirty days after the funds arrive, not before.

    Then check two things. Does your facility rental agreement state the refund timing? If not, add the sentence. And is there one named person who approves outgoing payments over some threshold — $500, $1,000, whatever fits your size — who is not the person taking the booking? If not, name them at the next board meeting.

    Thirty minutes, no budget, and this entire family of scams stops working on you.

    Money controls are only one part of the picture. MissionDefend’s free assessment asks plain-English questions about how your organization handles money, email, member data, and accounts — including who can send funds out and under what conditions — then returns a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, How To Spot, Avoid, and Report Fake Check Scams; Office of the Comptroller of the Currency, Aren’t cashier’s checks supposed to be honored immediately?; Office of the Comptroller of the Currency, Bank Accounts: Funds Availability; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • After the Storm: Disaster-Relief Giving Fraud Runs Both Ways

    After the Storm: Disaster-Relief Giving Fraud Runs Both Ways

    The storm came through on a Thursday night. By Friday morning the church has already decided to help — that’s not a decision that takes a meeting, and it shouldn’t be.

    By Friday afternoon two things are in motion.

    A message is circulating among your members with your church’s name on it, asking for donations to the relief effort, with a link. Nobody at the church wrote it.

    And in the office, an email has arrived from a coalition of regional relief organizations mobilizing in the affected county. They need commitments today; trucks leave in the morning. The letterhead is good, the tone is right, and there’s a wire transfer instruction at the bottom. The benevolence fund has $8,000 in it, and the pastor is inclined to send $5,000.

    Disaster fraud runs in both directions at once, and most guidance only covers one of them.

    Direction one: someone raises money in your name

    Disasters generate two things attackers want: an obvious reason to ask for money, and a population that has already decided to give.

    Your church supplies the third ingredient — a name people trust. So a page appears, or a Facebook post, or a text message chain among your members, with your church’s name and often your logo on it. The money goes somewhere else.

    The specific mechanics of cloned pages and lookalike names deserve their own treatment, and we’ve covered them separately. What matters here is the timing. A disaster compresses the window in which your members will believe an unusual appeal. In an ordinary week, a message asking for an immediate wire to a new account would strike your congregation as odd. In the week after a hurricane, it strikes them as exactly what a church would be doing.

    The defense is to occupy the space first. Within twenty-four hours of any disaster your church responds to, publish — bulletin, email, website, social — a short statement that says exactly how you are collecting, and exactly how you are not:

    We are receiving relief donations through [your normal giving page and address] only. We will not ask you for gift cards, wire transfers, or cryptocurrency, and we will not send anyone to your door. If you see an appeal using our name anywhere else, please tell the office before you give.

    Send it before you need it. The point is not to warn about a specific fake; it’s to establish what normal looks like while your members are still calm enough to read carefully.

    Direction two: your money goes out the door

    This is the direction churches don’t see coming, because it doesn’t feel like fraud. It feels like generosity under time pressure.

    The pattern is consistent. A relief organization contacts you — by email, sometimes by phone, sometimes through a name-drop from someone in your network. It has a real-sounding name, often one syllable away from an organization you’ve actually heard of. There is a deadline: trucks, a matching gift that expires, a shelter opening Monday. The ask is a wire transfer, a cashier’s check by overnight mail, or increasingly a payment through an app to a person who “coordinates” for them.

    Sometimes there’s no organization at all. Sometimes there’s a real disaster and a real need and a fake middleman. Occasionally the request arrives from a compromised mailbox belonging to someone you genuinely know, which is why it survives the sniff test.

    The variant aimed squarely at churches: an individual applies to the benevolence fund and needs help urgently because of the disaster — a relative stranded, a deposit on temporary housing, a vehicle repair to get to the affected area. The money needs to go to a third party, right now, by a method that can’t be reversed.

    Urgency is not a detail of these attacks. It is the entire mechanism. Every element of the pitch exists to remove the interval in which somebody would have checked. Take that interval back and almost nothing else matters.

    Why churches are especially exposed here

    Not negligence. Structure.

    Speed is a virtue in your world. A church that takes eleven days to approve disaster relief has failed at something real. Your instincts are correctly tuned for compassion, and fraud is designed to ride those instincts, not defeat them.

    Benevolence funds are built to move fast. They often have looser approval than the operating budget by design — that’s the point of having one. That same design means a single person can frequently authorize a payment without a second signature.

    The approver is often one person. A pastor or an administrator who will not want to say “let me check” to someone describing a family sleeping in a car.

    Ministry networks are informal. Partnerships form through relationships, conferences, and word of mouth, so an unfamiliar organization introducing itself is not unusual. In the corporate world, an unknown vendor asking for a wire is a red flag on its own. In yours, it’s Tuesday.

    Vetting an organization, and choosing how the money leaves

    You don’t need a due-diligence department. You need four checks, and together they take about as long as a coffee break.

    Confirm it exists as a tax-exempt organization. The IRS Tax Exempt Organization Search tool lets you check “an organization’s eligibility to receive tax-deductible charitable contributions.” Search the exact legal name. If nothing comes up, that alone isn’t proof of fraud — small groups and churches are treated differently — but it means you need a different reason to believe in them.

    Check state charity registration. Most states require organizations soliciting donations to register. Your state’s charity office, usually within the Attorney General’s or Secretary of State’s office, can confirm it. The National Association of State Charity Officials maintains a directory of all of them.

    Look them up at a standards-based evaluator. BBB Wise Giving Alliance publishes free reports at give.org against twenty accountability standards covering governance, finances, and truthful representation. The FTC points people to it and to Charity Watch for exactly this purpose.

    Search the name plus a hostile word. The FTC’s own advice: search the organization’s name along with “complaint,” “review,” “rating,” “fraud,” or “scam.” And the FTC’s blunt rule of thumb — “if you can’t find detailed information about a charity’s mission and programs, be suspicious.”

    If an organization is real and the need is real, none of this offends anyone. Legitimate relief organizations are asked to prove themselves constantly and have the answers ready.

    Then decide how you’ll send it, because that matters as much as who receives it. Some payment methods can be stopped or reversed. Some cannot. Fraudsters know exactly which is which, and they will steer you toward the second group while telling you it’s about speed.

    Never send by gift card, wire transfer, cryptocurrency, or cash on a first contact. The FTC states it plainly: “Don’t donate to anyone who insists you must pay by cash, gift card, wiring money, or cryptocurrency.” A relief organization does not need gift cards. Nobody’s supply truck runs on iTunes credit.

    Use a method with a paper trail and some recourse — a check to the organization’s legal name, or a credit card. Both give you something to point at later.

    And apply the money rule you already use for vendors. Any change to payment details — and any new payment instruction from a partner you already have — is verified by voice, on a phone number you already had, before the money goes out. Not the number in the email. The disaster version of that rule is one sentence longer: a new organization you’ve never paid before does not get a wire on its first contact, no matter what the deadline is.

    Route disaster giving through relationships you already have

    This is the single highest-leverage decision, and you can make it before any disaster happens.

    Most churches and nonprofits already have partners: a denominational relief arm, a regional association, a food bank, a long-standing mission partner, a local ministerial alliance. These organizations are typically on the ground faster than any stranger who emails you, and you can verify them once and reuse that verification for the next twenty years.

    Write it down as policy, in one sentence:

    Disaster giving goes to organizations we already have a relationship with. Anything else requires two people to approve and a twenty-four-hour wait.

    That policy costs you almost nothing in real responsiveness — a day, at most, on a giving decision, and your existing partners are unaffected. It costs a fraudster everything, because the pitch depends entirely on being answered inside the hour.

    The same shape works for benevolence: any benevolence payment to a third party rather than to the applicant, or by any irreversible method, waits until tomorrow and is approved by two people. Applicants with genuine need are not harmed by a day. The scripts fall apart.

    If it already happened

    Move within hours, not days.

    Call your bank immediately and ask about a recall. Wires and ACH transfers have narrow windows, but they exist, and the window closes fast.

    Report it to the FBI at ic3.gov the same day. Include the account details, the amount, and the timeline. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic incidents in 2025, and that process depends almost entirely on speed — it works dramatically better inside the first 24 to 72 hours.

    Report it to your state charity regulator and the FTC, which is how patterns get built into cases.

    Then tell your congregation what happened, if their gifts were involved. Plainly, without drama. Organizations that get quiet after being defrauded do more damage to their own credibility than the fraud did.

    What to do this week

    Write the two policy sentences down — disaster giving goes to existing partners; anything else waits twenty-four hours and needs two approvals — and email them to everyone who can authorize a payment. Ten minutes.

    Then draft the congregation notice now, while nothing is happening. Save it where you can find it. Fill in your real giving address, state that you’ll never ask for gift cards or wires, and leave it ready to send the same day something happens near you. Twenty minutes today, and it goes out inside an hour when it matters.

    MissionDefend’s free assessment walks through how your organization handles email, donations, member data, and accounts in plain English — including who can move money and how fast — and gives you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Before Giving to a Charity; Federal Trade Commission, After a disaster, make your donations count; Internal Revenue Service, Tax Exempt Organization Search; BBB Wise Giving Alliance, give.org; National Association of State Charity Officials, State Government directory; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • When Someone Else Fundraises In Your Name

    When Someone Else Fundraises In Your Name

    A member stops the pastor in the hallway after the second service. She’s a little embarrassed, the way people are when they think they might be about to say something foolish.

    She gave to the building fund online on Thursday. Fifty dollars. She wanted to check whether it went through, because she never got a receipt, and now the page won’t load.

    He asks her to show him. She pulls it up in her browser history: the church’s name across the top, the church’s logo, the photo from last spring’s picnic, a short paragraph about the building fund written in a voice that sounds almost right. The address bar reads something close to the church’s website, but not quite.

    Her fifty dollars is gone. So, in a quieter way, is something else — because for a few minutes on Sunday morning, she wasn’t sure whether the church had taken her money and failed to send a receipt.

    What impersonation actually looks like

    There are three common forms, and they’re often used together.

    The cloned website. Copying a website is not difficult, and it doesn’t require any access to yours. A browser will save an entire page — text, images, layout — in one click. An attacker pulls down your giving page, swaps the payment form for their own, and hosts it somewhere cheap. It looks exactly like your site because most of it is your site.

    The near-identical social media page. More common than the cloned site, because it’s free and it takes about four minutes. A new Facebook page with your church’s name, your logo as the profile picture, and six photos lifted from your existing page. Then it sends friend requests or messages to people who follow the real one — the member list is right there in public. Some versions don’t even ask for money at first. They build a small following, then post an urgent appeal three weeks later.

    The lookalike domain name. A domain is the address people type to reach you — firstchurchsomewhere.org. Anyone can register one that sits a keystroke away from yours: firstchurchsomewhere.com instead of .org, first-church-somewhere.org with hyphens, firstchurchsomwhere.org with a letter dropped, or firstchurchsomewhere-giving.org with a plausible word bolted on. Domains cost a few dollars a year and nobody checks who you are when you buy one.

    The lookalike domain is the piece that makes the other two convincing, because it survives the one check a careful person actually performs — glancing at the address bar.

    Your own members are the audience

    This is what separates charity impersonation from generic fraud, and it’s the reason it deserves your attention rather than your insurer’s.

    An attacker impersonating a national charity is fishing in an ocean. An attacker impersonating your church is working a list of a few hundred people who already trust the name, already give to it, and already expect to hear about a building fund or a mission trip or a family in crisis. The conversion rate is not comparable.

    They will also aim at the moments when giving is already elevated and already emotional — a fire, a funeral, a medical fundraiser for a family everybody knows, a capital campaign you announced from the front. Those are the moments when an appeal is expected, which means an extra appeal doesn’t look out of place.

    And here is the part leaders underestimate: your members will experience this as something that happened to them at your church. Not “I was defrauded by a stranger on the internet.” The first feeling is confusion about whether the church mishandled their gift; the second is embarrassment; the third, sometimes, is a quiet decision to give by check from now on and not mention it. You may never hear about most of it.

    That’s the actual damage. The money taken from any one person is usually small. The number of people who become slightly more hesitant is not.

    Finding out whether it’s happening

    You cannot respond to something you don’t know about. Three checks, none of them technical, all of them free.

    Search your own name. Once a quarter, type your organization’s name into a search engine and look past the first three results. Add the words donate, giving, and fund and search again. Do it in a private or incognito window so your own browsing history doesn’t push your real site to the top and hide everything else.

    Check each platform directly. Search your name inside Facebook, Instagram, and any other platform where you have a presence. Look for pages using your logo, your photos, or a name within a character or two of yours. Also search for pages you used to run — an abandoned page from a 2019 youth event is a gift to someone who wants a head start on credibility.

    Set up a Google Alert. Go to google.com/alerts, enter your organization’s name in quotation marks, and have results emailed weekly. Set up a second one for your name plus the word donate. It’s five minutes once, and then it runs on its own. It will not catch everything — it does not see inside social platforms, and it does not see pages that were never indexed — but it costs nothing and it has caught plenty of people.

    Add one more habit that isn’t a search: tell your congregation to tell you. Most impersonation is discovered by a member who thought something felt slightly wrong. If they know there’s a person to tell and that nobody will make them feel foolish, you’ll hear about it in hours instead of months.

    Getting it taken down

    Takedowns are unglamorous and mostly consist of filling in forms carefully. They work more often than people expect. Work all three channels at once rather than in sequence.

    The platform. Every major social platform has a reporting flow specifically for impersonation of an organization, distinct from general “this is spam.” Find that specific option — impersonation reports from the impersonated party are handled differently and faster than spam reports. Report from an account that administers your real page, because that connection helps establish who you are. Ask three or four people to file their own reports as well.

    The registrar and the host. Two different companies are usually involved: the registrar that sold the domain name, and the host that runs the server the page sits on. You can look up who they are with the ICANN registration data lookup at lookup.icann.org — type the fraudulent domain in and it will show you the registrar. Registrars are contractually required to publish an abuse contact; ICANN’s rules oblige them to maintain “an abuse contact to receive abuse reports” and to publish an email address for it, and to take “reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Email abuse@ that registrar with the exact fraudulent address, the exact address of your real site, and a plain statement that the page is soliciting donations while impersonating your organization. Attach screenshots. Do the same with the host if you can identify it.

    The regulator. Fundraising is regulated at the state level, and most states require an organization soliciting charitable donations there to register first. Your state’s charity office — usually inside the Attorney General’s office or the Secretary of State’s — is the right place to report someone soliciting in your name. The National Association of State Charity Officials keeps a directory of every state’s office. Also report the fraud to the FBI at ic3.gov; the loss per member may be small, but a pattern across several organizations is exactly what makes a case.

    Keep evidence before you report anything: full-page screenshots with the address bar visible, the exact URL, and the date. Pages come down, and once they’re gone you can’t prove what they said.

    None of this is legal advice, and if the impersonation is substantial or persistent — or if a member has lost real money — a short conversation with an attorney is worth having. Requirements vary by state.

    What to say publicly while it’s happening

    Say something, quickly, in the channels your members actually read. Silence gets filled with the wrong story.

    The tone that works is calm and specific. Not an apology, because you did nothing wrong, and not alarm.

    We’ve learned that someone has set up a page using our name and logo to collect donations. It is not us. Our giving page is only ever at [your exact address], and that’s the only place we ask you to give online. If you gave through any other page in the last few weeks, please call your bank or card company today and tell them the charge was fraudulent — then let the office know so we can help. Nobody here is going to think less of you. This was designed to be convincing.

    Three things that paragraph does: it states your real giving address in a form people can compare against, it gives a concrete next step with a same-day urgency that’s genuinely warranted, and it removes the shame. That last part is what determines whether you find out how many people were affected.

    Then do the standing version: publish your real giving address in the same place every time — the bulletin, the website footer, the bottom of every email — and say plainly that you will never ask for donations by direct message, gift card, wire transfer, or cryptocurrency. Members who know what normal looks like recognize abnormal without being told.

    What to do this week

    Search for yourself. Twenty minutes, in a private browsing window: your name in a search engine, then your name plus donate, then the same searches inside Facebook and Instagram. Write down what you find, including your own abandoned pages.

    Set two Google Alerts — your organization’s name in quotation marks, and your name plus donate — delivered weekly to whoever reads the office email.

    Register the obvious lookalikes, if you have twenty or thirty dollars a year to spend. If you own the .org, buy the .com and the .net and point them at your real site. It’s the cheapest control in this entire article.

    Half an hour, and you’ve turned an attack you’d have found out about from a confused member into one you’d find out about from a weekly email.

    Impersonation is one symptom of a wider question — how visible and how protected your organization is online. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including how your giving pages and domain names are set up — and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: ICANN, Registrar Abuse Reports; ICANN, Registration Data Lookup Tool; National Association of State Charity Officials, State Government directory; Federal Trade Commission, Before Giving to a Charity; Google, Create an alert.

  • Vishing: When the Scam Comes by Phone

    Vishing: When the Scam Comes by Phone

    The phone in the church office rings at 2:40 on a Wednesday. The screen says FIRST NATIONAL BANK.

    The caller is calm and slightly bored, the way people sound when they do this all day. There’s been unusual activity on the church’s account — two attempted transfers this morning, both declined. He needs to confirm he’s speaking with an authorized signer before he can discuss details, and then he’ll need to verify a code that’s about to be texted to the number on file, so the fraud hold can be lifted.

    Everything about that call is false, including the name on the screen.

    Email scams get most of the attention, and reasonably so. But phone-based attacks have a particular power that email doesn’t: a live human being, responding in real time, adapting to whatever you say. There’s no time to reread. There’s no forwarding it to a colleague. Social pressure operates the way it does in any conversation — hanging up on someone feels rude in a way that deleting an email never does.

    What vishing means

    Vishing is short for voice phishing — the same persuasion attack you’ve read about in this series, delivered by phone call instead of email.

    The goal is one of three things: get you to reveal a credential (a password, or more often a one-time code), get you to move money, or get you to install something on a computer.

    The name is jargon, but there’s nothing exotic underneath. Someone calls with an invented reason to be calling, and asks you to do something.

    Your caller ID is not evidence

    This is the single most important technical fact in this post, and most people have never been told it plainly.

    The number and name shown on your phone are supplied by the caller. They are not verified by anyone.

    When a call is placed, the caller’s system includes the number it wants displayed. Historically, the phone network passed that along without checking it. That’s how legitimate systems work too — it’s why a call from a hospital’s back office can display the hospital’s main switchboard number, and why your church’s outgoing calls can all show the office line rather than whichever extension dialled.

    That same flexibility is what lets an attacker display your bank’s actual customer service number, or your denomination’s regional office, or — and this happens — your own church’s number, calling a member of your congregation.

    The FCC describes caller ID spoofing as scammers falsifying the number that appears on your display in order to “trick Americans into answering their phones when they shouldn’t.”

    There is a countermeasure, and it’s worth understanding both what it does and what it doesn’t.

    STIR/SHAKEN is a caller ID authentication framework that US carriers are required to implement. In plain terms: the phone company that originates a call digitally “signs” it, and the companies that carry it onward can verify that signature. It’s the reason your phone sometimes displays “Caller Verified” or a similar label.

    What it does not do is guarantee that an unlabelled call is fake, or that a verified call is trustworthy. Verification confirms the call really came from the number shown — not that the person on the line is honest. Plenty of legitimate calls arrive unsigned, particularly from smaller carriers and internet-based phone systems. Treat it as weak supporting evidence, not proof.

    The practical takeaway for your staff: the name on the screen tells you nothing about who is actually calling.

    The versions aimed at ministries

    The bank fraud department. As above. The prize is usually a one-time code — the six digits your bank texts you. The caller creates a reason you’d expect to receive one, then asks you to read it out. That code is the second factor protecting your account; handing it over hands over the account.

    The IT helpdesk. “I’m calling from the company that supports your Microsoft 365 — we’re seeing sync errors on your mailbox.” The ask is either your password or permission to install a remote access tool so they can “take a look.” This one succeeds in small offices because the staff genuinely don’t know exactly who supports their systems.

    The utility shutoff. Aggressive, deadline-driven, aimed at the office administrator: the church’s power will be cut this afternoon unless an overdue balance is paid immediately, usually by prepaid card or transfer. Real utilities don’t operate this way.

    The denominational or grant office. More targeted. Someone who knows your affiliation calls about a compliance filing, an insurance audit, or a grant disbursement, and needs bank details or staff information to proceed.

    The follow-up call after an email. Increasingly common, and effective. An email arrives requesting a payment change; then a call arrives “confirming” it. Two channels agreeing feels like verification. It isn’t — the attacker controls both.

    The call to your congregation. Your church’s number is displayed, and an elderly member is told there’s a problem with their giving record, or that the church is collecting for an emergency. This one damages trust you spent decades building.

    Why it works on good people

    Live conversation removes the two things that protect you in email: time, and the ability to reread.

    A skilled caller uses authority (a title, an institution), urgency (a hold that expires, a shutoff today), and plausibility (they already know your pastor’s name, your bank, your address — all public). They may also use reciprocity, doing you a small favour first: “I’ve placed a temporary hold on the account for you, that’ll protect you while we sort this out.”

    And they exploit ordinary manners. Ending a call abruptly on a polite, professional-sounding person feels aggressive. Most people would rather stay on the line and be uncomfortable.

    That instinct is the thing to override, and the way to override it is not to make your staff ruder. It’s to give them a script that isn’t rude at all.

    The habit that defeats all of it

    One rule. It handles every variant above without anyone having to judge whether a particular call sounds legitimate:

    Hang up and call back on a number you already had.

    Not the number the caller gives you. Not the number that appeared on your screen — that’s the one that can be faked. The number on the back of your bank card, on a previous statement, in your contacts, on the signed contract, on the utility’s official website.

    The polite version, which anyone can say without confrontation:

    “I’m not able to discuss account details on an inbound call. Let me call you back on the number we have on file.”

    A legitimate caller from any real institution will not object to that. Fraud departments in particular expect it — it’s exactly what they train their own customers to do. A caller who pushes back, who explains why calling back won’t work, who says the case number will expire, has just identified themselves.

    Two absolute rules to teach alongside it, with no exceptions:

    Never read a one-time code to anyone on the phone. No bank, no vendor, no IT provider, no denominational office will ever ask you to. The entire purpose of that code is to prove you are present. Reading it aloud defeats it completely. Most banks now print this warning in the text message itself.

    Never install software or grant remote access because of an incoming call. If someone needs to see your screen, that arrangement is made through a relationship you initiated.

    Prepare before it happens

    Write down who actually supports you. A single sheet: your bank’s real fraud number, your IT support’s real number, your payroll provider, your insurer, your denominational contact. Print it. Put it where the phone is. Most vishing succeeds because the person answering genuinely doesn’t know who legitimately calls them, and searching for a number under pressure is when people click the wrong result.

    Extend the money rule to phone calls. The verification rule from earlier in this series — no payment change without a callback — applies identically to requests that arrive by voice. Write it that way so nobody wonders whether the phone is different.

    Give people permission to hang up. Say it out loud in a staff meeting: “If a call feels off, end it. You will never be in trouble for hanging up on someone, even if it turns out to be legitimate. We’ll sort it out.” Without that explicit permission, junior staff and volunteers will stay on the line out of politeness.

    Warn your congregation. Include a line in the newsletter: the church will never call you asking for payment, gift cards, or account details. Older members are being targeted heavily — the FBI logged 201,266 complaints from victims aged 60 and over in 2025, totalling $7.748 billion, up 59% in a single year.

    Run one practice call. Ask a board member to call the office pretending to be the bank. Ninety seconds, at a staff meeting. People remember doing it in a way they do not remember being told about it.

    If someone already gave something up

    If a one-time code was shared: change that account’s password immediately from a different device, sign out all active sessions, and call the institution’s real fraud line. Assume the account was accessed.

    If remote access was granted: disconnect that computer from the network — unplug the cable, turn off Wi-Fi — but don’t wipe it. Get someone technical to look at it before it goes back into use.

    If money moved: call your bank’s fraud line before doing anything else, then report to the FBI at ic3.gov. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process depends almost entirely on speed.

    In every case, tell someone immediately. The pattern that turns a contained mistake into a serious loss is a person who is embarrassed and waits.

    What to do this week

    Make the one-page contact sheet — bank fraud line, IT support, payroll, insurer — and tape it up next to the office phone. Then, at your next staff meeting, say the sentence out loud: nobody will ever be in trouble for hanging up and calling back.

    That’s fifteen minutes, and it closes the whole category.

    MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then gives you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Communications Commission, Combating Spoofed Robocalls with Caller ID Authentication; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • The Package Nobody Ordered: Brushing Scams and the QR Code in the Box

    The Package Nobody Ordered: Brushing Scams and the QR Code in the Box

    It’s a Tuesday, and there’s a box on the counter in the church office.

    Nobody remembers ordering it. It’s addressed to the church, correctly, with the right street number and the right suite. Inside is a phone case in a color nobody would choose, or a set of silicone kitchen rings, or a keychain flashlight — something cheap, sealed in plastic, with no packing slip and no invoice.

    There is one other thing in the box: a small printed card.

    Thank you for your order! Scan the QR code below to see who sent this gift and claim your free item.

    The volunteer who opens the mail on Tuesdays holds up her phone, taps the camera, and the code resolves into a link.

    That is the whole attack. It took nine seconds, and nothing about it felt like an attack.

    What a brushing scam actually is

    Start with the original version, because it explains why the box exists at all.

    A brushing scam is a fake-review scheme. A seller on a large marketplace wants better ratings, so they ship a cheap item to a real name at a real address — pulled from a data set they bought or scraped — and record it as a completed sale. Then they write a glowing review in that person’s name. Because a package genuinely shipped and genuinely arrived, the platform marks it a “verified purchase,” which is exactly the label shoppers trust most.

    The US Postal Inspection Service describes the goal plainly: the packages are sent so as “to give the impression that the recipient is a verified buyer who has written positive online reviews.”

    For years that was the end of it. Annoying, faintly creepy, mostly harmless to the recipient. You kept the phone case.

    The new part: the card with the QR code

    The scheme has been repurposed, and the second version is not harmless.

    A QR code — short for Quick Response code — is that square pattern of black and white blocks. Your phone’s camera reads it and turns it into a web address, then usually offers to open it. It is a link with the letters hidden.

    In the current variant, the package contains a card with a QR code and a reason to scan it. Scan to see who sent this. Scan to register your gift. Scan for a free item. Scan to leave a review. The code leads to a page that either asks for information — name, address, card number, or a username and password for an account you already have — or prompts you to install an app that gives an attacker access to the phone.

    That is phishing: a message built to look like it comes from someone you’d trust, designed to get you to hand over information or install something. When the bait is a QR code rather than a link in an email, the security world calls it quishing. The Postal Inspection Service now names this pattern directly, warning that “cards with QR codes are being sent inside packages as a part of brushing scams.”

    The FBI issued a public service announcement about it on 31 July 2025 — PSA I-073125-PSA, Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes. The Bureau’s description: criminals “send unsolicited packages containing a QR code that prompts the recipient to provide personal and financial information or unwittingly download malicious software.” The Federal Trade Commission flagged the same thing in a consumer alert in January 2025, noting that scanning “could take you to a phishing website that steals your personal information, like credit card numbers or usernames and passwords,” or “download malware onto your phone.”

    Three government bodies describing the same box. That’s about as verified as a threat gets.

    And a QR code is worse than a link in an email, for two reasons, neither of them technical.

    It hides where it goes. In an email you can hover over a link and see the address it leads to. You can notice that “your bank” is actually a string of nonsense followed by .ru. A QR code shows you nothing. It’s a picture. By the time the address appears, it’s in a small gray bar at the top of a browser window that has already loaded the page.

    It moves the attack onto a personal phone. Nobody scans a QR code with the church’s desktop computer. They scan it with the phone in their pocket — a device the organization doesn’t own, doesn’t manage, and can’t inspect. Whatever protections your email system has, they aren’t in the room for this. And a credential typed into a fake login page on a phone — a username and password — works just as well for an attacker as one typed on a laptop.

    This is a different problem from the one where an attacker sticks a fraudulent sticker over the QR code printed in your Sunday bulletin. That’s a code your church published, replaced. This is a code that arrived at your church uninvited.

    Why a church office is close to an ideal target

    Here is the part that makes this specifically your problem.

    Unexpected packages are normal at a church. At a house, a box you didn’t order is strange, and that strangeness is the one instinct protecting the average consumer. At a church, boxes arrive constantly — VBS curriculum, communion supplies, replacement bulbs, a case of coffee, something a small group leader ordered on the ministry card three weeks ago, a donated item somebody mailed in. Five different people can order things, and none of them tells the office. An unaccounted-for package doesn’t raise a flag because there is no baseline to raise it against.

    The person opening the mail is rarely the person who got the training. Mail-opening lands on a volunteer, a part-time administrator, or whoever is at the desk that morning. They’re helpful by disposition — that’s why they’re there. Solving the mystery of a strange package by scanning the code that offers to solve it is the natural, generous, competent-seeming thing to do.

    There’s no policy to violate. Nobody has ever written down what to do with an unexpected box, because until recently there was nothing to write.

    Churches are easy to research. Your address, your staff names, and often their email addresses are on your website. That is all the data set a brushing operation needs.

    It’s a symptom, not just an incident

    Even if nobody scans anything, the package tells you something.

    The USPIS point is worth taking seriously: “scammers obtain personal information through nefarious means.” The box arrived because your organization’s details are sitting in somebody’s list. Not necessarily from a breach of your systems — far more often from a vendor, a mailing list, a directory, or a public filing. But circulating, in the hands of people running fraud schemes.

    If the package was addressed to the church generally, that’s your organizational data. If it was addressed to a named staff member at the church address, that person’s details are circulating too — and the same list is likely being used for email and phone attacks that will arrive later and won’t come in a box.

    Treat it as a prompt, not an emergency. Two things are worth doing: confirm that multi-factor authentication is turned on for church email and any financial accounts, and mention to the named staff member that they may want to watch their own accounts for a while. That’s it. No panic required.

    What to tell your older members

    This lands hardest at home, and hardest on the people least likely to have anyone to ask.

    The FBI’s 2025 Internet Crime Report logged 201,266 complaints from victims aged 60 and over, with losses totaling $7.748 billion — losses up 59% in a single year, and averaging $38,500 per report. Those are the figures for all internet crime, not brushing alone, but the direction tells you who is being worked hardest right now.

    A church is one of the very few institutions that can warn that age group and actually be believed. Not a bank’s form letter, not a news segment. A line in the newsletter and a sentence from the front on a Sunday morning:

    If a package arrives that you didn’t order, don’t scan any code inside it. You can keep the item — you’re not obligated to pay for it. But the card with the QR code is the scam, and scanning it can hand over your accounts. If it happens, tell the office and we’ll help you sort it out.

    That last sentence matters more than the rest. People who have been caught by something like this tend to go quiet out of embarrassment, and the quiet is what turns a small problem into a big one.

    If you can’t identify what’s inside

    One physical-safety note the Postal Inspection Service raises, and it’s short.

    If an unsolicited package contains organic material — seeds, plant matter, food — or a substance you cannot identify, don’t handle it, don’t open it further, and don’t throw it in the trash. Set it down and report it. The Postal Inspection Service takes these reports, and unsolicited seed shipments in particular have been the subject of federal and state agricultural warnings. This is rare. It costs nothing to know.

    For an ordinary unwanted package, you’re within your rights to keep it or discard it. If it’s unopened, you can mark it “RETURN TO SENDER” and hand it back to the carrier. You are never obligated to pay for something you didn’t order.

    What to do this week

    Add one line to whatever passes for your mail routine. Say it out loud to whoever opens the mail, and write it on a sticky note on the mail table if that’s what it takes:

    If a package arrives that nobody can account for, don’t scan anything inside it. Set it aside and ask.

    Ten seconds to say. It closes the entire category, because it doesn’t require the volunteer to judge whether a particular card looks legitimate — only to notice that nobody ordered the box.

    Put four sentences in the next newsletter warning members about unexpected packages and the codes inside them. Use the language above. Aim it at the people in your congregation who live alone and get few visitors, because they’re the ones for whom a surprise package is a small bright spot rather than a question.

    Fifteen minutes, total, and no budget.

    If someone did scan a code and enter a password, treat it like any other stolen credential: change that password immediately from a different device, sign out of all sessions, turn on multi-factor authentication, and watch the account. If money moved, report it to the FBI at ic3.gov the same day — speed is most of what determines whether funds can be frozen. If personal information was entered, identitytheft.gov walks through the recovery steps.

    MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including the small physical habits like this one — and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: US Postal Inspection Service, Brushing Scam; FBI Internet Crime Complaint Center, Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes, I-073125-PSA; Federal Trade Commission, Scam alert: QR code on an unexpected package; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Payroll Diversion: The Email That Steals Someone’s Paycheck

    Payroll Diversion: The Email That Steals Someone’s Paycheck

    Most of the attacks in this series steal from the organization. This one steals from a person on your staff — and they usually don’t find out until payday, when the money simply isn’t there.

    The email goes to whoever handles payroll. It appears to come from a staff member:

    Hi Karen — I’ve switched banks. Could you update my direct deposit before Friday’s run? New details attached. Thanks!

    That’s it. No urgency theatre, no drama. Just an administrative request of a kind that arrives legitimately several times a year.

    Karen updates the record. On Friday, that staff member’s entire paycheck lands in an account controlled by a stranger, and the person who earned it opens their banking app to find nothing.

    Why this one hurts differently

    It’s worth naming the human dimension before the technical one, because it changes how you should respond.

    When BEC takes $40,000 from the church, the organization absorbs a loss. When payroll diversion succeeds, an individual — often someone on a modest church salary — misses rent. And there’s frequently no clean answer about who makes them whole. The employer may not be legally obliged to pay twice. The bank may not recover it. The person did nothing wrong at all; they were simply impersonated.

    That’s why this deserves its own attention rather than being folded into general invoice fraud. The victim is a colleague, and the fallout is personal.

    The two ways in

    The impersonation route. The attacker sends from an outside address with the staff member’s name as the display name — the friendly label your mail app shows instead of the actual address. It’s free text; anyone can set it to anything. On a phone, where the real address is hidden entirely, the message looks exactly like it came from your colleague.

    The account takeover route. More dangerous and, according to FBI advisories, the common pattern. The staff member is phished first — they receive a message that looks like it’s from the payroll provider or the IT helpdesk, follow a link to a convincing but counterfeit login page, and type in their credentials. Now the attacker has a genuine account, and the request to change direct deposit comes from the real address, in a real thread, from a real person’s mailbox.

    In the takeover version, attackers commonly do something that makes this much worse: they disable change notifications. Most payroll systems email the employee when their banking details are updated. The attacker turns that off first, which is why the theft goes unnoticed until payday rather than within the hour.

    They also frequently add a mail rule that quietly files any message containing “payroll,” “direct deposit,” or “deposit change” into an unread folder, so the employee never sees the confirmation even if one slips through.

    The FBI has warned about this pattern since 2018, noting that attackers use stolen credentials to access the employer’s HR system, replace the employee’s banking information, and then suppress the alerts. The Bureau’s guidance to employers is direct: require separate credentials for payroll systems, use two-factor authentication, and establish protocols requiring extra approval for banking change requests.

    What makes a church or nonprofit vulnerable

    Payroll is often one person’s job, done in a hurry. There’s no HR department. The office administrator handles payroll alongside facilities, bulletins, and the phone. A one-line request that takes ninety seconds to action gets actioned.

    Direct deposit changes are genuinely routine. People do switch banks. Requests like this arrive legitimately, which means there’s no natural suspicion attached to the category.

    Staff email addresses are public. Your staff page lists them. An attacker can determine who does payroll and who to impersonate without any access at all.

    The window is predictable. Payroll runs on a schedule. An attacker who knows you pay on the 15th and the last day of the month knows exactly when to send, and exactly how long they have before anyone notices.

    The control that stops it

    One rule, and it mirrors the one for vendor payments:

    No banking change is ever actioned from a written request alone. The person is called back on the number already in their personnel file, and asked to confirm.

    The details matter.

    Called back — you initiate the call. Don’t accept a number supplied in the request, and don’t accept a call from someone claiming to be the employee. The direction of the call is the control.

    The number already on file — from the personnel record, not the message signature. If your only number for them is one they gave you recently by email, that’s worth fixing.

    Confirm the specifics — read the last four digits of the new account number aloud and ask them to confirm. Don’t ask “did you request a change?” A yes-or-no question invites a yes from someone who isn’t listening carefully.

    Two additions worth making. Impose a deliberate delay — banking changes take effect on the next payroll run, not this one. Attackers depend on a change landing before the next payday; a one-cycle lag removes the whole business model. And notify the employee through a second channel whenever their details change — a text or a call, not just an email, because the email may be sitting in a folder the attacker created.

    Hardening the systems

    Multi-factor authentication on email and the payroll portal, separately. This is the extra code or tap after the password. It’s the single control that defeats the account-takeover route, and it’s free on Microsoft 365 and Google Workspace. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Make sure your payroll provider’s portal has it enabled too — it’s often a separate setting that nobody has turned on.

    Use different credentials for payroll. If your payroll login is the same password as your email, one phishing success gives away both. This is exactly the FBI’s recommendation.

    Turn change notifications back on, and check they’re on. Then verify quarterly that they haven’t been switched off. In the payroll system, confirm that alerts go to an address the employee controls and, ideally, to a second person in the office.

    Audit mail rules. Once a quarter, in each staff mailbox, look at the forwarding rules and filters. A rule nobody remembers creating — especially one that files or forwards messages containing payroll keywords — is a strong signal that the account has been compromised. This is the most commonly overlooked step after a password reset.

    Teach the staff member’s side too

    The control above protects the organization’s process. Your team also needs to recognize the phishing that precedes the takeover.

    Tell them plainly: you will never receive a legitimate email asking you to log in to view a pay stub, confirm your direct deposit, or re-verify your payroll account. If a message like that arrives, don’t use the link. Open a browser and go to the payroll site the way you normally do, or call the office.

    That single habit — never sign in from a link in a message — defeats credential phishing in every form, not just this one.

    If it already happened

    Move immediately; this is recoverable more often than people expect, but only quickly.

    Call the bank that received the money and report the deposit as fraudulent. If the payroll run has processed but the funds haven’t been withdrawn, they can sometimes be frozen.

    Call your own bank and your payroll provider and ask about a reversal. Some ACH transfers can be recalled within a narrow window.

    Report it to the FBI at ic3.gov, and use the words payroll diversion and business email compromise. The Bureau’s Recovery Asset Team can trigger a process to freeze funds in transit — in 2025 it ran 3,574 domestic cases and froze $507,042,623. It works dramatically better inside the first day or two.

    Assume the mailbox is compromised until proven otherwise. Change the password from a different device, revoke all active sessions (“sign out everywhere”), re-enable MFA, and check for mail rules the attacker added.

    Then take care of the person. Decide quickly whether the organization will cover the missed pay while recovery is attempted. Whatever you decide, decide it fast and say it plainly — a staff member who has lost a paycheck through no fault of their own should not spend a week wondering.

    What to do this week

    Write down one sentence and give it to whoever runs payroll: Banking changes are confirmed by calling the employee on the number in their personnel file, and take effect on the following pay run.

    Then check two settings — that change notifications are turned on in your payroll system, and that multi-factor authentication is enabled on the payroll portal as well as on email.

    Half an hour, and this attack stops working on you.

    MissionDefend’s free assessment walks through exactly these kinds of gaps in plain English — how you handle email, donations, member data, and accounts — and gives you a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI, Building a Digital Defense Against Payroll Phishing Scams; FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.

  • Business Email Compromise: How One Fake Invoice Drains an Account

    Business Email Compromise: How One Fake Invoice Drains an Account

    Your church is six months into a roof replacement. The contractor has invoiced twice already, both paid without incident. On a Thursday morning, the third invoice arrives from the same email address you’ve been corresponding with all spring.

    The invoice looks right. Same logo, same layout, same project reference, correct amount. There’s one difference, and it’s mentioned in a single line of the email body:

    Please note we’ve changed banks — updated remittance details are on the invoice. Sorry for the inconvenience.

    Your bookkeeper updates the payee, sends $47,000, and files the confirmation.

    Eleven days later the contractor calls to ask when they’re getting paid.

    This is business email compromise. It is the most expensive attack aimed at organizations your size, and it almost never looks like an attack while it’s happening.

    What BEC actually means

    Business email compromise — you’ll see it shortened to BEC everywhere — is the category of fraud where someone uses email to impersonate a person you trust in order to redirect a payment.

    The name is slightly misleading, and the confusion matters, because the two versions call for different responses.

    Version one: nothing was compromised. The attacker registered a domain that looks like your contractor’s and sent mail from it. Your vendor is `midlandroofing.com`; the attacker owns `midiandroofing.com` — an l swapped for an i, invisible in most fonts at normal size. Or `midland-roofing.com` with a hyphen. Or `midlandroofing.co` dropping the m. Everything else in the email is copied from real correspondence. Nobody’s account was ever accessed.

    Version two: an account really was taken over. The attacker got into a mailbox — usually through a phished password — and is sending from the genuine address. This version is far more dangerous, because there is nothing to spot in the sender line. It’s genuinely the right address. Worse, the attacker can read the entire history first: they know your project, your invoice format, your payment cycle, who approves what, and how your bookkeeper writes. They often set up a quiet mail rule that moves the real vendor’s messages into an unread folder, so the two of you stop seeing each other’s emails while the attacker relays between you.

    The second version is why “just look at the sender address” is necessary advice but not sufficient advice.

    The scale of it

    The FBI’s Internet Crime Complaint Center recorded 24,768 BEC complaints in 2025, totalling $3,046,598,558 in losses. That works out to an average reported loss of about $123,005 per complaint.

    Sit with that figure against a church budget. For most congregations, one successful BEC is larger than a quarter of total giving. For a small nonprofit, it can be existential.

    And BEC is a rounding error away from being invisible. There’s no ransom note, no locked screen, no alarm. The first sign is almost always a vendor politely asking about an overdue payment.

    The five shapes it takes in a ministry

    The vendor bank change. The scenario above. Most common and most costly, and it spikes during building projects, capital campaigns, and any period when large payments to unfamiliar contractors are normal.

    The leadership wire request. An email that appears to come from your pastor or executive director, asking the bookkeeper to send a payment urgently, usually with a reason it can’t be discussed by phone.

    The payroll redirect. A staff member appears to email HR asking to update their direct deposit details. We’re covering this one in full tomorrow, because it works differently enough to deserve its own post.

    The invoice that was never real. A plausible bill for something a church actually buys — copier maintenance, website hosting, denominational dues, a directory listing — from a company you can’t quite remember but probably use. Small enough to approve without scrutiny. Often repeated monthly until someone notices.

    The data request. No money at all. Someone asks for the staff list, W-2 information, or the donor database. That data becomes the ammunition for the next attack, aimed at a different organization.

    Why churches are good targets for this specifically

    Three things, none of them a failing.

    Approval is informal. In a five-person office, the person who receives the invoice is often the person who pays it. There’s no purchasing department, and adding one would be absurd. But it means a single deceived person completes the whole transaction.

    Large, irregular payments are normal. A church might make three $40,000 payments a year and hundreds of $200 payments. The big ones don’t recur often enough for anyone to develop an instinct about them, and they cluster in exactly the periods — building projects, campaigns — when everyone is busy and moving fast.

    Your relationships are public. Your bulletin thanks the contractor. Your newsletter names the architect. Your board minutes list the vendors. An attacker doesn’t have to guess who you’re paying.

    The one control that stops it

    There is a single procedure that defeats every version of this attack, and it costs nothing:

    Any change to payment details is verified by voice, using a phone number you already had, before the payment goes out.

    Every word in that sentence is load-bearing.

    Any change — not just large ones. The threshold approach fails, because attackers learn thresholds.

    By voice — not by email. If the attacker controls the email thread, every confirmation you receive is written by them. This is the part people get wrong most often: replying to the message and getting a reassuring answer feels like verification, and it is the opposite of verification.

    A number you already had — from a signed contract, a previous invoice, or your own contacts. Never the number in the email or on the new invoice. Attackers put their own number on the document precisely so you’ll “verify.”

    Before the payment goes out — because after is a recovery problem, not a prevention one.

    Two additions make it stronger. Require two people for any payment over a threshold your board sets — one to initiate, a different one to release. And read the bank details aloud during the verification call, digit by digit, rather than asking “did you change banks?” A yes-or-no question invites a yes.

    Write the rule down. Give it to everyone who touches a payment. And state plainly that no one will ever be criticized for making the call, including when the request appears to come from the senior pastor. In a small church, the person most likely to be defrauded is the one who feels least entitled to question leadership.

    Hardening the email side

    The procedure is the main defense. Three technical measures reduce how often you’re tested.

    Multi-factor authentication on every mailbox. This is the extra step after your password — a code from an app, or a tap on your phone. It’s what prevents version two of this attack, where an account is genuinely taken over. Microsoft’s research finds MFA blocks more than 99.2% of account compromise attacks. It’s free on Microsoft 365 and Google Workspace.

    External sender warnings. Ask whoever manages your email to enable the banner reading “This message came from outside your organization.” When a message claiming to be from your executive director carries that banner, the contradiction is visible immediately.

    Check for mail rules you didn’t create. After any suspected compromise — and once a quarter regardless — look in each mailbox’s settings for forwarding rules and filters. Attackers routinely add a rule that forwards everything to an outside address, or that files messages containing “invoice” or “payment” into an obscure folder. It’s the most common thing left behind, and it’s the thing people forget to check after changing a password.

    If it already happened

    Speed is nearly everything. The recall window on a fraudulent transfer is measured in hours.

    Call your bank’s fraud line first. Before you investigate, before you email anyone, before you’re certain. Ask them to attempt a recall. If you have the number ready in advance rather than searching for it, that alone can be the difference.

    Report to the FBI at ic3.gov immediately, and say the words business email compromise and fraudulent wire transfer. This is not a formality. The FBI’s Recovery Asset Team can initiate what’s called the Financial Fraud Kill Chain — a process to freeze funds before they’re moved onward. In 2025 it ran 3,574 domestic cases and froze $507,042,623. It works far better within the first 24–72 hours.

    Don’t reply to the fraudulent thread, and don’t delete anything. The mailbox is evidence.

    Change passwords from a different device and revoke active sessions — in Microsoft 365 and Google Workspace there’s a “sign out everywhere” option. Changing a password alone doesn’t kick out someone who’s already signed in.

    Then check the mail rules, as above.

    And tell your insurer. Many cyber liability policies cover funds transfer fraud, and most impose short notification deadlines.

    What to do this week

    Write down the verification rule and circulate it to everyone who can initiate or approve a payment. One paragraph. Then find your bank’s fraud number and put it somewhere that doesn’t require logging into a computer — taped inside a cabinet door is fine.

    That’s an afternoon’s work against the single most expensive attack aimed at organizations your size.

    When you’re ready to see where else you stand, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then gives you a baseline score and a ranked list of priorities.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.