Home Articles Get your free assessmentComing soon

Category: Threats & Scams

Plain-English breakdowns of the specific attacks aimed at churches and nonprofits — how each one works, what the message actually looks like, and the control that stops it.

  • Your Pastor Won’t Text You for Gift Cards: The Impersonation Scam

    Your Pastor Won’t Text You for Gift Cards: The Impersonation Scam

    If you work at a church, you have probably already seen this one. If you haven’t, you will.

    A member of your congregation gets a text from an unfamiliar number:

    Hello, are you available? I need a favor. — Pastor Mike

    Or an email lands in a volunteer’s inbox. The sender name says Pastor Mike Adams, exactly as it appears in every other message from him. The subject line is Quick request. The body is two sentences.

    Are you free right now? I’m in a meeting and can’t talk on the phone, but I need something handled discreetly.

    Anyone who replies gets the ask. The church needs to buy gift cards — Apple, Google Play, Amazon, Target — for a member in the hospital, or for a benevolence case, or as thank-you gifts for volunteers. The pastor will reimburse them. It’s urgent, it’s a little sensitive, and could they please just scratch off the backs and send photos of the codes?

    This scam runs constantly, in every denomination, in churches of every size. It is worth understanding precisely, because the mechanics are simpler than most people assume — and so is the fix.

    Nobody hacked anything

    The most important thing to understand: in almost every version of this scam, the pastor’s account was never broken into.

    That surprises people, because the message looks like it came from him. But the attacker didn’t need access. They needed one of two very ordinary tricks.

    Trick one: display name spoofing

    Every email has two separate pieces of sender information, and your mail app shows you one of them.

    The display name is the friendly label — Pastor Mike Adams. The email address is the actual routing information — mike@yourchurch.org.

    Here’s the thing that makes this scam work: the display name is just text. Anyone can type anything they like into it. There is no verification, no check, no ownership requirement. I can create a free email account right now and set my display name to “Pastor Mike Adams,” and every message I send will show up in your inbox with that name on it.

    The real address underneath would be something like `pastormike.adams247@gmail.com` or `mike.adams.church@outlook.com` — plausible enough that if you did glance at it, it might not alarm you.

    And on a phone, you usually can’t glance at it. Mobile mail apps show the display name and hide the address entirely to save screen space. That is not a bug in your phone. It’s a design choice that this scam exploits, and it’s why these messages so often get read and answered on a phone rather than a desktop.

    Trick two: an unfamiliar phone number

    The text-message version is even simpler. There’s no spoofing at all. The attacker just texts from a number you’ve never seen and signs the message with the pastor’s name. Because a new number shows up with no contact photo and no history, and because plenty of people do change phones, “Hi, this is Pastor Mike, I got a new number” is not automatically suspicious.

    Where do they get the names and numbers? Nowhere clever. Your staff page lists who your pastor is. Your bulletin names your office administrator. Your Facebook page shows who volunteers. Church directories get shared. None of that is a security failure — it’s a church being findable, which is the point of a church. But it means an attacker can build a convincing message with fifteen minutes of public browsing.

    Why gift cards specifically

    This is the detail that gives the scam away, once you know it.

    Gift cards are, for a criminal, close to perfect. They are effectively untraceable — once the code is spent, there’s no account holder to subpoena and no transaction to reverse. They are instantly transferable — a photo of the scratched-off code is all that’s needed; the physical card is irrelevant. They are irreversible — unlike a credit card charge or even a wire transfer, there is no dispute process and no recall window. And they are available everywhere, which means a victim can complete the whole request in twenty minutes at a grocery store.

    Compare that to a bank transfer, which leaves a paper trail, involves an institution that can freeze funds, and requires the criminal to maintain an account somewhere.

    So here is the rule that flows from that, and it’s worth putting in bold in your bulletin:

    No legitimate church request will ever involve buying gift cards and sending photos of the codes. Not for benevolence. Not for a hospital visit. Not for volunteer appreciation. Not ever. There is no scenario in normal church operations where that is how money moves.

    That single sentence, taught once, immunizes most people permanently — because it doesn’t require anyone to evaluate whether a particular message looks legitimate. It just makes the ask itself the tell.

    The wider pattern

    Gift cards are the most common version, but the same impersonation gets used for other requests, and your team should recognize the family resemblance:

    A request to wire funds urgently for a deposit or a contractor, before end of business.

    A request to buy cryptocurrency and send it to a wallet address.

    A request for the staff list, the member directory, or W-2 information — no money at all, just data, which then gets used for the next attack or sold.

    A request to buy something on your personal card and be reimbursed later, which is really just gift cards with extra steps.

    The shape is always the same: authority, urgency, a reason you can’t verify by voice right now, and a request that moves value in a way that can’t be undone.

    What the FBI data says

    This isn’t folklore. Phishing and spoofing were the most-reported cybercrime in America in 2025, with 191,561 complaints filed with the FBI’s Internet Crime Complaint Center.

    The demographic detail matters for congregations. Victims aged 60 and over filed 201,266 complaints in 2025, losing $7.748 billion — a 59% increase over the previous year, averaging $38,500 per victim. Older members of your congregation are being targeted heavily, and a warning from their church may be the most credible one they receive.

    How to shut it down

    Four things. None of them take money, and the first two take an afternoon.

    Tell your congregation, in plain words, from the front. Not a technical bulletin insert nobody reads — a spoken sentence, from the platform or in the newsletter, in the pastor’s own voice: “I will never text or email you asking for gift cards, money, or a favor involving payment. If you get a message like that with my name on it, it isn’t me. Please don’t reply, and please tell the office.” Coming from the person being impersonated, this lands differently than a security notice.

    Teach the one habit that works on a phone. Before acting on any message asking for money or a favor, tap the sender’s name to reveal the actual email address. On a text, check whether the number matches the one already in your contacts. If it doesn’t, that’s your answer. This takes three seconds and doesn’t require anyone to be technical.

    Make verification impersonal and expected. Write down that any money-related request is confirmed by voice, using a number you already had — not a number in the message. Say explicitly that this applies to requests that appear to come from leadership, and that nobody will ever be thought disloyal for making the call. That last clause is doing real work: the reason these scams succeed in churches is that questioning the pastor feels wrong.

    Turn on the technical guardrails. Two settings help meaningfully. First, multi-factor authentication on every staff email account — the extra code or tap after the password — which protects you in the cases where an account really is compromised rather than merely imitated. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Second, ask whoever manages your email to enable external sender warnings, the banner that says “This message came from outside your organization.” When a message claims to be from your pastor and carries that banner, the contradiction is visible even on a phone.

    If you want to go further, the fuller fix is email authentication — the SPF, DKIM and DMARC records that stop strangers sending mail that claims to come from your domain at all. That’s a bigger topic, and it’s coming later in this series.

    If someone already bought the cards

    Move fast; there’s a narrow window.

    Call the gift card issuer’s fraud line immediately — the number is on the back of the card or on the retailer’s website — and report the cards as fraudulently obtained. Occasionally, if the codes haven’t been spent, funds can be frozen. Keep the physical cards and the receipts; they’re evidence and they’re required for any claim.

    Report it to the FBI at ic3.gov. This feels pointless for a few hundred dollars, and it isn’t: the aggregate reporting is what drives takedowns, and it’s how the pattern gets tracked.

    Then tell your congregation what happened, without naming the person who was fooled. Someone who admits they were scammed has done your whole community a service, and how you treat them determines whether the next person speaks up in twenty minutes or three days.

    What to do this week

    Write four sentences and send them to your congregation under your pastor’s name: I will never text or email you asking for gift cards or money. If you get a message like that with my name on it, it isn’t me. Don’t reply. Tell the office.

    That’s it. That’s the highest-value fifteen minutes available to most churches this month.

    When you’re ready to look at the whole picture rather than one scam at a time, MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts — then give you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.

  • Social Engineering: Why Attackers Target Your People, Not Your Firewall

    Social Engineering: Why Attackers Target Your People, Not Your Firewall

    The email arrived at 8:52 on a Tuesday morning. It was from the pastor — his name, right there in the sender line — and it was short.

    Are you at your desk? I need you to handle something for me. I’m in a meeting so I can’t take calls.

    The office administrator wrote back that yes, she was at her desk. What did he need?

    Nothing about that exchange involved breaking into anything. No password was cracked. No virus was installed. No firewall was bypassed. And yet, ninety minutes later, the church was out $1,800 in gift cards.

    This is social engineering, and it is the single most common way churches and nonprofits lose money and data. Not because your organization is careless. Because it is the way the overwhelming majority of attacks now work, everywhere, and because the things that make a ministry good at being a ministry are the same things that make social engineering effective.

    What “social engineering” actually means

    The phrase sounds like jargon, and it is — but the idea underneath it is simple.

    Social engineering is persuading a person to do something, rather than forcing a computer to do it.

    That’s the whole definition. An attacker who breaks encryption is doing technical work. An attacker who convinces your bookkeeper to change a vendor’s bank details is doing social work. The second is dramatically easier, dramatically cheaper, and requires no special skill beyond patience and a plausible story.

    It helps to think of it the way you’d think about a con artist in any other era. The technology is new. The technique is not. Someone is establishing a reason you should trust them, creating a situation where checking feels rude or slow, and asking for something that seems small in the moment.

    You’ll see a lot of specific names for these attacks, and the vocabulary can feel like a wall. Here is the map, in plain terms:

    Phishing is social engineering delivered by email — a message designed to get you to click, log in, or reply. The name is a play on “fishing,” because early versions cast a wide net and waited.

    Spear phishing is the same thing aimed at one specific person, using details about them. A spear instead of a net.

    Vishing is voice phishing — the scam arrives by phone call.

    Smishing is SMS phishing — it arrives by text message.

    Pretexting is the invented backstory that makes the request feel routine. “I’m calling from your insurance carrier about the annual audit” is a pretext.

    Business email compromise, usually shortened to BEC, is the category where someone impersonates a leader or a vendor to redirect a payment.

    Every one of those is a flavor of the same thing. Someone is talking to a human being and asking them to act.

    The numbers, and why they matter to a small office

    It’s tempting to read all this and assume it’s a problem for banks. The federal data says otherwise.

    The FBI’s Internet Crime Complaint Center — the government’s clearinghouse for reported cybercrime, usually called IC3 — logged 1,008,597 complaints in 2025, with just under $20.9 billion in reported losses. Within that, phishing and spoofing generated 191,561 complaints, making it the single most-reported crime type in the country.

    Business email compromise accounted for 24,768 complaints and more than $3 billion. Divide those out and the average reported loss per BEC report was about $123,005.

    Now hold that number against a church budget. For most congregations, a single successful impersonation email costs more than a quarter’s giving. And note what didn’t appear anywhere in that description: malware, hacking tools, technical sophistication. It required someone to believe an email.

    There’s one more figure worth sitting with, because it touches your congregation rather than your office. IC3 recorded 201,266 complaints from victims aged 60 and over in 2025, with $7.748 billion in losses — a 59% increase over the prior year, and an average loss of $38,500 per victim. The people in your pews are being targeted, and many of them will hear about it from you before they hear about it from anyone else.

    The six levers

    Every social engineering attack pulls on at least one of six psychological levers. Once you can name them, you start noticing them, and noticing is most of the defense.

    Authority. The request appears to come from someone you don’t question — the pastor, the executive director, the board chair, the bank, the IRS. Authority short-circuits the instinct to verify, because verifying feels like doubting your boss.

    Urgency. There’s a deadline, real or invented. Before noon. Before the wire cutoff. Before the account is suspended. Urgency exists to prevent you from doing the one thing that would defeat the attack: pausing.

    Familiarity. The message uses the right names, the right tone, the right details. It mentions the building project by name. It knows your treasurer is called Deb, not Deborah. Familiarity is why these messages feel real — and it’s cheap to manufacture, because your staff page, bulletin, Facebook posts, and public filings are all free research material.

    Fear. Something bad will happen. Your mailbox will be deleted. Your account is compromised. There’s a legal problem. Fear narrows attention to the threat and away from the oddities in the message.

    Curiosity. An unexpected invoice. A shared document. A photo from the retreat. Curiosity is the lever behind most malicious attachments, because opening something to find out what it is feels harmless.

    The wish to be helpful. This is the one that matters most in ministry, and the one nobody wants to hear. Churches and nonprofits are staffed by people whose whole disposition is to help quickly, assume the best, and not interrogate someone who asks for something. That disposition is a virtue. It is also, precisely, the surface an attacker aims at.

    That last point deserves care. The lesson is not that your team should become suspicious of everyone. A congregation that treats every request as a threat has lost something more valuable than the money. The lesson is narrower and much more manageable: for a very small number of specific actions, verification becomes automatic and impersonal — not a judgment about the person asking, just the way that particular thing is always done.

    Why small organizations get chosen

    Three structural facts make churches and nonprofits attractive, and none of them are about carelessness.

    You hold valuable, irreplaceable data. Donor giving histories, member contact lists, background check results, counseling notes, children’s ministry records. Some of it has resale value. Some of it is simply devastating if it becomes public.

    Your money moves in ways that are hard to verify. Offerings, designated gifts, benevolence funds, reimbursements, contractor payments during a building project. Transaction volume is low enough that one fraudulent payment doesn’t stand out, and approval processes are usually informal because the team is small and trusts each other.

    And your information is public by design. A business hides its org chart. A church publishes it — with photos, titles, email addresses, and often direct phone numbers — because that’s how people find their pastor. An attacker doesn’t need to breach anything to learn who your finance person reports to.

    What actually stops it

    Because the attack targets people, the defense has to work at the level of people. Three things carry most of the weight, and none cost money.

    One rule, written down, about money. Any request to move funds, change bank details, or buy gift cards is verified by voice, using a phone number you already had — not a number in the message. Not by replying to the email. The attacker controls the email thread; they do not control the number in your directory. Write this rule down, tell everyone who touches money, and state plainly that nobody will ever be criticized for following it. The failure this prevents is a bookkeeper who feels too junior to question leadership.

    Permission to be wrong. The most expensive incidents are not the ones where someone got fooled. They’re the ones where someone got fooled and then waited three days to say so, hoping it would resolve itself. A misdirected payment caught in twenty minutes is often recoverable — the FBI’s Recovery Asset Team froze over $507 million across 3,574 domestic cases in 2025, and that process depends almost entirely on speed. The same mistake caught on Friday afternoon usually is not. Tell your team, in words, that reporting a mistake immediately is the desired behavior and will never be held against them.

    Fifteen minutes, twice a year, on real examples. Not an hour-long generic video. Show your actual staff the actual scams aimed at churches: the gift card request, the fake invoice from a vendor you really use, the “your mailbox is full” notice. Recognition is trainable. Familiarity with the specific shape of these messages is what makes someone pause.

    The rest of this series

    Over the coming weeks we’re going to take these apart one at a time — the gift card scam, business email compromise, payroll diversion, phone and text scams, AI voice cloning, and the rest. Each post explains one attack in plain language, shows what the message actually looks like, and ends with what to do about it.

    The goal isn’t to make you afraid of your inbox. It’s to make these attacks boring — familiar enough that when one arrives, someone on your team recognizes the shape of it and doesn’t have to guess.

    What to do this week

    Pick one thing. Write down the verify-by-voice rule for money requests, send it to everyone who touches a payment, and say explicitly that following it is never rude. That single paragraph, circulated once, closes the most expensive category of attack aimed at organizations like yours.

    MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts, then give you a baseline score and a ranked list of what to fix first. It’s launching soon — leave your email and we’ll tell you the moment it opens.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report.