If you work at a church, you have probably already seen this one. If you haven’t, you will.
A member of your congregation gets a text from an unfamiliar number:
Hello, are you available? I need a favor. — Pastor Mike
Or an email lands in a volunteer’s inbox. The sender name says Pastor Mike Adams, exactly as it appears in every other message from him. The subject line is Quick request. The body is two sentences.
Are you free right now? I’m in a meeting and can’t talk on the phone, but I need something handled discreetly.
Anyone who replies gets the ask. The church needs to buy gift cards — Apple, Google Play, Amazon, Target — for a member in the hospital, or for a benevolence case, or as thank-you gifts for volunteers. The pastor will reimburse them. It’s urgent, it’s a little sensitive, and could they please just scratch off the backs and send photos of the codes?
This scam runs constantly, in every denomination, in churches of every size. It is worth understanding precisely, because the mechanics are simpler than most people assume — and so is the fix.
Nobody hacked anything
The most important thing to understand: in almost every version of this scam, the pastor’s account was never broken into.
That surprises people, because the message looks like it came from him. But the attacker didn’t need access. They needed one of two very ordinary tricks.
Trick one: display name spoofing
Every email has two separate pieces of sender information, and your mail app shows you one of them.
The display name is the friendly label — Pastor Mike Adams. The email address is the actual routing information — mike@yourchurch.org.
Here’s the thing that makes this scam work: the display name is just text. Anyone can type anything they like into it. There is no verification, no check, no ownership requirement. I can create a free email account right now and set my display name to “Pastor Mike Adams,” and every message I send will show up in your inbox with that name on it.
The real address underneath would be something like `pastormike.adams247@gmail.com` or `mike.adams.church@outlook.com` — plausible enough that if you did glance at it, it might not alarm you.
And on a phone, you usually can’t glance at it. Mobile mail apps show the display name and hide the address entirely to save screen space. That is not a bug in your phone. It’s a design choice that this scam exploits, and it’s why these messages so often get read and answered on a phone rather than a desktop.
Trick two: an unfamiliar phone number
The text-message version is even simpler. There’s no spoofing at all. The attacker just texts from a number you’ve never seen and signs the message with the pastor’s name. Because a new number shows up with no contact photo and no history, and because plenty of people do change phones, “Hi, this is Pastor Mike, I got a new number” is not automatically suspicious.
Where do they get the names and numbers? Nowhere clever. Your staff page lists who your pastor is. Your bulletin names your office administrator. Your Facebook page shows who volunteers. Church directories get shared. None of that is a security failure — it’s a church being findable, which is the point of a church. But it means an attacker can build a convincing message with fifteen minutes of public browsing.
Why gift cards specifically
This is the detail that gives the scam away, once you know it.
Gift cards are, for a criminal, close to perfect. They are effectively untraceable — once the code is spent, there’s no account holder to subpoena and no transaction to reverse. They are instantly transferable — a photo of the scratched-off code is all that’s needed; the physical card is irrelevant. They are irreversible — unlike a credit card charge or even a wire transfer, there is no dispute process and no recall window. And they are available everywhere, which means a victim can complete the whole request in twenty minutes at a grocery store.
Compare that to a bank transfer, which leaves a paper trail, involves an institution that can freeze funds, and requires the criminal to maintain an account somewhere.
So here is the rule that flows from that, and it’s worth putting in bold in your bulletin:
No legitimate church request will ever involve buying gift cards and sending photos of the codes. Not for benevolence. Not for a hospital visit. Not for volunteer appreciation. Not ever. There is no scenario in normal church operations where that is how money moves.
That single sentence, taught once, immunizes most people permanently — because it doesn’t require anyone to evaluate whether a particular message looks legitimate. It just makes the ask itself the tell.
The wider pattern
Gift cards are the most common version, but the same impersonation gets used for other requests, and your team should recognize the family resemblance:
A request to wire funds urgently for a deposit or a contractor, before end of business.
A request to buy cryptocurrency and send it to a wallet address.
A request for the staff list, the member directory, or W-2 information — no money at all, just data, which then gets used for the next attack or sold.
A request to buy something on your personal card and be reimbursed later, which is really just gift cards with extra steps.
The shape is always the same: authority, urgency, a reason you can’t verify by voice right now, and a request that moves value in a way that can’t be undone.
What the FBI data says
This isn’t folklore. Phishing and spoofing were the most-reported cybercrime in America in 2025, with 191,561 complaints filed with the FBI’s Internet Crime Complaint Center.
The demographic detail matters for congregations. Victims aged 60 and over filed 201,266 complaints in 2025, losing $7.748 billion — a 59% increase over the previous year, averaging $38,500 per victim. Older members of your congregation are being targeted heavily, and a warning from their church may be the most credible one they receive.
How to shut it down
Four things. None of them take money, and the first two take an afternoon.
Tell your congregation, in plain words, from the front. Not a technical bulletin insert nobody reads — a spoken sentence, from the platform or in the newsletter, in the pastor’s own voice: “I will never text or email you asking for gift cards, money, or a favor involving payment. If you get a message like that with my name on it, it isn’t me. Please don’t reply, and please tell the office.” Coming from the person being impersonated, this lands differently than a security notice.
Teach the one habit that works on a phone. Before acting on any message asking for money or a favor, tap the sender’s name to reveal the actual email address. On a text, check whether the number matches the one already in your contacts. If it doesn’t, that’s your answer. This takes three seconds and doesn’t require anyone to be technical.
Make verification impersonal and expected. Write down that any money-related request is confirmed by voice, using a number you already had — not a number in the message. Say explicitly that this applies to requests that appear to come from leadership, and that nobody will ever be thought disloyal for making the call. That last clause is doing real work: the reason these scams succeed in churches is that questioning the pastor feels wrong.
Turn on the technical guardrails. Two settings help meaningfully. First, multi-factor authentication on every staff email account — the extra code or tap after the password — which protects you in the cases where an account really is compromised rather than merely imitated. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Second, ask whoever manages your email to enable external sender warnings, the banner that says “This message came from outside your organization.” When a message claims to be from your pastor and carries that banner, the contradiction is visible even on a phone.
If you want to go further, the fuller fix is email authentication — the SPF, DKIM and DMARC records that stop strangers sending mail that claims to come from your domain at all. That’s a bigger topic, and it’s coming later in this series.
If someone already bought the cards
Move fast; there’s a narrow window.
Call the gift card issuer’s fraud line immediately — the number is on the back of the card or on the retailer’s website — and report the cards as fraudulently obtained. Occasionally, if the codes haven’t been spent, funds can be frozen. Keep the physical cards and the receipts; they’re evidence and they’re required for any claim.
Report it to the FBI at ic3.gov. This feels pointless for a few hundred dollars, and it isn’t: the aggregate reporting is what drives takedowns, and it’s how the pattern gets tracked.
Then tell your congregation what happened, without naming the person who was fooled. Someone who admits they were scammed has done your whole community a service, and how you treat them determines whether the next person speaks up in twenty minutes or three days.
What to do this week
Write four sentences and send them to your congregation under your pastor’s name: I will never text or email you asking for gift cards or money. If you get a message like that with my name on it, it isn’t me. Don’t reply. Tell the office.
That’s it. That’s the highest-value fifteen minutes available to most churches this month.
When you’re ready to look at the whole picture rather than one scam at a time, MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts — then give you a baseline score and a ranked list of what to fix first.
No spam and no sales calls — just one email when it’s live.
Related reading
- the six-figure version of the same impersonation trick
- why attackers work on people instead of software
- giving staff somewhere to send the messages they doubt
MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.
Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.


