The call comes in on a Wednesday around 10 a.m., which is not an accident — late enough that the office is busy, early enough that nobody’s left for lunch.
“Hi, this is Marcus from TechServe — we handle the copier contract? We’re pushing a security update to all our units this week and I need someone to read me the numbers off the admin sticker on the back. Should take two minutes. Sorry for the hassle — half the churches in the county are on my list today.”
There is no Marcus. There is no update. But notice everything that call already got right: a plausible company, a plausible task, an apology, a time limit, and a detail — half the churches in the county — that makes the whole thing feel routine. By the time an ask arrives, it doesn’t feel like a request from a stranger. It feels like step three of a process that started before you picked up.
That manufactured backstory has a name: pretexting. The pretext is the invented situation — the role, the reason, the paperwork — that makes the eventual request seem normal. If phishing is a fake message, pretexting is a fake context. It’s the con artist’s stage set, and it’s the engine inside most of the attacks this series has covered: the fake invoice works because “vendor billing you” is a pretext, and the phone scam works because “your bank’s fraud department” is one.
The costumes that get worn at churches
Attackers pick pretexts the target already expects to encounter. For a church or small nonprofit, four costumes come up over and over.
The IT technician. “We’re doing maintenance on your email this afternoon — I’ll need someone to confirm the login so accounts don’t lock out.” Small congregations rarely have in-house IT, so someone external who handles computer things is entirely believable — most churches genuinely do have a guy. The test is simple: real technicians you actually pay never need your password. Anyone who asks for one is not your technician, whatever the caller ID says.
The vendor with an account problem. The copier company, the payroll processor, the giving platform, the alarm monitoring service. The caller knows which one you use — often because it’s visible on your website, in a bulletin PDF, or on a sticker by the door — and the “problem” needs an account number, a card update, or remote access to fix.
The authority up the chain. The diocese, the district office, the denomination’s insurance program, an “auditor” doing an annual review. Hierarchical organizations are trained to respond to the level above them, and attackers borrow that reflex. A folder of official-looking paperwork, a confident tone, and a Friday-afternoon deadline can move remarkable amounts of information.
The government caller. The IRS about your exempt status, a “grant administrator” about funds you’re eligible for, a court officer about a missed jury summons for your pastor. Impersonating agencies and businesses is now squarely illegal under a rule the Federal Trade Commission put into force on April 1, 2024 — a rule created precisely because the FTC logged over $1.1 billion in reported impersonation-scam losses in 2023, more than triple the 2020 figure. A rule after the fact, of course, only helps you if you didn’t comply during the call.
Why good people hold the door open
Pretexting exploits the two instincts churches deliberately cultivate: helpfulness and trust. The volunteer at the desk wants to be useful to the nice technician. The bookkeeper doesn’t want to make the diocese wait. Nobody wants to be the suspicious one — it feels rude, and ministry culture prizes warmth.
So the fix cannot be “make everyone suspicious.” It won’t take, and it would cost you something real. The fix is to make verification feel like procedure instead of accusation — the same shift that makes a bank teller checking ID feel professional rather than hostile.
What to do this week
Give the front desk a script that isn’t rude. One laminated card: “Happy to help with that — our process is to call you back through the main number we have on file for your company. What’s your name and extension?” A real vendor hears bookkeeping hygiene. A pretexter hears the con failing. The power of the callback is that it routes around everything the attacker controls — their number, their story, their urgency — to a channel you already trusted before the call existed.
Keep a one-page vendor sheet. Every company that can plausibly call you — copier, payroll, giving platform, insurance, IT, alarm — with the phone number from your contract or a bill you’ve paid, not from the internet. Verification only works if the real number takes ten seconds to find. Update it when contracts change, and note who your actual account rep is.
Decide what the “sticker information” is worth. Serial numbers, account numbers, staff direct lines, which software you use — none of it is secret, exactly, but each piece makes the next pretext more convincing. The attacker who knows your copier model and your administrator’s first name sounds like Marcus. Trim what’s published where you can, and treat unsolicited requests for those details as the reconnaissance they are.
Rehearse the two-question test. Before acting on any unsolicited contact, staff ask: Did I have a way to expect this? and Am I being given a reason not to verify? A real vendor’s real update survives a callback tomorrow. Only the fake one needs it done on this call, today, before lunch.
Pretexting is patient, polite, and completely dependent on one thing: the target acting inside the story the attacker built. A callback steps outside the story. Nothing inside it survives that.
MissionDefend’s free assessment includes the unglamorous controls that stop pretexting — callback rules, vendor verification, front-desk procedure — and shows you which ones your organization is missing. Get on the launch list.
Sources: Federal Trade Commission, FTC Announces Impersonation Rule Goes into Effect Today (April 1, 2024); Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

