Home Articles Get your free assessmentComing soon

Tag: benevolence

  • The Most Sensitive File in the Building

    The Most Sensitive File in the Building

    A pastor sits down after a Thursday afternoon conversation and writes half a page of notes. A marriage in trouble. A relapse. A name and a date and enough detail to remember what to follow up on next month.

    The notes go into a Word document on the office laptop, in a folder called Care. The laptop is the one the whole staff borrows when theirs is charging. The folder syncs to the shared drive, because everything on that laptop syncs to the shared drive — that’s how it was set up years ago, and it was set up that way so nothing would ever be lost.

    Every person on staff can open that folder. Not one of them ever has. That isn’t a security control; it’s good manners.

    Elsewhere in the same building: benevolence applications with bank details and eviction notices in a cabinet that doesn’t lock, a text thread on a personal phone that contains a full disclosure of abuse, and a notes field in the church management software where somebody typed “husband’s drinking again — do not mention to the Wilsons” three years ago, not realizing that eleven volunteers can see it.

    This is the most sensitive information any church holds, and it is almost always the least protected.

    Confidentiality and security are two different things

    This distinction is worth slowing down for, because the two are constantly confused.

    Clergy confidentiality — often discussed alongside the clergy-penitent privilege, a legal rule about what a minister can be compelled to testify to in court — is a legal and ethical concept. It’s about who may lawfully demand the information, and what a minister is obliged to do with it. Its scope varies significantly by state, and denominations layer their own ordination vows and disciplinary standards on top. Some states affirm the privilege broadly, some limit it to confessional communications, and the Children’s Bureau’s fifty-state summary notes that in some states it is denied altogether.

    Data security is about who can physically or technically reach the file. Passwords, permissions, locks, encryption.

    Here is the load-bearing sentence: a note that is privileged in principle is still readable by anyone with the password. Privilege governs a courtroom. It does nothing whatsoever against a compromised email account, a laptop left in a car, or a volunteer clicking into a folder they shouldn’t have been able to open.

    A related confusion is worth clearing up. Churches often assume health-privacy law covers them. Generally it does not — the federal rule applies to health plans, health care clearinghouses, and health care providers who transmit certain information electronically in connection with standard transactions. A congregation offering pastoral care isn’t ordinarily any of those. There may be exceptions if your ministry operates a counseling center, employs licensed clinicians, or bills insurance, and that’s a question for your attorney. But do not assume a federal law is protecting these records. Usually nothing is except your own practices.

    And one thing that overrides all of it: mandatory reporting obligations exist, they vary, and in defined circumstances they take precedence over confidentiality. According to the Children’s Bureau’s summary of state statutes, members of the clergy are named as mandated reporters in 29 states and Guam, and seven jurisdictions — New Hampshire, North Carolina, Oklahoma, Rhode Island, Texas, West Virginia, and Guam — disallow the clergy-penitent privilege as grounds for failing to report suspected child abuse or neglect. Four states — Indiana, New Jersey, North Carolina, and Wyoming — require all persons to report regardless of profession. That summary is current through May 2023 and these laws change. Know your own state’s rule cold, in writing, before you need it. Ask a lawyer. This article is not legal advice.

    Decide what gets written down at all

    The most effective control here isn’t technical. It’s editorial.

    Before you write anything, ask: what do I actually need to remember, and what would harm this person if it were read by someone else? Those two answers overlap far less than people assume.

    A workable standard for care notes in a congregational setting:

    Write enough to follow up. Date, who you met with, that a conversation happened, and what you committed to do. “Met with R. Follow up in two weeks. Referred to counseling resource list.”

    Leave out the detail that isn’t yours to hold. The specifics of a disclosure, third parties’ names, diagnoses, financial particulars, anything about someone’s spouse or children who were not in the room. If you don’t need it to be a good pastor next month, it doesn’t need to exist on paper.

    Never write speculation, judgment, or diagnosis. Not because someone might sue, though they might, but because you’re recording a guess about a human being that will outlive your memory of how uncertain you were.

    Assume it will be read. By a successor, by a board in a conflict, by a court under subpoena, by an attacker in a breach. Write the note that you would be content to have read aloud.

    This is not an argument for keeping no records. Continuity of care matters, and a pastor who remembers nothing serves people badly. It’s an argument for writing the minimum that does the job.

    Where these files should actually live

    Out of the general shared drive. This is the single highest-value change most churches can make in an afternoon. The default setup at a small organization is one shared drive, open to all staff, because that was simplest to configure. Care notes and benevolence files need to come out of it into a separate location with its own permissions.

    Access granted to named people, not to “staff.” There is a real difference between a folder shared with the staff group and a folder shared with Pastor Miller and Pastor Ruiz. The first automatically includes every future hire, every intern, and the office volunteer who was added to the group last spring. The second doesn’t. Name the individuals.

    Paper goes in a locking cabinet, and the key is controlled. Benevolence applications in particular — they routinely contain bank account numbers, Social Security numbers, pay stubs, and eviction notices, which is a more complete identity-theft package than most churches hold anywhere else.

    Set a retention limit and honor it. Decide how long care notes and benevolence files are kept, write it down, and destroy them on schedule. Records you no longer hold cannot be exposed, subpoenaed, or misread by a successor. What the right period is depends on your state, your denomination’s polity, your insurer, and whether any licensed counseling is involved — ask your attorney for the number, then follow it.

    Multi-factor authentication on the accounts that can reach any of this. MFA is the extra code or tap after the password. It’s free on Microsoft 365 and Google Workspace, and Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. If a folder is worth restricting, the account that can open it is worth protecting.

    Email, texting, and the notes field nobody thinks about

    Email is a filing cabinet you don’t control. A message about a member’s situation is copied into the sender’s sent folder, the recipient’s inbox, both mailboxes’ backups, and the provider’s servers. It stays there for years. If either account is ever compromised — the most common single security incident at any organization — the attacker gets not just the mailbox but the searchable history of everything the church knows about its people.

    If you must send something by email, keep the substance out of the subject line. Subject lines appear in notification previews on lock screens, on shared reception monitors, in mobile summaries, and in any forwarded thread. “Re: Thursday” is a fine subject line. “Re: Dana’s rehab intake” is a broadcast.

    Better: send “Can we talk about a pastoral matter today?” and have the conversation by voice.

    Texting is worse, and it’s what people actually use. A pastoral text thread sits on a personal phone with no organizational control at all. It appears in lock-screen previews. It’s visible to anyone who picks up the phone, including a spouse or a child. It backs up to a personal cloud account. And when that pastor leaves the church, the entire history leaves with them, on their device, permanently. Text to arrange a meeting. Don’t text the meeting.

    The church management software notes field is far more visible than people think. Almost every ChMS — church management software, the system that holds your directory, attendance, and giving — has a general notes or comments field on each person’s record. Staff type sensitive things into it because it’s convenient and it feels private.

    It usually isn’t. Depending on how your permissions are configured, that field may be visible to every staff member, every group leader, every volunteer with a login, and anyone who can run an export. Go look today: log in as a volunteer-level user, or ask one to show you their screen, and see exactly what a group leader can read on a member’s record. Most churches are surprised. Then either lock the field down properly or stop using it for anything but logistics.

    Two situations to plan for now

    When a staff member leaves. This is the moment the whole problem becomes visible. Their church account gets disabled — but the notes in their personal notebook go home in a box. The care history in their text messages leaves on their phone. The documents in their personal Dropbox stay in their personal Dropbox.

    Handle it at the front end rather than the back: make it clear from the first week of employment that ministry records belong to the ministry and live in ministry systems. Then, at departure, walk through it explicitly — accounts disabled, church files returned or transferred to the named successor, personal-device copies deleted, paper handed over. Have the conversation warmly and have it anyway, including when someone leaves on the best possible terms.

    When a device is lost. A laptop in a stolen car, a phone left in an airport. If care notes were on it, the question is whether anyone can read them.

    Two settings make the answer no, and both are free and already built in. Full-disk encryption — BitLocker on Windows, FileVault on Mac — scrambles everything on the drive so it’s unreadable without the login. On phones and tablets it’s on by default as long as you have a passcode. And remote wipe, which lets an administrator erase a device that’s gone. Turn both on across every device that touches ministry records, today, before you need them.

    If a device is lost, change the passwords for every account that was signed in on it, sign out all active sessions, and tell someone immediately. If information about people was exposed, notification requirements exist in every state and vary considerably — that’s a call to your attorney, promptly.

    What to do this week

    Open your shared drive and look at who can see the folder containing care notes, benevolence applications, or anything similar. If the answer is “everyone on staff,” move that folder somewhere with permissions granted to two or three named people. Fifteen minutes.

    Then log in to your church management software as a volunteer-level user and read what they can see on a member’s record. If the notes field is exposed, you’ve just found this week’s second job.

    MissionDefend’s free assessment asks straightforward questions about how your organization handles member data, accounts, email, and donations — no jargon — and returns a baseline score with the highest-value fixes ranked in order.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: U.S. Department of Health and Human Services, Children’s Bureau, Mandatory Reporting of Child Abuse and Neglect: State Statutes; U.S. Department of Health and Human Services, Covered Entities and Business Associates; Microsoft, mandatory multifactor authentication guidance; National Conference of State Legislatures, Security Breach Notification Laws.

  • The Check Cleared. Two Weeks Later It Didn’t.

    The Check Cleared. Two Weeks Later It Didn’t.

    A woman calls about renting the fellowship hall for her niece’s wedding reception in October. She’s pleasant, organized, and slightly apologetic about being out of state. She asks good questions about parking.

    The rental fee is $600. The check arrives four days later, made out to the church, for $3,850.

    She’s mortified when she calls. Her event coordinator handles the deposits for the caterer and the rental company and put the whole thing on one check by mistake. Would the church mind depositing it and sending the difference — $3,250 — on to the coordinator? She’ll text the details. The wedding is in nine weeks and the caterer wants the deposit by Friday.

    The treasurer deposits the check on Monday. It clears. On Wednesday, she wires $3,250 to the coordinator.

    Seventeen days later the bank calls. The check was counterfeit. The $3,850 is being pulled back out of the church’s account, and the $3,250 is gone.

    The one thing to understand about checks

    Everything in this article follows from a single fact that almost nobody has been told plainly:

    A check clearing does not mean the check is good.

    Those feel like the same sentence. They are not.

    When you deposit a check, federal law requires your bank to make the money available to you quickly — generally within a day or two for most deposits. That’s a consumer-protection rule, and it exists for good reasons: people shouldn’t wait two weeks to spend their own paycheck. The Office of the Comptroller of the Currency puts it directly: “funds may become available to you before the bank has been able to verify the check.”

    Verification is a separate, slower process. The check has to travel back through the system to the bank it was drawn on, and that bank decides whether it’s real. Forgeries, counterfeits, and checks drawn on closed accounts can be discovered weeks after the money appeared in your account. The FTC’s summary: “Fake checks can take weeks to be discovered and untangled.”

    When the forgery surfaces, the money comes back out of your account. Not the scammer’s — yours. The FTC again: “the scammer has any money you sent, and you’re stuck paying the money back to the bank.”

    Cashier’s checks are not an exception, despite their reputation. The OCC states it explicitly, answering that exact question: “If the check is fraudulent, the bank may charge it back against your account (in other words, deduct the funds from your account) or obtain a refund from you.”

    So when your treasurer says “it cleared,” what she means is “the bank has let us spend it.” She has not learned anything at all about whether it’s real. That gap — days of apparent certainty followed by weeks of actual risk — is the entire attack surface.

    The rental deposit that’s too big

    The scene above is the most common church-shaped version, and it comes in several outfits.

    A wedding reception. A family reunion. A conference that needs the sanctuary for a Saturday. A film production wanting the building for two days. A group renting the gym for a season. What they share: an out-of-state contact, unusual smoothness about the price, and an overpayment with a reason attached.

    The reason is always reasonable. An accounting error. A combined payment. A deposit from a third party who paid the wrong amount. Sometimes the overpayment is explained before the check arrives, which makes it feel disclosed rather than suspicious.

    And the ask is always the same shape: deposit this, then send part of it somewhere else, soon.

    That structure is the tell, independent of everything else. The money coming in is fake and slow to be discovered. The money going out is real and fast. The scam is nothing but the difference between those two speeds.

    The benevolence applicant who needs it passed along

    The version aimed at your compassion rather than your calendar.

    Someone approaches the benevolence fund. Their story involves a check they’ve received but can’t cash — no bank account, an account frozen, a check made out to a name their bank won’t accept, a settlement or back-pay check from an employer. Could the church deposit it and give them the cash, or wire part of it to a landlord, a bus company, a relative, a hospital?

    Sometimes there’s a variation in which the applicant has already been “helped” by someone else who sent them a check, and just needs the church to convert it.

    Everything about the request is calibrated to make a policy feel cruel. The person is in genuine-sounding distress, the amount is modest, and refusing seems to punish someone for not having a bank account — which is a real hardship affecting real people.

    But a church is not a check-cashing service, and there is no version of this that is safe. Not because the person in front of you is necessarily lying — occasionally they are also a victim, passed a fake check by someone else — but because the church absorbs the entire loss either way.

    The compassionate answer is not “no.” It’s: we don’t cash or deposit checks for anyone, but let’s talk about what you actually need and what we can pay directly. Paying a landlord or a utility directly, from your account to theirs, helps the person more than cash does and cannot be used against you.

    The donation with a request attached

    The third version wears the most flattering costume.

    A generous, unsolicited donation arrives from someone with no history with your organization — a large check, sometimes with a warm letter about your mission. Then a follow-up: the donor intended part of it for a partner ministry, a missionary, a scholarship recipient, a family they support, and would the church please forward that portion along?

    Or: they’ve changed their mind about the amount and would like a partial refund.

    Or, in the version that arrives with a fabricated story: a donor’s estate is disbursing funds and the church has been named, with a handling fee or a portion to be forwarded to another beneficiary.

    Same structure, dressed in gratitude. Money in, part of it out, and a reason to hurry.

    A genuine donor who wanted a partner ministry to receive money would send that money to the partner ministry.

    The three rules that close all of it

    You don’t need to evaluate stories. You need three rules that don’t require anyone to be a good judge of character.

    One: never refund, forward, or disburse any portion of a payment until the originating bank confirms the check is good, in writing. Not “the funds are available.” Not “it cleared.” Written confirmation that the check is legitimate and final. Your bank can tell you how to request it, and how long it takes for that specific check. If a payer objects to waiting for that, you have your answer.

    Give your staff the sentence so nobody has to invent it under pressure:

    “Our policy is that we don’t return any part of an overpayment until our bank confirms the original check is final. That usually takes a few weeks. The simplest fix is to void this one and send a new check for the correct amount — happy to do that today.”

    That offer is the perfect filter. A real customer is relieved. A fraudster will not accept it, because the correct amount is not the point.

    Two: impose a mandatory waiting period on outgoing money that depends on incoming money. Thirty days is a reasonable default, and worth writing into your facility rental agreement so it’s disclosed up front rather than negotiated in the moment: overpayments are refunded thirty days after the funds are received. Legitimate renters do not care. The scam has a shelf life measured in days and cannot survive the wait.

    Three: one person approves outgoing money, and it isn’t the person who took the call. Separating the relationship from the authorization is the oldest control in accounting and still the best. The person feeling the social pressure — the sympathy, the deadline, the mortified bride’s aunt — is not the person who signs. It is remarkably easy to say no to a request you did not personally receive.

    Two smaller habits worth adding. Only accept checks made out to the organization, never to an individual on staff. And look at the check itself — a business check with no perforated edge, a mismatch between the bank named on the check and the routing information, a check drawn on a bank in a state unrelated to everyone involved, or an amount that seems oddly specific are all worth a second look. None of these are proof, and a good forgery passes all of them, which is why the rules above don’t depend on inspection.

    If it already happened

    Call your bank first, today. If the outgoing payment hasn’t settled, it may be stoppable. This is genuinely a matter of hours.

    Report it to the FBI at ic3.gov, and use the phrase fake check scam along with the method the money left by. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic incidents in 2025, and that process works far better inside the first 24 to 72 hours than after.

    Report it to the FTC and to your state attorney general’s office, which is how patterns become cases.

    Then tell your board promptly and without spin. The instinct to quietly absorb a loss and mention it at the next quarterly meeting is understandable and always wrong. A treasurer who reports it the same day is doing the job correctly; the delay is what turns a loss into a governance problem.

    And be clear inside the organization about who was at fault: the person who deposited the check followed a completely ordinary procedure and was told by their own bank that the money was there. That’s not carelessness. It’s a gap in how the banking system communicates, which is exactly why it needs a rule rather than better judgment.

    What to do this week

    Write one sentence and give it to whoever handles deposits and rentals:

    We never send money back out of an overpayment, a donation, or a benevolence check until our bank confirms the original check is final — and refunds go out thirty days after the funds arrive, not before.

    Then check two things. Does your facility rental agreement state the refund timing? If not, add the sentence. And is there one named person who approves outgoing payments over some threshold — $500, $1,000, whatever fits your size — who is not the person taking the booking? If not, name them at the next board meeting.

    Thirty minutes, no budget, and this entire family of scams stops working on you.

    Money controls are only one part of the picture. MissionDefend’s free assessment asks plain-English questions about how your organization handles money, email, member data, and accounts — including who can send funds out and under what conditions — then returns a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, How To Spot, Avoid, and Report Fake Check Scams; Office of the Comptroller of the Currency, Aren’t cashier’s checks supposed to be honored immediately?; Office of the Comptroller of the Currency, Bank Accounts: Funds Availability; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • After the Storm: Disaster-Relief Giving Fraud Runs Both Ways

    After the Storm: Disaster-Relief Giving Fraud Runs Both Ways

    The storm came through on a Thursday night. By Friday morning the church has already decided to help — that’s not a decision that takes a meeting, and it shouldn’t be.

    By Friday afternoon two things are in motion.

    A message is circulating among your members with your church’s name on it, asking for donations to the relief effort, with a link. Nobody at the church wrote it.

    And in the office, an email has arrived from a coalition of regional relief organizations mobilizing in the affected county. They need commitments today; trucks leave in the morning. The letterhead is good, the tone is right, and there’s a wire transfer instruction at the bottom. The benevolence fund has $8,000 in it, and the pastor is inclined to send $5,000.

    Disaster fraud runs in both directions at once, and most guidance only covers one of them.

    Direction one: someone raises money in your name

    Disasters generate two things attackers want: an obvious reason to ask for money, and a population that has already decided to give.

    Your church supplies the third ingredient — a name people trust. So a page appears, or a Facebook post, or a text message chain among your members, with your church’s name and often your logo on it. The money goes somewhere else.

    The specific mechanics of cloned pages and lookalike names deserve their own treatment, and we’ve covered them separately. What matters here is the timing. A disaster compresses the window in which your members will believe an unusual appeal. In an ordinary week, a message asking for an immediate wire to a new account would strike your congregation as odd. In the week after a hurricane, it strikes them as exactly what a church would be doing.

    The defense is to occupy the space first. Within twenty-four hours of any disaster your church responds to, publish — bulletin, email, website, social — a short statement that says exactly how you are collecting, and exactly how you are not:

    We are receiving relief donations through [your normal giving page and address] only. We will not ask you for gift cards, wire transfers, or cryptocurrency, and we will not send anyone to your door. If you see an appeal using our name anywhere else, please tell the office before you give.

    Send it before you need it. The point is not to warn about a specific fake; it’s to establish what normal looks like while your members are still calm enough to read carefully.

    Direction two: your money goes out the door

    This is the direction churches don’t see coming, because it doesn’t feel like fraud. It feels like generosity under time pressure.

    The pattern is consistent. A relief organization contacts you — by email, sometimes by phone, sometimes through a name-drop from someone in your network. It has a real-sounding name, often one syllable away from an organization you’ve actually heard of. There is a deadline: trucks, a matching gift that expires, a shelter opening Monday. The ask is a wire transfer, a cashier’s check by overnight mail, or increasingly a payment through an app to a person who “coordinates” for them.

    Sometimes there’s no organization at all. Sometimes there’s a real disaster and a real need and a fake middleman. Occasionally the request arrives from a compromised mailbox belonging to someone you genuinely know, which is why it survives the sniff test.

    The variant aimed squarely at churches: an individual applies to the benevolence fund and needs help urgently because of the disaster — a relative stranded, a deposit on temporary housing, a vehicle repair to get to the affected area. The money needs to go to a third party, right now, by a method that can’t be reversed.

    Urgency is not a detail of these attacks. It is the entire mechanism. Every element of the pitch exists to remove the interval in which somebody would have checked. Take that interval back and almost nothing else matters.

    Why churches are especially exposed here

    Not negligence. Structure.

    Speed is a virtue in your world. A church that takes eleven days to approve disaster relief has failed at something real. Your instincts are correctly tuned for compassion, and fraud is designed to ride those instincts, not defeat them.

    Benevolence funds are built to move fast. They often have looser approval than the operating budget by design — that’s the point of having one. That same design means a single person can frequently authorize a payment without a second signature.

    The approver is often one person. A pastor or an administrator who will not want to say “let me check” to someone describing a family sleeping in a car.

    Ministry networks are informal. Partnerships form through relationships, conferences, and word of mouth, so an unfamiliar organization introducing itself is not unusual. In the corporate world, an unknown vendor asking for a wire is a red flag on its own. In yours, it’s Tuesday.

    Vetting an organization, and choosing how the money leaves

    You don’t need a due-diligence department. You need four checks, and together they take about as long as a coffee break.

    Confirm it exists as a tax-exempt organization. The IRS Tax Exempt Organization Search tool lets you check “an organization’s eligibility to receive tax-deductible charitable contributions.” Search the exact legal name. If nothing comes up, that alone isn’t proof of fraud — small groups and churches are treated differently — but it means you need a different reason to believe in them.

    Check state charity registration. Most states require organizations soliciting donations to register. Your state’s charity office, usually within the Attorney General’s or Secretary of State’s office, can confirm it. The National Association of State Charity Officials maintains a directory of all of them.

    Look them up at a standards-based evaluator. BBB Wise Giving Alliance publishes free reports at give.org against twenty accountability standards covering governance, finances, and truthful representation. The FTC points people to it and to Charity Watch for exactly this purpose.

    Search the name plus a hostile word. The FTC’s own advice: search the organization’s name along with “complaint,” “review,” “rating,” “fraud,” or “scam.” And the FTC’s blunt rule of thumb — “if you can’t find detailed information about a charity’s mission and programs, be suspicious.”

    If an organization is real and the need is real, none of this offends anyone. Legitimate relief organizations are asked to prove themselves constantly and have the answers ready.

    Then decide how you’ll send it, because that matters as much as who receives it. Some payment methods can be stopped or reversed. Some cannot. Fraudsters know exactly which is which, and they will steer you toward the second group while telling you it’s about speed.

    Never send by gift card, wire transfer, cryptocurrency, or cash on a first contact. The FTC states it plainly: “Don’t donate to anyone who insists you must pay by cash, gift card, wiring money, or cryptocurrency.” A relief organization does not need gift cards. Nobody’s supply truck runs on iTunes credit.

    Use a method with a paper trail and some recourse — a check to the organization’s legal name, or a credit card. Both give you something to point at later.

    And apply the money rule you already use for vendors. Any change to payment details — and any new payment instruction from a partner you already have — is verified by voice, on a phone number you already had, before the money goes out. Not the number in the email. The disaster version of that rule is one sentence longer: a new organization you’ve never paid before does not get a wire on its first contact, no matter what the deadline is.

    Route disaster giving through relationships you already have

    This is the single highest-leverage decision, and you can make it before any disaster happens.

    Most churches and nonprofits already have partners: a denominational relief arm, a regional association, a food bank, a long-standing mission partner, a local ministerial alliance. These organizations are typically on the ground faster than any stranger who emails you, and you can verify them once and reuse that verification for the next twenty years.

    Write it down as policy, in one sentence:

    Disaster giving goes to organizations we already have a relationship with. Anything else requires two people to approve and a twenty-four-hour wait.

    That policy costs you almost nothing in real responsiveness — a day, at most, on a giving decision, and your existing partners are unaffected. It costs a fraudster everything, because the pitch depends entirely on being answered inside the hour.

    The same shape works for benevolence: any benevolence payment to a third party rather than to the applicant, or by any irreversible method, waits until tomorrow and is approved by two people. Applicants with genuine need are not harmed by a day. The scripts fall apart.

    If it already happened

    Move within hours, not days.

    Call your bank immediately and ask about a recall. Wires and ACH transfers have narrow windows, but they exist, and the window closes fast.

    Report it to the FBI at ic3.gov the same day. Include the account details, the amount, and the timeline. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic incidents in 2025, and that process depends almost entirely on speed — it works dramatically better inside the first 24 to 72 hours.

    Report it to your state charity regulator and the FTC, which is how patterns get built into cases.

    Then tell your congregation what happened, if their gifts were involved. Plainly, without drama. Organizations that get quiet after being defrauded do more damage to their own credibility than the fraud did.

    What to do this week

    Write the two policy sentences down — disaster giving goes to existing partners; anything else waits twenty-four hours and needs two approvals — and email them to everyone who can authorize a payment. Ten minutes.

    Then draft the congregation notice now, while nothing is happening. Save it where you can find it. Fill in your real giving address, state that you’ll never ask for gift cards or wires, and leave it ready to send the same day something happens near you. Twenty minutes today, and it goes out inside an hour when it matters.

    MissionDefend’s free assessment walks through how your organization handles email, donations, member data, and accounts in plain English — including who can move money and how fast — and gives you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Before Giving to a Charity; Federal Trade Commission, After a disaster, make your donations count; Internal Revenue Service, Tax Exempt Organization Search; BBB Wise Giving Alliance, give.org; National Association of State Charity Officials, State Government directory; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.