It is 4:15 on a Thursday when the bookkeeper realizes something is wrong. That morning she got a notification about a sign-in to the church email account from a city none of you have visited, and now, in the mailbox settings, there is a forwarding rule she did not create.
By 5:30 the person who helps you with computers has confirmed it: someone else has been in that mailbox for at least eleven days. It holds the counting team’s spreadsheets, scanned checks, the pastoral care list, and four years of correspondence.
The pastor asks the question every leader asks at this moment, and it is the right one:
What do we tell people?
The answer that feels safest — wait until we understand it fully, then send something carefully worded — is almost always the wrong one. Not because the caution is unreasonable, but because of how congregations actually respond to bad news.
People forgive the incident. They do not forgive the silence
Congregations are generally forgiving about the incident itself. They understand that a church has two staff and a volunteer treasurer, that email accounts get compromised at corporations with security teams, that nobody was careless in a way that deserves punishment. Most members have clicked something they shouldn’t have.
What they don’t forgive is finding out late, finding out from somewhere else, or reading a message obviously written to limit liability rather than to inform. A member who learns three weeks later that their giving records were exposed doesn’t think these things happen. They think they knew and didn’t tell me, and that attaches to the leadership permanently.
The reputational damage from a slow, defensive, lawyer-flavored message is usually larger than the damage from the incident itself. The incident is a thing that happened to you. The silence is a thing you chose.
What you must know before you speak, and what you can say anyway
Twelve hours in, you will not know much. Not which records were accessed, not whether anything was downloaded, not whether member data will be misused. Those answers can take weeks.
Here is the reframe that unlocks the whole problem. There are three things you can almost always say honestly within hours, and they are the three things people actually want:
What happened, in the plainest terms. Not the technical mechanism — someone gained access to one of our email accounts is enough.
What you are doing about it. You locked the account, brought in help, and are reviewing what was in there. All true within the first afternoon.
What you want them to do. This is the part people scan for, and the part most notices bury.
You don’t need the full scope to say those three things. What you should have before you speak is confirmation from someone competent that an incident occurred and that the immediate hole is closed. Announcing a breach that turns out to be a misconfigured setting is its own kind of damage.
One constraint worth knowing. All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring notification when certain kinds of personal information are exposed — and what counts as personal information, what triggers the duty, how long you have, what the letter must say, and whether a state attorney general has to be told all differ materially from state to state. There is no single national deadline or rule. Ask your attorney what applies to you before the formal notice goes out. Nothing here is legal advice.
Hours, then days: two different messages
Separate the two communications in your mind and the timing problem largely dissolves.
The holding statement goes out within about 24 hours: what happened, what you’re doing, what to watch for, and when they’ll hear from you next. Its job is to make sure nobody learns this from a rumor. The full notice goes out in days, once you know the scope — specific about what was and wasn’t affected, carrying any formal notification your attorney says is required.
A holding statement you can adapt:
Subject: An important notice from [Church Name] Dear friends, I’m writing about something that happened here this week, and I want you to hear it from us rather than anywhere else. On Thursday we discovered that an unauthorized person had access to one of our church email accounts. We have locked that account, changed the passwords, and brought in outside help to determine exactly what was accessed and when. We do not yet know the full extent of what was in that mailbox or whether any of it was taken. That review is underway, and I would rather tell you what we know today than wait until we know everything. What we’re asking you to do. Please be cautious about any message that appears to come from the church over the next several weeks — anything asking you to give, click a link, update payment details, or send money or gift cards. The church will never contact you asking for payment, gift cards, banking details, or a password. If you receive something like that, call the office at [number] before you act on it. We will not be offended by the call. This happens to organizations far larger than ours, and what matters now is how we respond. I will write again by [specific date] with what we’ve found. If you have questions before then, call me directly at [number]. [Name] [Role], [Church Name]
Notice what it doesn’t do: speculate, promise nothing was taken, or apologize in a way that assigns fault to a person. And it sets a specific date for the next message — the easiest way to buy time honestly.
The follow-up, several days later:
Subject: Update on the email incident at [Church Name] Dear friends, On [date] I wrote about unauthorized access to one of our church email accounts. Here is what we now know. The account was accessed between [date] and [date]. The mailbox contained [describe plainly: correspondence, some giving records, and documents containing member names and addresses]. We have [no evidence that / evidence that] this information was copied or misused. If your information was affected, you are receiving a separate letter with specific steps, including [credit monitoring / what to watch for]. If you did not receive that letter, our review indicates your information was not in the affected account. What we have changed. Every church account now requires a second step to log in beyond the password, so a stolen password alone is no longer enough. We have reviewed every account for unauthorized forwarding rules, and our board adopted a written security policy on [date]. What we’re still asking of you. Keep treating unexpected messages about the church with suspicion — anything about giving, payments, or account details, and especially anything referring to this incident. Call the office to check. We would much rather field the call. We have reported this to [law enforcement / the appropriate authorities] and are following the notification requirements that apply to us. I’m grateful for the grace you’ve shown this week. If you’d like to talk, my number is [number]. [Name]
Who speaks, and how it reaches the people least likely to read email
Decide the voice before you need it. It should be the senior pastor or the board chair — one person, named, with a real phone number in the message. An unsigned notice from “the church office” reads as institutional distancing at exactly the wrong moment.
Then use every channel, because they reach different people:
Email, to everyone you have an address for. Fastest, and the record of what you said.
The website. A short dated notice on the front page. This is where members send their adult children, and where anyone who hears a rumor will check.
From the front, on Sunday. Two minutes, in plain language, not buried in announcements. Members who hear their pastor say it out loud experience it entirely differently than members who read it, and it visibly signals that the leadership is not hiding. Put a printed copy in the bulletin too.
A phone tree. The one that gets skipped, and the one that matters most.
Here is the uncomfortable arithmetic. The members most likely to be targeted by follow-on scams are your older members — the FBI logged 201,266 complaints from victims aged 60 and over in 2025, a 37% increase over 2024, and $7.748 billion in losses, which was up 59% in a single year. The members least likely to read an emailed notice are very often the same people. A written notice reaches the people who need it least.
So build a short list of members who don’t use email reliably, split it among your deacons, elders, or care team, and call them. The script is three sentences: Something happened with the church’s email. Nobody needs to do anything. But if anyone contacts you claiming to be from the church and asks for money or account details, hang up and call the office.
Twenty people making six calls each covers a congregation in an evening.
The instruction that stops them being victimized twice
Attackers who have been inside a mailbox for eleven days know your members’ names, your pastor’s writing style, your giving cycle, and the fact that you just announced a breach. The second wave is often more profitable than the first: a message that references the incident, expresses concern, and asks the member to “verify” something.
So give the instruction in a form people can remember under pressure:
The church will never contact you asking for money, gift cards, banking details, passwords, or account verification — by email, text, or phone. If anyone does, it isn’t us. Hang up or delete it, and call the office on the number in the bulletin.
Put that sentence in the holding statement, the follow-up, the bulletin, and the phone script, and repeat it in the newsletter a month later. It’s permanent congregational hygiene that happens to be most urgent right now.
What not to do
Don’t minimize. “A minor issue with one of our systems” is the phrase that gets quoted back to you when the scope turns out to be larger. Describe it accurately, or as still under review — never smaller than it is.
Don’t name the staff member. Not in the notice, not from the pulpit, not in conversation. That person is already carrying it, and naming them tells everyone else in your organization that reporting a mistake gets you publicly identified — precisely the behavior you cannot afford. If your board asks who, the answer is: a member of our team was targeted by a convincing message, and they reported it quickly, which is what limited this.
Don’t promise it can never happen again. You can’t deliver it, and it’s what people remember if there’s a second incident. Say what you have changed instead — stronger, and true.
Don’t go quiet because of legal advice. Counsel should review the wording of anything you send — that is what counsel is for, and formal notification has requirements you should not guess at. But there is a difference between have a lawyer read this before it goes out and say nothing until the lawyer is comfortable, and the second can run for weeks. Bring your attorney in on day one and give them a deadline. Saying nothing is not neutral; it is a choice, and its consequences compound daily.
Don’t let the first Sunday pass in silence. If the congregation is in the building and nobody mentions it, you have communicated something.
What to do this week
You almost certainly are not in an incident right now, which is exactly why this is the week.
Write two things and put them in a shared folder labeled clearly enough that a panicking person can find it: the name and mobile number of whoever will speak publicly if this happens, and a draft holding statement — adapt the one above in fifteen minutes by filling in the brackets.
Then build the phone-tree list: which members don’t use email, and who calls them. On the worst day, that list is the difference between reaching your congregation and merely emailing it.
Forty-five minutes, and the first 24 hours stop being improvised.
The best time to work all of this out is before you need it. MissionDefend’s free assessment asks plain-English questions about how your church handles email, donations, member data, and accounts, then hands back a baseline score and a ranked list of what to fix first.
No spam and no sales calls — just one email when it’s live.
Related reading
- the plan that decides who speaks before anything happens
- the formal notices that follow your first announcement
- responding when the breach happened at your provider
MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.
Sources: Federal Trade Commission, Data Breach Response: A Guide for Business; National Conference of State Legislatures, Security Breach Notification Laws; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.


