Home Articles Get your free assessmentComing soon

Tag: check fraud

  • The Job Opening You Never Posted

    The Job Opening You Never Posted

    The first voicemail comes in on a Monday. A woman named Denise, polite and a little apprehensive, asking when her start date is and whether she should bring anything on the first day. She mentions she already deposited the check.

    Nobody at the church knows who she is.

    By Thursday there have been four more calls, one email with a scanned driver’s license attached, and a message from a man who is no longer polite at all, because his bank has just reversed a $3,200 deposit and told him he owes them the money. He has an offer letter with the church’s logo on it. He has text messages from someone who signed off as the church’s “HR coordinator.” He does not have a job, and the church does not have an HR coordinator.

    No one at the church did anything wrong. No system was broken into. Someone simply took the name of a trusted local institution, put it on a job posting, and let the name do the work.

    The posting you never wrote

    The scam is straightforward. A fraudster creates a job listing on a recruitment site, a community Facebook group, or a job board — “remote personal assistant,” “part-time bookkeeper,” “youth ministry coordinator.” The employer name is a real church. Sometimes the logo is lifted from the church website. Sometimes the posting copies the mission statement word for word, because that language is right there to copy.

    The FBI has warned about exactly this pattern, describing how criminals “spoof legitimate companies to post fraudulent job postings on commonly used employment-oriented networking sites,” directing applicants to spoofed websites, email addresses, and phone numbers that the scammers control.

    What follows is fast, and the speed is deliberate. The applicant is contacted within hours. The interview happens entirely over text message, WhatsApp, Signal, or a chat window — never a video call, never in person, occasionally a brief phone call from a number that never answers again. The applicant is hired, usually within two days.

    Then comes the part that actually makes money.

    The check is the whole point

    The new hire is told the organization will provide equipment — a laptop, a monitor, software for the ministry’s donor database. A check arrives, or an image of one, for more than the equipment costs. Deposit it, buy the equipment from “our approved vendor,” and send the balance on to the vendor by wire, payment app, or gift card.

    The check is counterfeit. The money the applicant sends is real.

    The Federal Trade Commission puts it about as plainly as it can be put: “The check is fake and will bounce, and the bank will want you to repay the full amount of the fake check, while the scammer keeps the real money you sent them.”

    The trap is a piece of banking mechanics almost nobody outside of banking knows. Your bank may make a deposited check’s funds available to you well before it knows whether the check is any good. Seeing the balance in your account is not the same as the check having cleared. When it is finally identified as counterfeit, the deposit is reversed — and the person who deposited it is the one holding the loss.

    That’s why the FTC’s rule for job seekers is absolute: “if you get an offer that includes depositing a check and then using some of the money for any reason, that’s a scam.”

    The quieter version: the onboarding packet

    Not every variant involves a check. In some, the “hire” goes smoothly and the only ask is paperwork — a direct deposit authorization, a tax form, a copy of a driver’s license, a Social Security number “for the background check.”

    That packet is the product. It is enough to open accounts, file a fraudulent tax return, or take out credit in the applicant’s name. The FTC’s guidance on remote job scams describes scammers asking targets to “fill out direct deposit and tax forms with your bank account and other personal information.”

    This version is harder to spot because nothing about it feels like a scam. Onboarding paperwork is exactly what a new job involves. The only thing wrong is that the employer doesn’t exist.

    Why churches and nonprofits get picked

    The name buys instant trust. A job seeker who sees “First Baptist” or “Habitat affiliate” or a hospice’s name on a listing relaxes in a way they would not for an unknown LLC. That trust was built over decades by people doing good work, and it is being spent by someone else.

    The brand is sympathetic. Ministry work attracts applicants who are motivated by more than a paycheck, and who are therefore more inclined to give the organization the benefit of the doubt when something is slightly odd.

    There is no HR department to call and check. This is the structural reason, and it is not a failing — it is what a small organization looks like. At a company with 4,000 employees, a suspicious applicant calls recruiting. At a church with a pastor, an administrator, and a part-time music director, there is no recruiting line to call, and the main number goes to voicemail on Wednesday afternoons.

    Your staff page tells the scammer everything. Names, titles, email format, the pastor’s photo. All of it is public on purpose, because a church website that hides its people would be a strange church website. None of that should change.

    And here is what it costs you, even though no money left your accounts.

    You inherit a stream of confused and increasingly angry people, some of whom are out thousands of dollars they did not have. They are not wrong to be upset, and the first person they reach is whoever answers your phone. That is a hard morning for an office administrator who had no warning.

    Then there is the reputational damage, which is slower and more corrosive. The FBI has noted that job seekers “who are unaware they have been scammed may write negative reviews of the victim company; thus, adversely impacting the company’s ratings.” Some people will never learn the church wasn’t involved. They will simply remember the name attached to the worst financial week of their year.

    What actually closes it

    Publish every real opening in one place, on your own website. One page — /jobs or /employment — that is the single source of truth. If there are no openings, the page should say so in a sentence. This is the whole defense in one move, and it works because it gives every applicant, and every reporter, and every skeptical spouse a place to check. The FBI’s advice to job seekers is precisely this: verify job postings found on networking and third-party sites on the hiring company’s own website.

    Put a short standing notice on that page. Say the things you’d otherwise have to say fifty times on the phone:

    All open positions are listed on this page. We do not conduct interviews only by text or chat. We never send money, checks, or equipment funds to an applicant, and we never ask an applicant to purchase anything on our behalf. If you have been contacted by someone claiming to hire on our behalf and this page does not list the role, it is not us — please contact us at [number].

    The rule to state and never bend: every real opening is listed on our own website, and no legitimate hire of ours ever begins with a check.

    Search for yourself once a quarter. Ten minutes. Put your organization’s name into a job board search, into Facebook, into a plain web search alongside the word “hiring.” The FBI specifically recommends that businesses proactively search for fraudulent postings under their own name. If you find one, report it to the platform — every major job site and social network has a report link on the listing itself — and ask for it to be removed.

    Respond publicly when it happens. A short post on your website and social accounts, and a line in the newsletter. Not defensive, not lengthy. We’ve learned that someone is posting fake job openings using our name. We are not hiring for these roles. Our real openings are always here. If you were contacted, here’s what to do. Silence lets the story be told by people who are furious and misinformed.

    Report it. Send the details to the FBI at ic3.gov, and to the FTC at reportfraud.ftc.gov. Include screenshots of the posting, the account that posted it, and any messages applicants forwarded to you. Encourage the applicants to file their own reports — theirs carry the financial loss, which is what drives a case.

    If you’re the applicant reading this

    Some of you found this page because you searched the church’s name at eleven at night with a bad feeling. Here is the short version.

    You are not gullible. This scam is engineered to feel normal, and it borrows the credibility of an institution that spent years earning it.

    Call the organization at a number you found yourself, on their own website — not one from the offer letter or the messages. Ask whether the role exists. That one call resolves most of these.

    If you already deposited a check and sent money on, call your bank immediately and say the words fake check scam. Speed genuinely matters. Then report it at ic3.gov.

    If you handed over a Social Security number, bank details, or a copy of your ID, go to identitytheft.gov. It is the FTC’s official site, it is free, and it will generate a specific recovery plan for you — freezing credit, disputing accounts, the whole sequence — rather than leaving you to figure it out. The FTC directs job scam victims there for exactly this reason.

    And tell someone in your life today rather than next week. The single thing that turns this from a bad experience into a long one is the silence people keep out of embarrassment.

    What to do this week

    Create or update one page on your website listing every current opening — including a plain sentence when there are none — and add the standing notice above. Then spend ten minutes searching your organization’s name on a job board and on Facebook to see whether anything is already out there.

    That’s about thirty minutes, and it turns a scam you can’t prevent into one you can answer in a single sentence.

    If you want to know what else about your organization is easy for a stranger to borrow, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — including the public-facing gaps like this one that most security checklists skip entirely.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Scammers Exploit Security Weaknesses on Job Recruitment Websites to Impersonate Legitimate Businesses; Federal Trade Commission, Job Scams; Federal Trade Commission, Searching for a job to work remotely? Avoid scams and identity theft.