Home Articles Get your free assessmentComing soon

Tag: donation fraud

  • QR Codes in the Bulletin: The Giving Scam Nobody Sees Coming

    QR Codes in the Bulletin: The Giving Scam Nobody Sees Coming

    The giving QR code is on the back of the bulletin, on the screen during announcements, on the laminated card in each pew rack, and on the poster by the door — because it works. Point a phone at the square, the giving page opens, and the awkwardness of passing a plate past a visitor is gone.

    Now consider what that square actually is. A QR code — the name stands for quick response — is a web address printed as a pattern a camera can read. That’s all. And its defining feature is the problem: a human being cannot read it. You can proofread every word of the bulletin, but you cannot proofread the code. A square that sends the congregation to your giving platform and a square that sends them to a scammer’s copy of it look identical from across the room, and nearly identical from six inches.

    The FBI warned about exactly this in a public service announcement back in January 2022: criminals “tamper with both digital and physical QR codes,” swapping legitimate ones for their own to steal credentials and payments. The FTC followed in December 2023 with the consumer version, describing the physical trick already common on parking meters — a scam sticker printed and stuck over the real code.

    A parking meter and a pew card have a lot in common. Both sit unattended in a public place. Both are trusted by the person scanning. And both are asking for money.

    The two directions the swap happens

    On paper, with a sticker. Someone prints their own code on adhesive labels — a task that takes ten minutes and costs nothing — and applies them to the lobby poster, the pew cards, the yard sign for the capital campaign. The fake destination is a page that looks like your giving platform: same logo, lifted from your website; same colors; a form that takes card numbers. Sunday’s gifts flow to an account you’ve never heard of, and the failure is invisible until someone asks why online giving dipped.

    Upstream, in the file. The subtler version never touches your building. It compromises the source of the code: the shared Canva account a volunteer uses for slides, the email thread where the bulletin file gets passed around, the church email account of whoever assembles it. Change the code in the master file once, and the church then prints, projects and distributes the fraud itself, every week, with its own hands.

    And to complete the picture: this scam also arrives at the church from outside — unsolicited packages with “scan to see who sent you this gift” cards, which we covered in the brushing scam. Same square, opposite direction. Today’s post is about the codes you publish.

    Why nobody notices

    Nobody checks the destination. On a phone, the preview that appears when you scan shows a URL for a moment — but giving platforms have long, forgettable addresses full of subdomains ( `yourchurch.givingvendor.com`, `app.vendor.com/give/12345` ), so the congregation has no memory of what the right address looks like. The FTC’s advice — inspect the URL for misspellings before opening — assumes you know what correct is. Most givers don’t.

    That’s not a reason to abandon the codes. It’s the design constraint: the safeguards have to live with the people who publish the code, because the people who scan it can’t be expected to catch anything.

    What to do this week

    Put the giving address into human memory. Pick the shortest true form of your giving URL and print it next to every code, every time: “Scan, or visit yourchurch.org/give.” That one habit does three jobs: givers who prefer typing never scan at all; anyone who scans can compare what opened against what’s printed; and a swapped sticker now has to fake two things that must agree. A code with no readable address beside it is asking the congregation to trust ink they can’t read.

    Make one person the owner of the square. Not a committee — a name. That person generates the code (directly from the giving platform, not from free third-party QR generator sites, which can route through tracking domains you don’t control), keeps the master graphic in one place, and is the only source others copy from. Every “just grab the code from last month’s file” is a link in a chain nobody is watching.

    Add the codes to a monthly walk-through. First Sunday of the month, someone scans every published code in the building — pew cards, posters, yard signs, the slide deck — on their own phone and confirms each lands on the real page. It takes five minutes. While they’re at it: run a fingernail over printed codes. A sticker over ink has an edge you can feel. That’s the FBI’s tampering warning turned into a chore anyone can do.

    Watch the money like a control, not a report. Whoever reconciles giving should treat an unexplained dip in online gifts as a security signal worth a same-week look, not a trend to discuss at the quarterly meeting. In the sticker version of this scam, the finance spreadsheet is the only alarm that ever goes off.

    Tell givers the one rule that survives everything. In the bulletin, once a season: our giving page is yourchurch.org/give — if a code ever takes you anywhere else, close it and tell the office. You’re not teaching the congregation to distrust the plate. You’re giving them the same gift every post in this series comes down to: a known-good channel to fall back on.

    The QR code turned your congregation’s generosity into a single point of failure. It can stay — it should stay — but it graduates from decoration to infrastructure. Infrastructure gets an owner, a checklist, and an alarm.

    The MissionDefend assessment asks who owns your giving links, who can edit what gets printed, and whether anyone would notice a swap — along with the rest of your baseline. Join the launch list.


    Sources: FBI Internet Crime Complaint Center, Cybercriminals Tampering with QR Codes to Steal Victim Funds, Alert I-011822-PSA (January 18, 2022); Federal Trade Commission, Scammers hide harmful links in QR codes to steal your information (December 6, 2023).

  • After the Storm: Disaster-Relief Giving Fraud Runs Both Ways

    After the Storm: Disaster-Relief Giving Fraud Runs Both Ways

    The storm came through on a Thursday night. By Friday morning the church has already decided to help — that’s not a decision that takes a meeting, and it shouldn’t be.

    By Friday afternoon two things are in motion.

    A message is circulating among your members with your church’s name on it, asking for donations to the relief effort, with a link. Nobody at the church wrote it.

    And in the office, an email has arrived from a coalition of regional relief organizations mobilizing in the affected county. They need commitments today; trucks leave in the morning. The letterhead is good, the tone is right, and there’s a wire transfer instruction at the bottom. The benevolence fund has $8,000 in it, and the pastor is inclined to send $5,000.

    Disaster fraud runs in both directions at once, and most guidance only covers one of them.

    Direction one: someone raises money in your name

    Disasters generate two things attackers want: an obvious reason to ask for money, and a population that has already decided to give.

    Your church supplies the third ingredient — a name people trust. So a page appears, or a Facebook post, or a text message chain among your members, with your church’s name and often your logo on it. The money goes somewhere else.

    The specific mechanics of cloned pages and lookalike names deserve their own treatment, and we’ve covered them separately. What matters here is the timing. A disaster compresses the window in which your members will believe an unusual appeal. In an ordinary week, a message asking for an immediate wire to a new account would strike your congregation as odd. In the week after a hurricane, it strikes them as exactly what a church would be doing.

    The defense is to occupy the space first. Within twenty-four hours of any disaster your church responds to, publish — bulletin, email, website, social — a short statement that says exactly how you are collecting, and exactly how you are not:

    We are receiving relief donations through [your normal giving page and address] only. We will not ask you for gift cards, wire transfers, or cryptocurrency, and we will not send anyone to your door. If you see an appeal using our name anywhere else, please tell the office before you give.

    Send it before you need it. The point is not to warn about a specific fake; it’s to establish what normal looks like while your members are still calm enough to read carefully.

    Direction two: your money goes out the door

    This is the direction churches don’t see coming, because it doesn’t feel like fraud. It feels like generosity under time pressure.

    The pattern is consistent. A relief organization contacts you — by email, sometimes by phone, sometimes through a name-drop from someone in your network. It has a real-sounding name, often one syllable away from an organization you’ve actually heard of. There is a deadline: trucks, a matching gift that expires, a shelter opening Monday. The ask is a wire transfer, a cashier’s check by overnight mail, or increasingly a payment through an app to a person who “coordinates” for them.

    Sometimes there’s no organization at all. Sometimes there’s a real disaster and a real need and a fake middleman. Occasionally the request arrives from a compromised mailbox belonging to someone you genuinely know, which is why it survives the sniff test.

    The variant aimed squarely at churches: an individual applies to the benevolence fund and needs help urgently because of the disaster — a relative stranded, a deposit on temporary housing, a vehicle repair to get to the affected area. The money needs to go to a third party, right now, by a method that can’t be reversed.

    Urgency is not a detail of these attacks. It is the entire mechanism. Every element of the pitch exists to remove the interval in which somebody would have checked. Take that interval back and almost nothing else matters.

    Why churches are especially exposed here

    Not negligence. Structure.

    Speed is a virtue in your world. A church that takes eleven days to approve disaster relief has failed at something real. Your instincts are correctly tuned for compassion, and fraud is designed to ride those instincts, not defeat them.

    Benevolence funds are built to move fast. They often have looser approval than the operating budget by design — that’s the point of having one. That same design means a single person can frequently authorize a payment without a second signature.

    The approver is often one person. A pastor or an administrator who will not want to say “let me check” to someone describing a family sleeping in a car.

    Ministry networks are informal. Partnerships form through relationships, conferences, and word of mouth, so an unfamiliar organization introducing itself is not unusual. In the corporate world, an unknown vendor asking for a wire is a red flag on its own. In yours, it’s Tuesday.

    Vetting an organization, and choosing how the money leaves

    You don’t need a due-diligence department. You need four checks, and together they take about as long as a coffee break.

    Confirm it exists as a tax-exempt organization. The IRS Tax Exempt Organization Search tool lets you check “an organization’s eligibility to receive tax-deductible charitable contributions.” Search the exact legal name. If nothing comes up, that alone isn’t proof of fraud — small groups and churches are treated differently — but it means you need a different reason to believe in them.

    Check state charity registration. Most states require organizations soliciting donations to register. Your state’s charity office, usually within the Attorney General’s or Secretary of State’s office, can confirm it. The National Association of State Charity Officials maintains a directory of all of them.

    Look them up at a standards-based evaluator. BBB Wise Giving Alliance publishes free reports at give.org against twenty accountability standards covering governance, finances, and truthful representation. The FTC points people to it and to Charity Watch for exactly this purpose.

    Search the name plus a hostile word. The FTC’s own advice: search the organization’s name along with “complaint,” “review,” “rating,” “fraud,” or “scam.” And the FTC’s blunt rule of thumb — “if you can’t find detailed information about a charity’s mission and programs, be suspicious.”

    If an organization is real and the need is real, none of this offends anyone. Legitimate relief organizations are asked to prove themselves constantly and have the answers ready.

    Then decide how you’ll send it, because that matters as much as who receives it. Some payment methods can be stopped or reversed. Some cannot. Fraudsters know exactly which is which, and they will steer you toward the second group while telling you it’s about speed.

    Never send by gift card, wire transfer, cryptocurrency, or cash on a first contact. The FTC states it plainly: “Don’t donate to anyone who insists you must pay by cash, gift card, wiring money, or cryptocurrency.” A relief organization does not need gift cards. Nobody’s supply truck runs on iTunes credit.

    Use a method with a paper trail and some recourse — a check to the organization’s legal name, or a credit card. Both give you something to point at later.

    And apply the money rule you already use for vendors. Any change to payment details — and any new payment instruction from a partner you already have — is verified by voice, on a phone number you already had, before the money goes out. Not the number in the email. The disaster version of that rule is one sentence longer: a new organization you’ve never paid before does not get a wire on its first contact, no matter what the deadline is.

    Route disaster giving through relationships you already have

    This is the single highest-leverage decision, and you can make it before any disaster happens.

    Most churches and nonprofits already have partners: a denominational relief arm, a regional association, a food bank, a long-standing mission partner, a local ministerial alliance. These organizations are typically on the ground faster than any stranger who emails you, and you can verify them once and reuse that verification for the next twenty years.

    Write it down as policy, in one sentence:

    Disaster giving goes to organizations we already have a relationship with. Anything else requires two people to approve and a twenty-four-hour wait.

    That policy costs you almost nothing in real responsiveness — a day, at most, on a giving decision, and your existing partners are unaffected. It costs a fraudster everything, because the pitch depends entirely on being answered inside the hour.

    The same shape works for benevolence: any benevolence payment to a third party rather than to the applicant, or by any irreversible method, waits until tomorrow and is approved by two people. Applicants with genuine need are not harmed by a day. The scripts fall apart.

    If it already happened

    Move within hours, not days.

    Call your bank immediately and ask about a recall. Wires and ACH transfers have narrow windows, but they exist, and the window closes fast.

    Report it to the FBI at ic3.gov the same day. Include the account details, the amount, and the timeline. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic incidents in 2025, and that process depends almost entirely on speed — it works dramatically better inside the first 24 to 72 hours.

    Report it to your state charity regulator and the FTC, which is how patterns get built into cases.

    Then tell your congregation what happened, if their gifts were involved. Plainly, without drama. Organizations that get quiet after being defrauded do more damage to their own credibility than the fraud did.

    What to do this week

    Write the two policy sentences down — disaster giving goes to existing partners; anything else waits twenty-four hours and needs two approvals — and email them to everyone who can authorize a payment. Ten minutes.

    Then draft the congregation notice now, while nothing is happening. Save it where you can find it. Fill in your real giving address, state that you’ll never ask for gift cards or wires, and leave it ready to send the same day something happens near you. Twenty minutes today, and it goes out inside an hour when it matters.

    MissionDefend’s free assessment walks through how your organization handles email, donations, member data, and accounts in plain English — including who can move money and how fast — and gives you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Before Giving to a Charity; Federal Trade Commission, After a disaster, make your donations count; Internal Revenue Service, Tax Exempt Organization Search; BBB Wise Giving Alliance, give.org; National Association of State Charity Officials, State Government directory; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.