A member stops the pastor in the hallway after the second service. She’s a little embarrassed, the way people are when they think they might be about to say something foolish.
She gave to the building fund online on Thursday. Fifty dollars. She wanted to check whether it went through, because she never got a receipt, and now the page won’t load.
He asks her to show him. She pulls it up in her browser history: the church’s name across the top, the church’s logo, the photo from last spring’s picnic, a short paragraph about the building fund written in a voice that sounds almost right. The address bar reads something close to the church’s website, but not quite.
Her fifty dollars is gone. So, in a quieter way, is something else — because for a few minutes on Sunday morning, she wasn’t sure whether the church had taken her money and failed to send a receipt.
What impersonation actually looks like
There are three common forms, and they’re often used together.
The cloned website. Copying a website is not difficult, and it doesn’t require any access to yours. A browser will save an entire page — text, images, layout — in one click. An attacker pulls down your giving page, swaps the payment form for their own, and hosts it somewhere cheap. It looks exactly like your site because most of it is your site.
The near-identical social media page. More common than the cloned site, because it’s free and it takes about four minutes. A new Facebook page with your church’s name, your logo as the profile picture, and six photos lifted from your existing page. Then it sends friend requests or messages to people who follow the real one — the member list is right there in public. Some versions don’t even ask for money at first. They build a small following, then post an urgent appeal three weeks later.
The lookalike domain name. A domain is the address people type to reach you — firstchurchsomewhere.org. Anyone can register one that sits a keystroke away from yours: firstchurchsomewhere.com instead of .org, first-church-somewhere.org with hyphens, firstchurchsomwhere.org with a letter dropped, or firstchurchsomewhere-giving.org with a plausible word bolted on. Domains cost a few dollars a year and nobody checks who you are when you buy one.
The lookalike domain is the piece that makes the other two convincing, because it survives the one check a careful person actually performs — glancing at the address bar.
Your own members are the audience
This is what separates charity impersonation from generic fraud, and it’s the reason it deserves your attention rather than your insurer’s.
An attacker impersonating a national charity is fishing in an ocean. An attacker impersonating your church is working a list of a few hundred people who already trust the name, already give to it, and already expect to hear about a building fund or a mission trip or a family in crisis. The conversion rate is not comparable.
They will also aim at the moments when giving is already elevated and already emotional — a fire, a funeral, a medical fundraiser for a family everybody knows, a capital campaign you announced from the front. Those are the moments when an appeal is expected, which means an extra appeal doesn’t look out of place.
And here is the part leaders underestimate: your members will experience this as something that happened to them at your church. Not “I was defrauded by a stranger on the internet.” The first feeling is confusion about whether the church mishandled their gift; the second is embarrassment; the third, sometimes, is a quiet decision to give by check from now on and not mention it. You may never hear about most of it.
That’s the actual damage. The money taken from any one person is usually small. The number of people who become slightly more hesitant is not.
Finding out whether it’s happening
You cannot respond to something you don’t know about. Three checks, none of them technical, all of them free.
Search your own name. Once a quarter, type your organization’s name into a search engine and look past the first three results. Add the words donate, giving, and fund and search again. Do it in a private or incognito window so your own browsing history doesn’t push your real site to the top and hide everything else.
Check each platform directly. Search your name inside Facebook, Instagram, and any other platform where you have a presence. Look for pages using your logo, your photos, or a name within a character or two of yours. Also search for pages you used to run — an abandoned page from a 2019 youth event is a gift to someone who wants a head start on credibility.
Set up a Google Alert. Go to google.com/alerts, enter your organization’s name in quotation marks, and have results emailed weekly. Set up a second one for your name plus the word donate. It’s five minutes once, and then it runs on its own. It will not catch everything — it does not see inside social platforms, and it does not see pages that were never indexed — but it costs nothing and it has caught plenty of people.
Add one more habit that isn’t a search: tell your congregation to tell you. Most impersonation is discovered by a member who thought something felt slightly wrong. If they know there’s a person to tell and that nobody will make them feel foolish, you’ll hear about it in hours instead of months.
Getting it taken down
Takedowns are unglamorous and mostly consist of filling in forms carefully. They work more often than people expect. Work all three channels at once rather than in sequence.
The platform. Every major social platform has a reporting flow specifically for impersonation of an organization, distinct from general “this is spam.” Find that specific option — impersonation reports from the impersonated party are handled differently and faster than spam reports. Report from an account that administers your real page, because that connection helps establish who you are. Ask three or four people to file their own reports as well.
The registrar and the host. Two different companies are usually involved: the registrar that sold the domain name, and the host that runs the server the page sits on. You can look up who they are with the ICANN registration data lookup at lookup.icann.org — type the fraudulent domain in and it will show you the registrar. Registrars are contractually required to publish an abuse contact; ICANN’s rules oblige them to maintain “an abuse contact to receive abuse reports” and to publish an email address for it, and to take “reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Email abuse@ that registrar with the exact fraudulent address, the exact address of your real site, and a plain statement that the page is soliciting donations while impersonating your organization. Attach screenshots. Do the same with the host if you can identify it.
The regulator. Fundraising is regulated at the state level, and most states require an organization soliciting charitable donations there to register first. Your state’s charity office — usually inside the Attorney General’s office or the Secretary of State’s — is the right place to report someone soliciting in your name. The National Association of State Charity Officials keeps a directory of every state’s office. Also report the fraud to the FBI at ic3.gov; the loss per member may be small, but a pattern across several organizations is exactly what makes a case.
Keep evidence before you report anything: full-page screenshots with the address bar visible, the exact URL, and the date. Pages come down, and once they’re gone you can’t prove what they said.
None of this is legal advice, and if the impersonation is substantial or persistent — or if a member has lost real money — a short conversation with an attorney is worth having. Requirements vary by state.
What to say publicly while it’s happening
Say something, quickly, in the channels your members actually read. Silence gets filled with the wrong story.
The tone that works is calm and specific. Not an apology, because you did nothing wrong, and not alarm.
We’ve learned that someone has set up a page using our name and logo to collect donations. It is not us. Our giving page is only ever at [your exact address], and that’s the only place we ask you to give online. If you gave through any other page in the last few weeks, please call your bank or card company today and tell them the charge was fraudulent — then let the office know so we can help. Nobody here is going to think less of you. This was designed to be convincing.
Three things that paragraph does: it states your real giving address in a form people can compare against, it gives a concrete next step with a same-day urgency that’s genuinely warranted, and it removes the shame. That last part is what determines whether you find out how many people were affected.
Then do the standing version: publish your real giving address in the same place every time — the bulletin, the website footer, the bottom of every email — and say plainly that you will never ask for donations by direct message, gift card, wire transfer, or cryptocurrency. Members who know what normal looks like recognize abnormal without being told.
What to do this week
Search for yourself. Twenty minutes, in a private browsing window: your name in a search engine, then your name plus donate, then the same searches inside Facebook and Instagram. Write down what you find, including your own abandoned pages.
Set two Google Alerts — your organization’s name in quotation marks, and your name plus donate — delivered weekly to whoever reads the office email.
Register the obvious lookalikes, if you have twenty or thirty dollars a year to spend. If you own the .org, buy the .com and the .net and point them at your real site. It’s the cheapest control in this entire article.
Half an hour, and you’ve turned an attack you’d have found out about from a confused member into one you’d find out about from a weekly email.
Impersonation is one symptom of a wider question — how visible and how protected your organization is online. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including how your giving pages and domain names are set up — and returns a baseline score with a ranked list of what to fix first.
No spam and no sales calls — just one email when it’s live.
Related reading
- fake job listings posted under your ministry’s name
- the six weeks when giving fraud peaks
- who actually controls your church’s Facebook page
MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.
Sources: ICANN, Registrar Abuse Reports; ICANN, Registration Data Lookup Tool; National Association of State Charity Officials, State Government directory; Federal Trade Commission, Before Giving to a Charity; Google, Create an alert.

