Home Articles Get your free assessmentComing soon

Tag: impersonation

  • Pretexting: The Fake IT Guy and the Vendor Who Isn’t

    Pretexting: The Fake IT Guy and the Vendor Who Isn’t

    The call comes in on a Wednesday around 10 a.m., which is not an accident — late enough that the office is busy, early enough that nobody’s left for lunch.

    “Hi, this is Marcus from TechServe — we handle the copier contract? We’re pushing a security update to all our units this week and I need someone to read me the numbers off the admin sticker on the back. Should take two minutes. Sorry for the hassle — half the churches in the county are on my list today.”

    There is no Marcus. There is no update. But notice everything that call already got right: a plausible company, a plausible task, an apology, a time limit, and a detail — half the churches in the county — that makes the whole thing feel routine. By the time an ask arrives, it doesn’t feel like a request from a stranger. It feels like step three of a process that started before you picked up.

    That manufactured backstory has a name: pretexting. The pretext is the invented situation — the role, the reason, the paperwork — that makes the eventual request seem normal. If phishing is a fake message, pretexting is a fake context. It’s the con artist’s stage set, and it’s the engine inside most of the attacks this series has covered: the fake invoice works because “vendor billing you” is a pretext, and the phone scam works because “your bank’s fraud department” is one.

    The costumes that get worn at churches

    Attackers pick pretexts the target already expects to encounter. For a church or small nonprofit, four costumes come up over and over.

    The IT technician. “We’re doing maintenance on your email this afternoon — I’ll need someone to confirm the login so accounts don’t lock out.” Small congregations rarely have in-house IT, so someone external who handles computer things is entirely believable — most churches genuinely do have a guy. The test is simple: real technicians you actually pay never need your password. Anyone who asks for one is not your technician, whatever the caller ID says.

    The vendor with an account problem. The copier company, the payroll processor, the giving platform, the alarm monitoring service. The caller knows which one you use — often because it’s visible on your website, in a bulletin PDF, or on a sticker by the door — and the “problem” needs an account number, a card update, or remote access to fix.

    The authority up the chain. The diocese, the district office, the denomination’s insurance program, an “auditor” doing an annual review. Hierarchical organizations are trained to respond to the level above them, and attackers borrow that reflex. A folder of official-looking paperwork, a confident tone, and a Friday-afternoon deadline can move remarkable amounts of information.

    The government caller. The IRS about your exempt status, a “grant administrator” about funds you’re eligible for, a court officer about a missed jury summons for your pastor. Impersonating agencies and businesses is now squarely illegal under a rule the Federal Trade Commission put into force on April 1, 2024 — a rule created precisely because the FTC logged over $1.1 billion in reported impersonation-scam losses in 2023, more than triple the 2020 figure. A rule after the fact, of course, only helps you if you didn’t comply during the call.

    Why good people hold the door open

    Pretexting exploits the two instincts churches deliberately cultivate: helpfulness and trust. The volunteer at the desk wants to be useful to the nice technician. The bookkeeper doesn’t want to make the diocese wait. Nobody wants to be the suspicious one — it feels rude, and ministry culture prizes warmth.

    So the fix cannot be “make everyone suspicious.” It won’t take, and it would cost you something real. The fix is to make verification feel like procedure instead of accusation — the same shift that makes a bank teller checking ID feel professional rather than hostile.

    What to do this week

    Give the front desk a script that isn’t rude. One laminated card: “Happy to help with that — our process is to call you back through the main number we have on file for your company. What’s your name and extension?” A real vendor hears bookkeeping hygiene. A pretexter hears the con failing. The power of the callback is that it routes around everything the attacker controls — their number, their story, their urgency — to a channel you already trusted before the call existed.

    Keep a one-page vendor sheet. Every company that can plausibly call you — copier, payroll, giving platform, insurance, IT, alarm — with the phone number from your contract or a bill you’ve paid, not from the internet. Verification only works if the real number takes ten seconds to find. Update it when contracts change, and note who your actual account rep is.

    Decide what the “sticker information” is worth. Serial numbers, account numbers, staff direct lines, which software you use — none of it is secret, exactly, but each piece makes the next pretext more convincing. The attacker who knows your copier model and your administrator’s first name sounds like Marcus. Trim what’s published where you can, and treat unsolicited requests for those details as the reconnaissance they are.

    Rehearse the two-question test. Before acting on any unsolicited contact, staff ask: Did I have a way to expect this? and Am I being given a reason not to verify? A real vendor’s real update survives a callback tomorrow. Only the fake one needs it done on this call, today, before lunch.

    Pretexting is patient, polite, and completely dependent on one thing: the target acting inside the story the attacker built. A callback steps outside the story. Nothing inside it survives that.

    MissionDefend’s free assessment includes the unglamorous controls that stop pretexting — callback rules, vendor verification, front-desk procedure — and shows you which ones your organization is missing. Get on the launch list.


    Sources: Federal Trade Commission, FTC Announces Impersonation Rule Goes into Effect Today (April 1, 2024); Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • AI Voice Cloning: When the Caller Sounds Exactly Like Your Director

    AI Voice Cloning: When the Caller Sounds Exactly Like Your Director

    The bookkeeper answers on the second ring, and it’s the executive director’s voice. Not a voice like hers — her voice. The slight rasp. The way she says “listen” at the start of a sentence when she’s stressed.

    Listen — I’m about to get on a flight and the auction deposit didn’t go through. I need you to send it again before we lose the venue. I’ll text you the details. Don’t call back, I’m boarding.

    It’s her voice. It is not her.

    This is voice cloning — using artificial intelligence to generate speech that sounds like a specific, real person. The software behind it is cheap, legal, widely available, and needs surprisingly little to work with: a short sample of someone talking is enough to produce a convincing copy saying anything an attacker types. The FBI warned about exactly this in a December 2024 public service announcement: criminals are generating “short audio clips containing a loved one’s voice” to fake a crisis and demand immediate money. The Federal Trade Commission issued the same warning back in March 2023 — all a scammer needs is “a short audio clip of your family member’s voice,” which, the FTC notes, “he could get from content posted online.”

    Read that last part again, and then think about where your pastor’s voice lives.

    Churches are uniquely exposed, and it’s worth saying plainly

    For most small organizations, the boss’s voice isn’t on the internet. For a church, the entire leadership team is on the internet, every single week, in high-quality audio, saying thousands of words in every register — calm, urgent, warm, commanding. The livestream. The sermon podcast. The YouTube archive going back years.

    None of that is a mistake, and the answer is absolutely not to stop. Public preaching is the work. But it changes the math your staff should carry in their heads: for your organization, “it sounded exactly like him” is not evidence of anything. Not anymore. A scammer targeting your church has a better voice sample of your senior pastor than most attackers have of a Fortune 500 CEO.

    How the scam is actually run

    Voice cloning didn’t invent a new con. It upgraded three old ones we’ve already covered in this series.

    The urgent-request call. The gift card scam — “I need you to handle something quietly” — has historically arrived by email or text, where the impersonation is only a display name. A cloned voice moves it to the phone, where the impersonation is your ears telling you it’s really him. The structure is identical: urgency, secrecy, an odd payment method.

    The family emergency. A grandparent gets a call from a grandchild — the grandchild’s actual voice — in trouble, needing bail or a hospital deposit, begging them not to tell mom and dad. This is the version the FTC’s alert describes, and it targets exactly the older adults a church is best positioned to warn.

    The verification call. The FBI’s PSA notes criminals also use AI-generated audio of a victim’s own voice to get past phone-based identity checks at banks. That one you can’t train away — but it’s a reason to prefer app-based verification over “we’ll call you” security wherever your financial institutions offer a choice.

    One more thing makes the phone version stronger than it should be: the number on the screen can lie. Caller ID spoofing — displaying a number the caller doesn’t own — remains routine, as the FCC documents, and the STIR/SHAKEN verification system that carriers use confirms which network a call came from, not whether the person speaking is honest. A familiar voice from a familiar number can still be neither.

    Why “listen carefully” is not a defense

    You’ll find advice suggesting you listen for robotic cadence or odd pauses. The FBI’s own PSA suggests paying attention to tone and word choice — and that’s worth doing — but treat it as a tripwire, not a wall. The technology improves monthly, the clips are short by design, and a stressed listener on a bad connection hears what they expect to hear. Any defense that requires your bookkeeper to out-listen a machine on the worst morning of her month is not a defense.

    The defense that works is procedural, and it’s the same one that stops every impersonation scam regardless of how good the impersonation is: the request and the verification must travel on different channels.

    What to do this week

    Set the callback rule for money and credentials. Any request to move money, buy gift cards, change banking details, or share a password — no matter who it comes from, no matter how it arrives, no matter how real the voice sounds — is confirmed by hanging up and calling the person back on the number already in your contacts. Not the number that just called. Not a number from the message. The clone can call you; it cannot answer the real person’s phone.

    Agree on a family-style code word for leadership. Pick a phrase the executive team knows and would never appear in a sermon. If a “boarding a plane right now” call ever demands money and can’t take a callback, ask for the word. It’s thirty seconds of setup for a control no voice model can generate. Encourage staff to set the same thing up with their own aging parents — this scam reaches homes before it reaches offices.

    Kill the secrecy lever in policy. Write it down: no financial request at this organization is ever confidential from the treasurer or bookkeeper’s normal verification steps. “Don’t tell anyone” or “don’t call back” is not a request a real leader here will ever make — which converts the scammer’s favorite pressure line into an alarm.

    Tell the congregation about the grandparent version. One announcement, one bulletin line: if a family member calls in crisis asking for money, hang up and call them back on their own number — a voice can be faked. The FTC’s guidance is exactly that — don’t trust the voice, verify through a known channel — and older members are far more likely to hear it from you than from a federal agency’s blog.

    The voice on the phone used to be proof. It’s now just another sender name, as forgeable as the “From” line on an email. The organizations that handle this well won’t be the ones with the sharpest ears — they’ll be the ones where calling back is so routine that nobody even feels awkward doing it.

    The free MissionDefend assessment checks whether verification rules like these actually exist at your church — not just in someone’s head — along with the rest of your security baseline. Join the launch list to get first access.


    Sources: FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, Alert I-120324-PSA (December 3, 2024); Federal Trade Commission, Scammers use AI to enhance their family emergency schemes (March 20, 2023); Federal Communications Commission, Caller ID Spoofing.

  • The Job Opening You Never Posted

    The Job Opening You Never Posted

    The first voicemail comes in on a Monday. A woman named Denise, polite and a little apprehensive, asking when her start date is and whether she should bring anything on the first day. She mentions she already deposited the check.

    Nobody at the church knows who she is.

    By Thursday there have been four more calls, one email with a scanned driver’s license attached, and a message from a man who is no longer polite at all, because his bank has just reversed a $3,200 deposit and told him he owes them the money. He has an offer letter with the church’s logo on it. He has text messages from someone who signed off as the church’s “HR coordinator.” He does not have a job, and the church does not have an HR coordinator.

    No one at the church did anything wrong. No system was broken into. Someone simply took the name of a trusted local institution, put it on a job posting, and let the name do the work.

    The posting you never wrote

    The scam is straightforward. A fraudster creates a job listing on a recruitment site, a community Facebook group, or a job board — “remote personal assistant,” “part-time bookkeeper,” “youth ministry coordinator.” The employer name is a real church. Sometimes the logo is lifted from the church website. Sometimes the posting copies the mission statement word for word, because that language is right there to copy.

    The FBI has warned about exactly this pattern, describing how criminals “spoof legitimate companies to post fraudulent job postings on commonly used employment-oriented networking sites,” directing applicants to spoofed websites, email addresses, and phone numbers that the scammers control.

    What follows is fast, and the speed is deliberate. The applicant is contacted within hours. The interview happens entirely over text message, WhatsApp, Signal, or a chat window — never a video call, never in person, occasionally a brief phone call from a number that never answers again. The applicant is hired, usually within two days.

    Then comes the part that actually makes money.

    The check is the whole point

    The new hire is told the organization will provide equipment — a laptop, a monitor, software for the ministry’s donor database. A check arrives, or an image of one, for more than the equipment costs. Deposit it, buy the equipment from “our approved vendor,” and send the balance on to the vendor by wire, payment app, or gift card.

    The check is counterfeit. The money the applicant sends is real.

    The Federal Trade Commission puts it about as plainly as it can be put: “The check is fake and will bounce, and the bank will want you to repay the full amount of the fake check, while the scammer keeps the real money you sent them.”

    The trap is a piece of banking mechanics almost nobody outside of banking knows. Your bank may make a deposited check’s funds available to you well before it knows whether the check is any good. Seeing the balance in your account is not the same as the check having cleared. When it is finally identified as counterfeit, the deposit is reversed — and the person who deposited it is the one holding the loss.

    That’s why the FTC’s rule for job seekers is absolute: “if you get an offer that includes depositing a check and then using some of the money for any reason, that’s a scam.”

    The quieter version: the onboarding packet

    Not every variant involves a check. In some, the “hire” goes smoothly and the only ask is paperwork — a direct deposit authorization, a tax form, a copy of a driver’s license, a Social Security number “for the background check.”

    That packet is the product. It is enough to open accounts, file a fraudulent tax return, or take out credit in the applicant’s name. The FTC’s guidance on remote job scams describes scammers asking targets to “fill out direct deposit and tax forms with your bank account and other personal information.”

    This version is harder to spot because nothing about it feels like a scam. Onboarding paperwork is exactly what a new job involves. The only thing wrong is that the employer doesn’t exist.

    Why churches and nonprofits get picked

    The name buys instant trust. A job seeker who sees “First Baptist” or “Habitat affiliate” or a hospice’s name on a listing relaxes in a way they would not for an unknown LLC. That trust was built over decades by people doing good work, and it is being spent by someone else.

    The brand is sympathetic. Ministry work attracts applicants who are motivated by more than a paycheck, and who are therefore more inclined to give the organization the benefit of the doubt when something is slightly odd.

    There is no HR department to call and check. This is the structural reason, and it is not a failing — it is what a small organization looks like. At a company with 4,000 employees, a suspicious applicant calls recruiting. At a church with a pastor, an administrator, and a part-time music director, there is no recruiting line to call, and the main number goes to voicemail on Wednesday afternoons.

    Your staff page tells the scammer everything. Names, titles, email format, the pastor’s photo. All of it is public on purpose, because a church website that hides its people would be a strange church website. None of that should change.

    And here is what it costs you, even though no money left your accounts.

    You inherit a stream of confused and increasingly angry people, some of whom are out thousands of dollars they did not have. They are not wrong to be upset, and the first person they reach is whoever answers your phone. That is a hard morning for an office administrator who had no warning.

    Then there is the reputational damage, which is slower and more corrosive. The FBI has noted that job seekers “who are unaware they have been scammed may write negative reviews of the victim company; thus, adversely impacting the company’s ratings.” Some people will never learn the church wasn’t involved. They will simply remember the name attached to the worst financial week of their year.

    What actually closes it

    Publish every real opening in one place, on your own website. One page — /jobs or /employment — that is the single source of truth. If there are no openings, the page should say so in a sentence. This is the whole defense in one move, and it works because it gives every applicant, and every reporter, and every skeptical spouse a place to check. The FBI’s advice to job seekers is precisely this: verify job postings found on networking and third-party sites on the hiring company’s own website.

    Put a short standing notice on that page. Say the things you’d otherwise have to say fifty times on the phone:

    All open positions are listed on this page. We do not conduct interviews only by text or chat. We never send money, checks, or equipment funds to an applicant, and we never ask an applicant to purchase anything on our behalf. If you have been contacted by someone claiming to hire on our behalf and this page does not list the role, it is not us — please contact us at [number].

    The rule to state and never bend: every real opening is listed on our own website, and no legitimate hire of ours ever begins with a check.

    Search for yourself once a quarter. Ten minutes. Put your organization’s name into a job board search, into Facebook, into a plain web search alongside the word “hiring.” The FBI specifically recommends that businesses proactively search for fraudulent postings under their own name. If you find one, report it to the platform — every major job site and social network has a report link on the listing itself — and ask for it to be removed.

    Respond publicly when it happens. A short post on your website and social accounts, and a line in the newsletter. Not defensive, not lengthy. We’ve learned that someone is posting fake job openings using our name. We are not hiring for these roles. Our real openings are always here. If you were contacted, here’s what to do. Silence lets the story be told by people who are furious and misinformed.

    Report it. Send the details to the FBI at ic3.gov, and to the FTC at reportfraud.ftc.gov. Include screenshots of the posting, the account that posted it, and any messages applicants forwarded to you. Encourage the applicants to file their own reports — theirs carry the financial loss, which is what drives a case.

    If you’re the applicant reading this

    Some of you found this page because you searched the church’s name at eleven at night with a bad feeling. Here is the short version.

    You are not gullible. This scam is engineered to feel normal, and it borrows the credibility of an institution that spent years earning it.

    Call the organization at a number you found yourself, on their own website — not one from the offer letter or the messages. Ask whether the role exists. That one call resolves most of these.

    If you already deposited a check and sent money on, call your bank immediately and say the words fake check scam. Speed genuinely matters. Then report it at ic3.gov.

    If you handed over a Social Security number, bank details, or a copy of your ID, go to identitytheft.gov. It is the FTC’s official site, it is free, and it will generate a specific recovery plan for you — freezing credit, disputing accounts, the whole sequence — rather than leaving you to figure it out. The FTC directs job scam victims there for exactly this reason.

    And tell someone in your life today rather than next week. The single thing that turns this from a bad experience into a long one is the silence people keep out of embarrassment.

    What to do this week

    Create or update one page on your website listing every current opening — including a plain sentence when there are none — and add the standing notice above. Then spend ten minutes searching your organization’s name on a job board and on Facebook to see whether anything is already out there.

    That’s about thirty minutes, and it turns a scam you can’t prevent into one you can answer in a single sentence.

    If you want to know what else about your organization is easy for a stranger to borrow, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — including the public-facing gaps like this one that most security checklists skip entirely.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Scammers Exploit Security Weaknesses on Job Recruitment Websites to Impersonate Legitimate Businesses; Federal Trade Commission, Job Scams; Federal Trade Commission, Searching for a job to work remotely? Avoid scams and identity theft.

  • Your Pastor Won’t Text You for Gift Cards: The Impersonation Scam

    Your Pastor Won’t Text You for Gift Cards: The Impersonation Scam

    If you work at a church, you have probably already seen this one. If you haven’t, you will.

    A member of your congregation gets a text from an unfamiliar number:

    Hello, are you available? I need a favor. — Pastor Mike

    Or an email lands in a volunteer’s inbox. The sender name says Pastor Mike Adams, exactly as it appears in every other message from him. The subject line is Quick request. The body is two sentences.

    Are you free right now? I’m in a meeting and can’t talk on the phone, but I need something handled discreetly.

    Anyone who replies gets the ask. The church needs to buy gift cards — Apple, Google Play, Amazon, Target — for a member in the hospital, or for a benevolence case, or as thank-you gifts for volunteers. The pastor will reimburse them. It’s urgent, it’s a little sensitive, and could they please just scratch off the backs and send photos of the codes?

    This scam runs constantly, in every denomination, in churches of every size. It is worth understanding precisely, because the mechanics are simpler than most people assume — and so is the fix.

    Nobody hacked anything

    The most important thing to understand: in almost every version of this scam, the pastor’s account was never broken into.

    That surprises people, because the message looks like it came from him. But the attacker didn’t need access. They needed one of two very ordinary tricks.

    Trick one: display name spoofing

    Every email has two separate pieces of sender information, and your mail app shows you one of them.

    The display name is the friendly label — Pastor Mike Adams. The email address is the actual routing information — mike@yourchurch.org.

    Here’s the thing that makes this scam work: the display name is just text. Anyone can type anything they like into it. There is no verification, no check, no ownership requirement. I can create a free email account right now and set my display name to “Pastor Mike Adams,” and every message I send will show up in your inbox with that name on it.

    The real address underneath would be something like `pastormike.adams247@gmail.com` or `mike.adams.church@outlook.com` — plausible enough that if you did glance at it, it might not alarm you.

    And on a phone, you usually can’t glance at it. Mobile mail apps show the display name and hide the address entirely to save screen space. That is not a bug in your phone. It’s a design choice that this scam exploits, and it’s why these messages so often get read and answered on a phone rather than a desktop.

    Trick two: an unfamiliar phone number

    The text-message version is even simpler. There’s no spoofing at all. The attacker just texts from a number you’ve never seen and signs the message with the pastor’s name. Because a new number shows up with no contact photo and no history, and because plenty of people do change phones, “Hi, this is Pastor Mike, I got a new number” is not automatically suspicious.

    Where do they get the names and numbers? Nowhere clever. Your staff page lists who your pastor is. Your bulletin names your office administrator. Your Facebook page shows who volunteers. Church directories get shared. None of that is a security failure — it’s a church being findable, which is the point of a church. But it means an attacker can build a convincing message with fifteen minutes of public browsing.

    Why gift cards specifically

    This is the detail that gives the scam away, once you know it.

    Gift cards are, for a criminal, close to perfect. They are effectively untraceable — once the code is spent, there’s no account holder to subpoena and no transaction to reverse. They are instantly transferable — a photo of the scratched-off code is all that’s needed; the physical card is irrelevant. They are irreversible — unlike a credit card charge or even a wire transfer, there is no dispute process and no recall window. And they are available everywhere, which means a victim can complete the whole request in twenty minutes at a grocery store.

    Compare that to a bank transfer, which leaves a paper trail, involves an institution that can freeze funds, and requires the criminal to maintain an account somewhere.

    So here is the rule that flows from that, and it’s worth putting in bold in your bulletin:

    No legitimate church request will ever involve buying gift cards and sending photos of the codes. Not for benevolence. Not for a hospital visit. Not for volunteer appreciation. Not ever. There is no scenario in normal church operations where that is how money moves.

    That single sentence, taught once, immunizes most people permanently — because it doesn’t require anyone to evaluate whether a particular message looks legitimate. It just makes the ask itself the tell.

    The wider pattern

    Gift cards are the most common version, but the same impersonation gets used for other requests, and your team should recognize the family resemblance:

    A request to wire funds urgently for a deposit or a contractor, before end of business.

    A request to buy cryptocurrency and send it to a wallet address.

    A request for the staff list, the member directory, or W-2 information — no money at all, just data, which then gets used for the next attack or sold.

    A request to buy something on your personal card and be reimbursed later, which is really just gift cards with extra steps.

    The shape is always the same: authority, urgency, a reason you can’t verify by voice right now, and a request that moves value in a way that can’t be undone.

    What the FBI data says

    This isn’t folklore. Phishing and spoofing were the most-reported cybercrime in America in 2025, with 191,561 complaints filed with the FBI’s Internet Crime Complaint Center.

    The demographic detail matters for congregations. Victims aged 60 and over filed 201,266 complaints in 2025, losing $7.748 billion — a 59% increase over the previous year, averaging $38,500 per victim. Older members of your congregation are being targeted heavily, and a warning from their church may be the most credible one they receive.

    How to shut it down

    Four things. None of them take money, and the first two take an afternoon.

    Tell your congregation, in plain words, from the front. Not a technical bulletin insert nobody reads — a spoken sentence, from the platform or in the newsletter, in the pastor’s own voice: “I will never text or email you asking for gift cards, money, or a favor involving payment. If you get a message like that with my name on it, it isn’t me. Please don’t reply, and please tell the office.” Coming from the person being impersonated, this lands differently than a security notice.

    Teach the one habit that works on a phone. Before acting on any message asking for money or a favor, tap the sender’s name to reveal the actual email address. On a text, check whether the number matches the one already in your contacts. If it doesn’t, that’s your answer. This takes three seconds and doesn’t require anyone to be technical.

    Make verification impersonal and expected. Write down that any money-related request is confirmed by voice, using a number you already had — not a number in the message. Say explicitly that this applies to requests that appear to come from leadership, and that nobody will ever be thought disloyal for making the call. That last clause is doing real work: the reason these scams succeed in churches is that questioning the pastor feels wrong.

    Turn on the technical guardrails. Two settings help meaningfully. First, multi-factor authentication on every staff email account — the extra code or tap after the password — which protects you in the cases where an account really is compromised rather than merely imitated. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Second, ask whoever manages your email to enable external sender warnings, the banner that says “This message came from outside your organization.” When a message claims to be from your pastor and carries that banner, the contradiction is visible even on a phone.

    If you want to go further, the fuller fix is email authentication — the SPF, DKIM and DMARC records that stop strangers sending mail that claims to come from your domain at all. That’s a bigger topic, and it’s coming later in this series.

    If someone already bought the cards

    Move fast; there’s a narrow window.

    Call the gift card issuer’s fraud line immediately — the number is on the back of the card or on the retailer’s website — and report the cards as fraudulently obtained. Occasionally, if the codes haven’t been spent, funds can be frozen. Keep the physical cards and the receipts; they’re evidence and they’re required for any claim.

    Report it to the FBI at ic3.gov. This feels pointless for a few hundred dollars, and it isn’t: the aggregate reporting is what drives takedowns, and it’s how the pattern gets tracked.

    Then tell your congregation what happened, without naming the person who was fooled. Someone who admits they were scammed has done your whole community a service, and how you treat them determines whether the next person speaks up in twenty minutes or three days.

    What to do this week

    Write four sentences and send them to your congregation under your pastor’s name: I will never text or email you asking for gift cards or money. If you get a message like that with my name on it, it isn’t me. Don’t reply. Tell the office.

    That’s it. That’s the highest-value fifteen minutes available to most churches this month.

    When you’re ready to look at the whole picture rather than one scam at a time, MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts — then give you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.