Home Articles Get your free assessmentComing soon

Tag: passwords

  • When the Breach Isn’t Yours

    When the Breach Isn’t Yours

    The email arrives on a Thursday morning, and the subject line is careful in a way that tells you something before you open it: An important update regarding your account.

    Your church management system — the one holding your directory, your attendance records, your kids’ check-in data, and every pledge for the last six years — has had what the letter calls a security incident. A third party accessed portions of its environment. The company is working with outside experts and law enforcement. It takes the security of your data very seriously.

    You read it twice. You didn’t click anything. Nobody on staff did anything wrong. Your passwords were fine.

    And you still have to do something about it, today, because eleven thousand names in that database belong to people who trusted your church with them.

    What the words mean, and whether the notice is real

    A breach means someone got into a system and reached information they weren’t supposed to reach. That’s all. It doesn’t necessarily mean a movie-style intrusion or a ransom note. Very often it’s a stolen password used on an ordinary login screen.

    The important part is whose system. When the breach is at a company you buy software from rather than in your own building, security people call it third-party risk — sometimes supply-chain risk. Both terms describe the same simple, uncomfortable fact: the data you’re responsible for lives on computers you don’t control, run by people you’ll never meet.

    You accepted that trade the day you stopped keeping the directory in a filing cabinet, and it was almost certainly the right trade. A cloud giving platform is more secure than a spreadsheet on the office computer, by a wide margin. But it moves the risk rather than removing it, and once every three or four years the bill for that comes due in your inbox.

    This is not hypothetical for churches. In 2020 the fundraising and donor-management company Blackbaud — which the FTC described as serving more than 45,000 organizations including nonprofits, foundations, schools, and healthcare providers — was breached by an attacker who used stolen credentials and stayed inside for three months. Tens of thousands of customer organizations were affected, and millions of individual people. Not one of them did anything to cause it.

    Which brings us to the step everybody skips. Before you act on the notice at all, confirm it’s real.

    Breach notification emails are one of the most effective phishing pretexts in existence. They arrive when you’re rattled. They carry a plausible reason to log in immediately. And they can be sent by anyone — including, routinely, by attackers who read the same news story you did and mailed a counterfeit version to every customer of the breached company they could find.

    So do not click the link in the email — not the one saying Secure your account, not the one offering credit monitoring.

    Instead, open a browser and go to the vendor the way you normally do, from your bookmark or by typing the address you already know, and log in. A real vendor in the middle of a breach response will have a notice on the dashboard, a status page, and a support article. If there’s nothing there, call the support number from your contract or a past invoice, not from the email.

    The FTC gives the same advice about any message claiming your information has been exposed: don’t use a link or a phone number from the message itself.

    What usually gets taken, and what “no financial data” actually means

    Not all exposed data is equal, and vendor notices are often written to blur that. Three broad categories:

    Contact and profile data. Names, addresses, email addresses, phone numbers, birthdays, family relationships, giving history, notes fields. This is what almost always goes, and vendors tend to describe it in the mildest available language. It is not harmless. Your member directory is a targeting list — see below.

    Passwords. The notice may say passwords were hashed. Hashing turns a password into a scrambled string that can’t be reversed directly, which is genuinely better than storing the plain text. But hashes can be attacked by guessing at industrial speed, and a short or common password will fall. Treat “hashed passwords were exposed” as “passwords were exposed, and you have some time.”

    Payment and identity data. Card numbers, bank account and routing numbers, Social Security numbers. Reputable giving platforms generally don’t hold full card numbers — they hand that to a payment processor and keep a token instead. That’s real protection, and it’s why “no card data was involved” is often true.

    Now the caution, and it comes with a documented example.

    “No financial data was affected” is not the same as “nothing was affected.” It is a statement about one category, made early, on incomplete information — and sometimes it is simply wrong.

    Blackbaud told customers in July 2020 that the attacker “did not access credit card information, bank account information, or social security numbers.” According to the FTC, the attacker had in fact taken bank account numbers and Social Security numbers. The SEC, in a separate action, found the company’s own staff learned this within days and that senior management responsible for public disclosures wasn’t told. Customers weren’t corrected until October — three months in which affected people didn’t know they had reason to watch their credit.

    The lesson isn’t that vendors lie. It’s that early breach statements are provisional. Respond to what a breach could plausibly have exposed, not to the most reassuring sentence in the notice, and read the follow-up letters instead of filing them.

    The first forty-eight hours

    Once you’ve confirmed the notice is genuine, this is the whole list.

    Change the password on that service, and stop reusing it. If the same password protects your email, your bank, or your giving platform, change it everywhere it was used. Reuse is what turns one company’s breach into your problem: attackers take the leaked list and try those pairs against every major service. That technique has a name — credential stuffing — and it only works on reused passwords.

    Turn on multi-factor authentication. This is the second step after your password: a code, a tap on your phone, a security key. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Turn it on for the breached service and, while you’re thinking about it, for staff email — that’s the account that unlocks everything else.

    Check for things that shouldn’t be there. In the affected system and in your email: mail rules or forwarding you didn’t create, connected or authorized apps you don’t recognize, user accounts belonging to people who left, and any API keys or integrations. Attackers who get in leave doors open behind them, and this is the step most organizations skip after resetting a password.

    Look at who still has access. A breach is a good excuse to do the review you’ve been meaning to do. Remove the volunteer from 2019. Downgrade the three people with full administrator rights who don’t need them.

    Write down what you did and when. A dated page in a notebook. If this becomes a conversation with your insurer, your board, or a lawyer, “we don’t remember exactly” is a bad answer and the notebook is a good one.

    The second wave is aimed at your people

    Here’s what gets underestimated. The most damaging consequence of a member-data breach usually isn’t the breach. It’s the phishing that comes six weeks later, built out of the details.

    Someone now knows that Helen Ortiz gives $150 on the fifteenth of the month by automatic transfer, attends the Tuesday women’s study, and has a granddaughter named Kayla. An email that uses those specifics doesn’t read like a scam. It reads like church.

    So tell your congregation something concrete, and do it before the calls start:

    Our church management provider had a security incident. Some of your contact and giving information may have been included. Because of that, expect more convincing-looking messages over the next few months. Our church will never email or text you asking for gift cards, a wire transfer, or your login details, and we will never change our giving instructions by email. If anything claiming to be from us asks for money in a new way, call the office at the number you’ve always used.

    That paragraph, in the newsletter and said out loud on a Sunday, prevents more harm than anything else on this page.

    What to ask the vendor, in writing

    Email support and keep the thread. You’re entitled to answers, and the written record matters later.

    • What specific categories of data about our organization and our members were involved?
    • Were passwords included, and were they hashed?
    • When did this happen, when was it discovered, and when were we told?
    • What has been fixed, and how do you know the attacker no longer has access?
    • Are you notifying affected individuals directly, or is that our responsibility?
    • Will you provide written notice we can share with our board and our insurer?

    That last one is not a formality. Your board will ask, and so may your insurance carrier.

    And two more for the next vendor, asked before you sign:

    “Do you support multi-factor authentication, and can we require it for every user?” Supporting it isn’t enough — you want to enforce it, including for volunteers.

    “If you have a security incident, what will you tell us, and how fast?” You’re listening for a specific commitment rather than reassurance. A vendor who has thought about this has an answer ready.

    Your own duty to notify

    This part needs care, and it needs a professional.

    Every state, plus the District of Columbia, Guam, Puerto Rico, and the Virgin Islands, has a law requiring notification when personal information is exposed. Those laws differ substantially — in what counts as covered information, in deadlines, in whether a state agency or attorney general must be told, and in what the notice has to say. Some reach nonprofits squarely; some don’t. And because your members may live in several states, more than one law can apply to a single incident.

    The general shape is this: a breach at your vendor may still create a notification obligation for you, because in most of these laws the duty follows whoever owns the relationship with the individual. The vendor may handle it. It may not. “They said they’d take care of it” is not a legal analysis.

    So do two things. Get the vendor’s position in writing, and ask a lawyer licensed in your state — one hour of somebody’s time, early. Your denomination, your insurance carrier, or your board may already have someone. This is not a place to guess, and it’s not something this article can decide for you.

    What to do this week

    Pick your two most sensitive systems — almost certainly your church management software and your giving platform. Log in to each, turn on multi-factor authentication, and look at the user list. Remove anyone who no longer serves, and reduce anyone with administrator rights who doesn’t need them.

    Then write down, on the same page as your other vendors, who to call at each company if something goes wrong.

    Twenty minutes per system, and you’ll have done more than most organizations do after an actual breach.

    MissionDefend’s free assessment covers exactly this ground — who has access to what, which accounts have a second factor, and how member data is handled — in plain English, and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, FTC says Blackbaud’s lax security allowed hacker to steal sensitive data; U.S. Securities and Exchange Commission, SEC Charges Software Company Blackbaud Inc. for Misleading Disclosures About Ransomware Attack; Federal Trade Commission, Data Breach Response: A Guide for Business; Federal Trade Commission, Did you get an email saying your personal info is for sale on the dark web?; Microsoft, mandatory multifactor authentication guidance.

  • The Blackmail Email Every Pastor Eventually Gets

    The Blackmail Email Every Pastor Eventually Gets

    It arrives at 11:40 on a Tuesday night, which is not an accident.

    The subject line is your own old password. Not a password you use now — one you recognize, from years ago, from an account you’d half forgotten. Seeing it sitting there in a subject line does something physical.

    The message says the sender has had access to your devices for months. It says a program on your computer turned on your camera and recorded you. It says there is a list of your contacts — your congregation, your board, your family — and that everything will go to all of them unless a payment in cryptocurrency arrives within 48 hours.

    If you are a pastor, an executive director, or a board chair, there is a good chance you have already received one of these, or will. And there is a very good chance you told no one.

    This article exists mostly for that second part.

    What the message actually is

    These emails are sent by the million. They are not written for you. Nobody selected you, studied you, or sat outside your house. A list of email addresses was purchased, a template was filled in automatically, and the send button was pressed on all of it at once.

    A typical one reads something like this:

    I know [password] is your password. I placed malware on an adult site you visited and it recorded you through your camera. I also copied your contact list. You have 48 hours to send $1,900 in Bitcoin to the address below. If you pay, I delete everything. If you tell anyone, I send it immediately.

    The FBI has been warning about this family of scam since at least 2016, when it published an alert on extortion emails tied to high-profile data breaches. A later alert describes the same tactic directly — messages claiming “I have a recorded video of you,” made more convincing by including “the recipient’s user name or password” taken from a breach.

    The New York State Police, warning residents about the same automated campaigns, stated the bottom line without hedging: despite these claims, the scammer does not have access to the victim’s device or personal information.

    Where the password came from

    This is the detail that makes the email feel real, and it has a boring explanation.

    A data breach is what happens when a company that stored your information gets broken into and that information is taken. Not your computer — theirs. A retailer, a forum, a fitness app, a hotel chain, a professional association, a church management platform. If you made an account there years ago, your email address and password were sitting in their database, and when that database was stolen, yours went with it.

    Those stolen databases get combined, resold, and eventually circulated freely. Millions of email-and-password pairs, sitting in files anyone can obtain.

    So the scammer’s software takes a line from one of those files, drops the password into a template next to the matching email address, and sends. That’s it. The password in your subject line is evidence of one thing only: that a company you once did business with was breached, probably a long time ago, possibly before you were in your current role.

    It is not evidence of a camera, or malware, or anyone watching anything.

    Some versions include your home address instead, or as well. Same explanation — addresses are in those same breached records, and in a hundred commercial marketing databases besides.

    The version with a photo of your house

    A newer variant, which the New York State Police specifically flagged, includes a photo of the recipient’s home.

    It is startling by design. It is also nothing more than an address run through publicly available street-level map imagery — the same pictures anyone can pull up of any address in the country, automatically, at scale. The photo proves the sender has your address. Your address is in the breached data. The chain ends there.

    Knowing that in advance takes most of the force out of it. That is the entire reason this section exists.

    What to actually do, in order

    Do not reply. Not to argue, not to deny, not to ask what they have. Any response tells an automated system that a live human read the message, and moves your address onto a much more valuable list.

    Do not pay, and do not negotiate. The FBI’s guidance on these schemes is explicit: do not communicate with the perpetrators, and do not pay the ransom, because the funds go on to finance further criminal activity. Payment also marks you as someone who pays, which is followed by another demand.

    Check the password. Go to haveibeenpwned.com — a free, long-established service that lets you enter an email address and see which known breaches it has appeared in. It will usually name the company and the year, which turns an unnerving mystery into a mundane fact you can look at.

    Change that password anywhere it is still in use. This is the one genuine action item in the whole episode. If the password in that email is still protecting your church email, your bank, your donor database, or anything else, change it today. Different password for every account — which in practice means a password manager, because nobody can hold forty of them in their head.

    Turn on multi-factor authentication on your email and anything financial. That’s the extra code or phone tap after the password. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. It means a stolen password on its own is no longer enough to get into anything, which is exactly the situation you want to be in the next time a database somewhere is breached — and there will be a next time.

    Report it. File at ic3.gov. The FBI asks that you include the email with its header information and the cryptocurrency address, and use the keyword “Extortion E-mail Scheme.” Your report takes five minutes and joins thousands of others that let investigators trace where the payments go.

    Then delete it and block the sender.

    The part that matters most: tell someone

    Here is the thing the scam is actually built on. Not malware. Not surveillance. The fear of being seen.

    The message is engineered around a specific instruction — don’t tell anyone — because isolation is the mechanism. A person who forwards the email to a colleague within ten minutes almost never pays. A person who sits with it alone at midnight sometimes does.

    For church and nonprofit leaders this pressure lands harder than it does on most people, and it’s worth saying why. Your role is bound up with your reputation in a way that an accountant’s isn’t. You have a congregation, a board, a family, and a sense that the position requires you to be beyond question. That’s precisely the leverage the sender is counting on — and they’re counting on it without knowing a single thing about you.

    So say it plainly, in a staff meeting or an elders’ meeting, before anyone receives one:

    If you get one of these, forward it to me or to [name] the same day. Nobody who receives one of these has done anything wrong. Everyone gets them.

    Say the last part out loud, because it is true and because the person who eventually needs it will not be in a state to work it out for themselves. Receiving a threatening email is not a moral event. It means an address of yours is on a list, along with tens of millions of others.

    If you lead an organization, receiving one yourself is a gift of a teaching moment. Mentioning it — briefly, matter-of-factly, without drama — at the next staff meeting does more to protect your people than any policy document. It tells them this happens to leaders too, and that the response here is a shrug and a report, not shame.

    If a threat is ever genuinely credible

    Almost all of these are bluffs. Not all threats are.

    If someone contacts you with something specific and real — an actual image, an actual private message, knowledge that could only come from an actual relationship — that is a different situation, and it is not one to handle alone or by paying.

    It is a matter for law enforcement, and for one trusted colleague or board member you tell immediately. Contact your local FBI field office or file at ic3.gov, and preserve everything: the messages, the account names, the timestamps. Do not delete, and do not pay. Paying an extortionist who genuinely holds something has never once ended the demands.

    And if the person being threatened is a minor, or if a minor is involved in any way, that goes to law enforcement immediately — not to an internal conversation first.

    The instinct in all of these cases is silence, and silence is the one thing that reliably makes it worse. Whatever the circumstances, a leader facing this should have at least one other person in the room.

    What to do this week

    Take the ten minutes: put your work email address into haveibeenpwned.com, see which breaches it turns up, and change any password from that list still in use. While you’re there, turn on multi-factor authentication for your email account if it isn’t already on.

    Then, at your next staff or board meeting, spend sixty seconds saying the sentence out loud — if you ever get a threatening email demanding payment, forward it to me the same day; everybody gets these and nobody is in trouble. That sentence is the whole defense, and it has to be said before it is needed.

    MissionDefend’s free assessment walks through the basics in plain English — how your organization handles email, donations, member data, and accounts — and hands back a baseline score with a ranked list of what to fix first. Password reuse and missing multi-factor authentication are usually near the top of that list, and they are usually the cheapest things on it to fix.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Extortion E-mail Schemes Tied to Recent High-Profile Data Breaches; FBI Internet Crime Complaint Center, Online Extortion Scams Increasing During The Covid-19 Crisis; New York State Police, New York State Police warns of nationwide automated sextortion scams; Microsoft, mandatory multifactor authentication guidance.