Home Articles Get your free assessmentComing soon

Tag: phishing

  • Anatomy of a Phishing Email: Eight Tells and What They Look Like

    Anatomy of a Phishing Email: Eight Tells and What They Look Like

    Phishing — the fake email built to make you click, log in, or pay — was the most-reported cybercrime in America again in 2025: 191,561 complaints to the FBI’s Internet Crime Complaint Center, more than any other category. It holds that title year after year for a boring reason: it keeps working.

    It keeps working partly because the training most people got is out of date. The old advice was “look for bad grammar and obvious typos.” CISA — the federal cybersecurity agency — now says plainly that generative AI has made well-written phishing routine. The clumsy Nigerian-prince era is over; the fakes are fluent now.

    What hasn’t changed is the structure. A phishing email has a job to do — create trust, create pressure, deliver a click — and the machinery for doing that job leaves the same fingerprints it always has. Here are eight of them, each shown the way it actually lands in a church office inbox. The examples are composites, not real messages, but every pattern in them is drawn from the attacks this series has already decoded.

    1. The display name that doesn’t match the address

    From: Pastor David Reeves ‹pastordavid.stmarks@gmail‑mail‑secure.com›
    Are you available? I need a favor handled discreetly.

    Email lets anyone put any name in the “From” line — the display name is decoration, chosen by the sender. The tell is the actual address behind it. On a phone, that address is hidden by default, which is exactly why so much phishing succeeds on phones: tap the sender’s name and read the real address before you believe anything else about the message. Your pastor’s real address you know. Everything else is a costume.

    2. Urgency with a deadline measured in hours

    Your mailbox will be deactivated in 4 hours. Verify now to avoid interruption.

    Legitimate organizations almost never need you to act within the hour, because nothing real works that way. Manufactured deadlines exist to keep you from doing the one thing that kills every scam: pausing to check. CISA lists urgent, consequence-laden language as the leading sign of phishing. When an email makes your chest tighten, that feeling is the payload.

    3. The mismatched link

    www.churchgivingportal.com/login

    The words of a link and its destination are two separate things — the blue text can say anything while pointing anywhere. On a computer, hover over the link without clicking and read the true address in the corner of the window. On a phone, press and hold to preview it. Watch for near-misses built to survive a glance: `rnicrosoft.com` (r-n masquerading as m), `yourchurch-give.com` instead of `yourchurch.org/give`, or a real brand name buried in front of an unrelated domain: `microsoft.security-check-portal.com`. The only part that matters is the last two pieces before the first slash.

    4. The login page you didn’t navigate to

    Your document is ready: OfferingReport_Q2.pdf — Sign in to view.

    The fake login page is where credentials actually get stolen. The email is just the ride there. The rule that beats it: a link you clicked in an email never gets a password. If a message says a document, invoice or voicemail is waiting behind a sign-in, close it and go to the service directly — type the address or use the app. If the document is real, it’s there. This habit also defeats attacks good enough to beat inspection, which some now are.

    5. A request that switches channels or demands secrecy

    Don’t call me, I’m going into the service. Just reply here.

    Real requests survive verification; fake ones must prevent it. So the message forbids exactly the act that would expose it — “don’t call,” “keep this between us,” “I’m unreachable.” We’ve seen this lever in the gift card scam, in payroll diversion, and in voice cloning. Treat any instruction not to verify as the confession it is.

    6. The attachment that needs something extra

    Invoice attached. If the document appears blank, click Enable Content to view.

    An attachment that requires you to click a button, enable macros, or install “a viewer” to read it isn’t a document with a problem — it’s a program wearing a document’s clothes. Modern office software disables that machinery by default precisely because it was the most common way malware got run. The email is asking you to overrule your own safety equipment.

    7. The reply-to that goes somewhere else

    From: finance@yourdenomination.org
    Reply-To: finance.office.desk@outlook.com

    Some phishing genuinely spoofs a trusted address in the “From” line — but the conversation has to route back to the attacker, and the hidden Reply-To field is where that happens. If you hit reply and the address in the compose window isn’t the one you thought you were talking to, stop. This is also why continuing an email thread is not verification: in business email compromise, the thread itself is the stolen property.

    8. Almost right, at the wrong moment

    Following up on the invoice from last month’s roof repair — updated remittance details attached.

    The most dangerous phishing contains no visible mistakes, because it’s built from real information: your actual roofer, a real project, plausible timing. The tell isn’t in the text — it’s in the event: money or credentials being requested with any change from the established pattern (new bank details, new payment method, new address, unusual quiet urgency). At that point the email’s quality is irrelevant, because your procedure — confirm changes by phone on a number you already have — doesn’t care how good the writing is.

    What to do this week

    Print these eight, tape them by the office computer, and spend ten minutes at the next staff meeting reading the examples aloud — people recognize patterns far faster from specimens than from rules. Then set the reporting habit: CISA’s guidance is recognize, resist, delete — and in an organization, “resist” means report it to whoever handles your email before deleting, so one alert reader protects everyone. Make the report thank-worthy, never eye-roll-worthy; the person who forwards a false alarm is your early-warning system working.

    And keep the fallback that underlies this whole series: when an email requests money, credentials, or account changes, the email itself is never the proof. Verification travels on a different channel — a phone number you already had, an address you typed yourself.

    The MissionDefend assessment checks whether your organization has these habits in place — reporting culture, verification rules, MFA — and gives you a prioritized plan for what’s missing. Join the launch list.


    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report (phishing/spoofing complaint count); Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing.

  • Smishing: Text-Message Scams Aimed at Church Staff

    Smishing: Text-Message Scams Aimed at Church Staff

    The text arrives on a Saturday, while the office is closed and the administrator is in the grocery store checkout line.

    USPS: Your package could not be delivered due to an incomplete address. Update your information within 24 hours: [link]

    She is expecting a package — the new children’s ministry curriculum, ordered Tuesday. The link looks vaguely official. She’s holding a phone in one hand and a gallon of milk in the other. This is precisely the moment the message was designed for.

    This is smishing — phishing carried out by text message. The name is a mash-up of SMS (the technical name for a text message) and phishing (tricking someone into clicking a link or giving up information by pretending to be someone they trust). Same con as the fake email, different doorway. And the doorway matters, because the phone in your pocket gets a level of trust and speed of response that email never did.

    Why texts work when emails fail

    Your email has a spam filter that has been learning for twenty years. Your text messages, for the most part, do not. A scam that would never survive the trip to your inbox lands on your lock screen untouched.

    The behavior around texts is different too. People answer texts fast — usually within minutes, often mid-task, standing up, one-handed. Nobody prints a text out and walks it down the hall to ask the treasurer if it looks right. And on a phone, the single best defense you have on a computer — hovering over a link to see where it really goes — mostly isn’t available. The screen is small, the address is shortened, and the browser hides the details.

    The scale of the problem is not small. The Federal Trade Commission reported that Americans lost $470 million to text-message scams in 2024 — five times the losses reported in 2020, even though the number of reports went down. Fewer people are falling for it; the ones who do are losing more.

    The five texts your staff will actually receive

    The FTC’s data names the five most common text scams by reported losses. Every one of them maps cleanly onto a week in a church office.

    The fake package notice. The most common of all. “Your delivery could not be completed.” A church office receives packages constantly — curriculum, supplies, communion cups, things five different volunteers ordered — so someone is always expecting a delivery. That’s what makes it work. The link leads to a page that harvests your address, your card number, or your login.

    The bogus job offer. Recruiting texts for part-time, work-from-home positions — sometimes called task scams, because they pay small amounts for trivial online tasks before demanding a deposit to “unlock” larger earnings. These circulate through congregations, and they sometimes borrow a real ministry’s name to look credible.

    The fake fraud alert. “Did you attempt a purchase of $487.23 at Best Buy? Reply NO to dispute.” There was no purchase. The reply — or the phone call that follows — is the scam. It ends with the “bank” walking the victim through moving money to a “safe account” that belongs to the attacker.

    The unpaid toll. A small, plausible amount — a few dollars — with a payment link and a late-fee threat. Small enough to pay without thinking, which is the entire design.

    The wrong number. “Hi, is this Jennifer? We’re still on for Tuesday?” It looks like a misdial. Replying politely starts a friendly conversation that, over weeks, becomes a relationship — and eventually an investment opportunity. This one costs its victims the most, and it targets exactly the demographic most churches serve.

    The church-office wrinkle

    For a business, smishing is a consumer problem that occasionally reaches payroll. For a church, it’s stickier, for one structural reason: the phone that receives the scam is almost never a device the organization controls. It’s the administrator’s personal phone, the volunteer treasurer’s personal phone, the youth director’s personal phone — carrying church email, the giving platform app, and the group chat with every leader in it.

    That means you cannot solve this with software. There is no filter you can buy for a phone you don’t own. What you can change is the procedure — what a person does in the ten seconds after the message lands.

    What to do this week

    Adopt the two-line text policy. Say it at the next staff meeting, put it in the volunteer handbook, and have leadership repeat it until it’s folklore: We never handle money, passwords, or account changes by text. If a text asks for any of those, it’s fake until proven otherwise by a phone call to a number we already have. That single rule defeats every scam on the FTC’s list, because every one of them needs the text itself to carry the action.

    Teach the app-not-the-link habit. If a text claims to be your bank, the postal service, or a toll authority, the response is never the link in the message — it’s opening the official app, or typing the address you already know. If the alert is real, it will be waiting there.

    Report, then delete. Forward scam texts to 7726 — that spells SPAM on a keypad — which helps carriers block similar messages for everyone. Then report it at ReportFraud.ftc.gov, and delete it. Don’t reply, not even “STOP,” to a message you believe is a scam; a reply confirms the number is live.

    Warn the congregation once a season. A single line in the bulletin or newsletter — the church will never text you asking for gift cards, payments, or personal information — protects the people your staff can’t. The wrong-number romance scam in particular preys on older adults, and a warning from a trusted pulpit lands where a news story doesn’t.

    Smishing is the same social engineering we covered on day one of this series — persuasion instead of hacking — squeezed into 160 characters. The persuasion doesn’t survive a pause and a phone call. Build the pause into the routine.

    Want to know where your organization actually stands? MissionDefend’s free assessment asks plain-English questions about how your church handles email, texts, donations and member data, then gives you a prioritized plan. Join the launch list and be first in line.


    Sources: Federal Trade Commission, New FTC Data Show Top Text Message Scams of 2024; Overall Losses to Text Scams Hit $470 Million (April 16, 2025); Federal Trade Commission, How To Recognize and Report Spam Text Messages; Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing.

  • The Package Nobody Ordered: Brushing Scams and the QR Code in the Box

    The Package Nobody Ordered: Brushing Scams and the QR Code in the Box

    It’s a Tuesday, and there’s a box on the counter in the church office.

    Nobody remembers ordering it. It’s addressed to the church, correctly, with the right street number and the right suite. Inside is a phone case in a color nobody would choose, or a set of silicone kitchen rings, or a keychain flashlight — something cheap, sealed in plastic, with no packing slip and no invoice.

    There is one other thing in the box: a small printed card.

    Thank you for your order! Scan the QR code below to see who sent this gift and claim your free item.

    The volunteer who opens the mail on Tuesdays holds up her phone, taps the camera, and the code resolves into a link.

    That is the whole attack. It took nine seconds, and nothing about it felt like an attack.

    What a brushing scam actually is

    Start with the original version, because it explains why the box exists at all.

    A brushing scam is a fake-review scheme. A seller on a large marketplace wants better ratings, so they ship a cheap item to a real name at a real address — pulled from a data set they bought or scraped — and record it as a completed sale. Then they write a glowing review in that person’s name. Because a package genuinely shipped and genuinely arrived, the platform marks it a “verified purchase,” which is exactly the label shoppers trust most.

    The US Postal Inspection Service describes the goal plainly: the packages are sent so as “to give the impression that the recipient is a verified buyer who has written positive online reviews.”

    For years that was the end of it. Annoying, faintly creepy, mostly harmless to the recipient. You kept the phone case.

    The new part: the card with the QR code

    The scheme has been repurposed, and the second version is not harmless.

    A QR code — short for Quick Response code — is that square pattern of black and white blocks. Your phone’s camera reads it and turns it into a web address, then usually offers to open it. It is a link with the letters hidden.

    In the current variant, the package contains a card with a QR code and a reason to scan it. Scan to see who sent this. Scan to register your gift. Scan for a free item. Scan to leave a review. The code leads to a page that either asks for information — name, address, card number, or a username and password for an account you already have — or prompts you to install an app that gives an attacker access to the phone.

    That is phishing: a message built to look like it comes from someone you’d trust, designed to get you to hand over information or install something. When the bait is a QR code rather than a link in an email, the security world calls it quishing. The Postal Inspection Service now names this pattern directly, warning that “cards with QR codes are being sent inside packages as a part of brushing scams.”

    The FBI issued a public service announcement about it on 31 July 2025 — PSA I-073125-PSA, Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes. The Bureau’s description: criminals “send unsolicited packages containing a QR code that prompts the recipient to provide personal and financial information or unwittingly download malicious software.” The Federal Trade Commission flagged the same thing in a consumer alert in January 2025, noting that scanning “could take you to a phishing website that steals your personal information, like credit card numbers or usernames and passwords,” or “download malware onto your phone.”

    Three government bodies describing the same box. That’s about as verified as a threat gets.

    And a QR code is worse than a link in an email, for two reasons, neither of them technical.

    It hides where it goes. In an email you can hover over a link and see the address it leads to. You can notice that “your bank” is actually a string of nonsense followed by .ru. A QR code shows you nothing. It’s a picture. By the time the address appears, it’s in a small gray bar at the top of a browser window that has already loaded the page.

    It moves the attack onto a personal phone. Nobody scans a QR code with the church’s desktop computer. They scan it with the phone in their pocket — a device the organization doesn’t own, doesn’t manage, and can’t inspect. Whatever protections your email system has, they aren’t in the room for this. And a credential typed into a fake login page on a phone — a username and password — works just as well for an attacker as one typed on a laptop.

    This is a different problem from the one where an attacker sticks a fraudulent sticker over the QR code printed in your Sunday bulletin. That’s a code your church published, replaced. This is a code that arrived at your church uninvited.

    Why a church office is close to an ideal target

    Here is the part that makes this specifically your problem.

    Unexpected packages are normal at a church. At a house, a box you didn’t order is strange, and that strangeness is the one instinct protecting the average consumer. At a church, boxes arrive constantly — VBS curriculum, communion supplies, replacement bulbs, a case of coffee, something a small group leader ordered on the ministry card three weeks ago, a donated item somebody mailed in. Five different people can order things, and none of them tells the office. An unaccounted-for package doesn’t raise a flag because there is no baseline to raise it against.

    The person opening the mail is rarely the person who got the training. Mail-opening lands on a volunteer, a part-time administrator, or whoever is at the desk that morning. They’re helpful by disposition — that’s why they’re there. Solving the mystery of a strange package by scanning the code that offers to solve it is the natural, generous, competent-seeming thing to do.

    There’s no policy to violate. Nobody has ever written down what to do with an unexpected box, because until recently there was nothing to write.

    Churches are easy to research. Your address, your staff names, and often their email addresses are on your website. That is all the data set a brushing operation needs.

    It’s a symptom, not just an incident

    Even if nobody scans anything, the package tells you something.

    The USPIS point is worth taking seriously: “scammers obtain personal information through nefarious means.” The box arrived because your organization’s details are sitting in somebody’s list. Not necessarily from a breach of your systems — far more often from a vendor, a mailing list, a directory, or a public filing. But circulating, in the hands of people running fraud schemes.

    If the package was addressed to the church generally, that’s your organizational data. If it was addressed to a named staff member at the church address, that person’s details are circulating too — and the same list is likely being used for email and phone attacks that will arrive later and won’t come in a box.

    Treat it as a prompt, not an emergency. Two things are worth doing: confirm that multi-factor authentication is turned on for church email and any financial accounts, and mention to the named staff member that they may want to watch their own accounts for a while. That’s it. No panic required.

    What to tell your older members

    This lands hardest at home, and hardest on the people least likely to have anyone to ask.

    The FBI’s 2025 Internet Crime Report logged 201,266 complaints from victims aged 60 and over, with losses totaling $7.748 billion — losses up 59% in a single year, and averaging $38,500 per report. Those are the figures for all internet crime, not brushing alone, but the direction tells you who is being worked hardest right now.

    A church is one of the very few institutions that can warn that age group and actually be believed. Not a bank’s form letter, not a news segment. A line in the newsletter and a sentence from the front on a Sunday morning:

    If a package arrives that you didn’t order, don’t scan any code inside it. You can keep the item — you’re not obligated to pay for it. But the card with the QR code is the scam, and scanning it can hand over your accounts. If it happens, tell the office and we’ll help you sort it out.

    That last sentence matters more than the rest. People who have been caught by something like this tend to go quiet out of embarrassment, and the quiet is what turns a small problem into a big one.

    If you can’t identify what’s inside

    One physical-safety note the Postal Inspection Service raises, and it’s short.

    If an unsolicited package contains organic material — seeds, plant matter, food — or a substance you cannot identify, don’t handle it, don’t open it further, and don’t throw it in the trash. Set it down and report it. The Postal Inspection Service takes these reports, and unsolicited seed shipments in particular have been the subject of federal and state agricultural warnings. This is rare. It costs nothing to know.

    For an ordinary unwanted package, you’re within your rights to keep it or discard it. If it’s unopened, you can mark it “RETURN TO SENDER” and hand it back to the carrier. You are never obligated to pay for something you didn’t order.

    What to do this week

    Add one line to whatever passes for your mail routine. Say it out loud to whoever opens the mail, and write it on a sticky note on the mail table if that’s what it takes:

    If a package arrives that nobody can account for, don’t scan anything inside it. Set it aside and ask.

    Ten seconds to say. It closes the entire category, because it doesn’t require the volunteer to judge whether a particular card looks legitimate — only to notice that nobody ordered the box.

    Put four sentences in the next newsletter warning members about unexpected packages and the codes inside them. Use the language above. Aim it at the people in your congregation who live alone and get few visitors, because they’re the ones for whom a surprise package is a small bright spot rather than a question.

    Fifteen minutes, total, and no budget.

    If someone did scan a code and enter a password, treat it like any other stolen credential: change that password immediately from a different device, sign out of all sessions, turn on multi-factor authentication, and watch the account. If money moved, report it to the FBI at ic3.gov the same day — speed is most of what determines whether funds can be frozen. If personal information was entered, identitytheft.gov walks through the recovery steps.

    MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including the small physical habits like this one — and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: US Postal Inspection Service, Brushing Scam; FBI Internet Crime Complaint Center, Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes, I-073125-PSA; Federal Trade Commission, Scam alert: QR code on an unexpected package; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Social Engineering: Why Attackers Target Your People, Not Your Firewall

    Social Engineering: Why Attackers Target Your People, Not Your Firewall

    The email arrived at 8:52 on a Tuesday morning. It was from the pastor — his name, right there in the sender line — and it was short.

    Are you at your desk? I need you to handle something for me. I’m in a meeting so I can’t take calls.

    The office administrator wrote back that yes, she was at her desk. What did he need?

    Nothing about that exchange involved breaking into anything. No password was cracked. No virus was installed. No firewall was bypassed. And yet, ninety minutes later, the church was out $1,800 in gift cards.

    This is social engineering, and it is the single most common way churches and nonprofits lose money and data. Not because your organization is careless. Because it is the way the overwhelming majority of attacks now work, everywhere, and because the things that make a ministry good at being a ministry are the same things that make social engineering effective.

    What “social engineering” actually means

    The phrase sounds like jargon, and it is — but the idea underneath it is simple.

    Social engineering is persuading a person to do something, rather than forcing a computer to do it.

    That’s the whole definition. An attacker who breaks encryption is doing technical work. An attacker who convinces your bookkeeper to change a vendor’s bank details is doing social work. The second is dramatically easier, dramatically cheaper, and requires no special skill beyond patience and a plausible story.

    It helps to think of it the way you’d think about a con artist in any other era. The technology is new. The technique is not. Someone is establishing a reason you should trust them, creating a situation where checking feels rude or slow, and asking for something that seems small in the moment.

    You’ll see a lot of specific names for these attacks, and the vocabulary can feel like a wall. Here is the map, in plain terms:

    Phishing is social engineering delivered by email — a message designed to get you to click, log in, or reply. The name is a play on “fishing,” because early versions cast a wide net and waited.

    Spear phishing is the same thing aimed at one specific person, using details about them. A spear instead of a net.

    Vishing is voice phishing — the scam arrives by phone call.

    Smishing is SMS phishing — it arrives by text message.

    Pretexting is the invented backstory that makes the request feel routine. “I’m calling from your insurance carrier about the annual audit” is a pretext.

    Business email compromise, usually shortened to BEC, is the category where someone impersonates a leader or a vendor to redirect a payment.

    Every one of those is a flavor of the same thing. Someone is talking to a human being and asking them to act.

    The numbers, and why they matter to a small office

    It’s tempting to read all this and assume it’s a problem for banks. The federal data says otherwise.

    The FBI’s Internet Crime Complaint Center — the government’s clearinghouse for reported cybercrime, usually called IC3 — logged 1,008,597 complaints in 2025, with just under $20.9 billion in reported losses. Within that, phishing and spoofing generated 191,561 complaints, making it the single most-reported crime type in the country.

    Business email compromise accounted for 24,768 complaints and more than $3 billion. Divide those out and the average reported loss per BEC report was about $123,005.

    Now hold that number against a church budget. For most congregations, a single successful impersonation email costs more than a quarter’s giving. And note what didn’t appear anywhere in that description: malware, hacking tools, technical sophistication. It required someone to believe an email.

    There’s one more figure worth sitting with, because it touches your congregation rather than your office. IC3 recorded 201,266 complaints from victims aged 60 and over in 2025, with $7.748 billion in losses — a 59% increase over the prior year, and an average loss of $38,500 per victim. The people in your pews are being targeted, and many of them will hear about it from you before they hear about it from anyone else.

    The six levers

    Every social engineering attack pulls on at least one of six psychological levers. Once you can name them, you start noticing them, and noticing is most of the defense.

    Authority. The request appears to come from someone you don’t question — the pastor, the executive director, the board chair, the bank, the IRS. Authority short-circuits the instinct to verify, because verifying feels like doubting your boss.

    Urgency. There’s a deadline, real or invented. Before noon. Before the wire cutoff. Before the account is suspended. Urgency exists to prevent you from doing the one thing that would defeat the attack: pausing.

    Familiarity. The message uses the right names, the right tone, the right details. It mentions the building project by name. It knows your treasurer is called Deb, not Deborah. Familiarity is why these messages feel real — and it’s cheap to manufacture, because your staff page, bulletin, Facebook posts, and public filings are all free research material.

    Fear. Something bad will happen. Your mailbox will be deleted. Your account is compromised. There’s a legal problem. Fear narrows attention to the threat and away from the oddities in the message.

    Curiosity. An unexpected invoice. A shared document. A photo from the retreat. Curiosity is the lever behind most malicious attachments, because opening something to find out what it is feels harmless.

    The wish to be helpful. This is the one that matters most in ministry, and the one nobody wants to hear. Churches and nonprofits are staffed by people whose whole disposition is to help quickly, assume the best, and not interrogate someone who asks for something. That disposition is a virtue. It is also, precisely, the surface an attacker aims at.

    That last point deserves care. The lesson is not that your team should become suspicious of everyone. A congregation that treats every request as a threat has lost something more valuable than the money. The lesson is narrower and much more manageable: for a very small number of specific actions, verification becomes automatic and impersonal — not a judgment about the person asking, just the way that particular thing is always done.

    Why small organizations get chosen

    Three structural facts make churches and nonprofits attractive, and none of them are about carelessness.

    You hold valuable, irreplaceable data. Donor giving histories, member contact lists, background check results, counseling notes, children’s ministry records. Some of it has resale value. Some of it is simply devastating if it becomes public.

    Your money moves in ways that are hard to verify. Offerings, designated gifts, benevolence funds, reimbursements, contractor payments during a building project. Transaction volume is low enough that one fraudulent payment doesn’t stand out, and approval processes are usually informal because the team is small and trusts each other.

    And your information is public by design. A business hides its org chart. A church publishes it — with photos, titles, email addresses, and often direct phone numbers — because that’s how people find their pastor. An attacker doesn’t need to breach anything to learn who your finance person reports to.

    What actually stops it

    Because the attack targets people, the defense has to work at the level of people. Three things carry most of the weight, and none cost money.

    One rule, written down, about money. Any request to move funds, change bank details, or buy gift cards is verified by voice, using a phone number you already had — not a number in the message. Not by replying to the email. The attacker controls the email thread; they do not control the number in your directory. Write this rule down, tell everyone who touches money, and state plainly that nobody will ever be criticized for following it. The failure this prevents is a bookkeeper who feels too junior to question leadership.

    Permission to be wrong. The most expensive incidents are not the ones where someone got fooled. They’re the ones where someone got fooled and then waited three days to say so, hoping it would resolve itself. A misdirected payment caught in twenty minutes is often recoverable — the FBI’s Recovery Asset Team froze over $507 million across 3,574 domestic cases in 2025, and that process depends almost entirely on speed. The same mistake caught on Friday afternoon usually is not. Tell your team, in words, that reporting a mistake immediately is the desired behavior and will never be held against them.

    Fifteen minutes, twice a year, on real examples. Not an hour-long generic video. Show your actual staff the actual scams aimed at churches: the gift card request, the fake invoice from a vendor you really use, the “your mailbox is full” notice. Recognition is trainable. Familiarity with the specific shape of these messages is what makes someone pause.

    The rest of this series

    Over the coming weeks we’re going to take these apart one at a time — the gift card scam, business email compromise, payroll diversion, phone and text scams, AI voice cloning, and the rest. Each post explains one attack in plain language, shows what the message actually looks like, and ends with what to do about it.

    The goal isn’t to make you afraid of your inbox. It’s to make these attacks boring — familiar enough that when one arrives, someone on your team recognizes the shape of it and doesn’t have to guess.

    What to do this week

    Pick one thing. Write down the verify-by-voice rule for money requests, send it to everyone who touches a payment, and say explicitly that following it is never rude. That single paragraph, circulated once, closes the most expensive category of attack aimed at organizations like yours.

    MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts, then give you a baseline score and a ranked list of what to fix first. It’s launching soon — leave your email and we’ll tell you the moment it opens.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report.