The giving QR code is on the back of the bulletin, on the screen during announcements, on the laminated card in each pew rack, and on the poster by the door — because it works. Point a phone at the square, the giving page opens, and the awkwardness of passing a plate past a visitor is gone.
Now consider what that square actually is. A QR code — the name stands for quick response — is a web address printed as a pattern a camera can read. That’s all. And its defining feature is the problem: a human being cannot read it. You can proofread every word of the bulletin, but you cannot proofread the code. A square that sends the congregation to your giving platform and a square that sends them to a scammer’s copy of it look identical from across the room, and nearly identical from six inches.
The FBI warned about exactly this in a public service announcement back in January 2022: criminals “tamper with both digital and physical QR codes,” swapping legitimate ones for their own to steal credentials and payments. The FTC followed in December 2023 with the consumer version, describing the physical trick already common on parking meters — a scam sticker printed and stuck over the real code.
A parking meter and a pew card have a lot in common. Both sit unattended in a public place. Both are trusted by the person scanning. And both are asking for money.
The two directions the swap happens
On paper, with a sticker. Someone prints their own code on adhesive labels — a task that takes ten minutes and costs nothing — and applies them to the lobby poster, the pew cards, the yard sign for the capital campaign. The fake destination is a page that looks like your giving platform: same logo, lifted from your website; same colors; a form that takes card numbers. Sunday’s gifts flow to an account you’ve never heard of, and the failure is invisible until someone asks why online giving dipped.
Upstream, in the file. The subtler version never touches your building. It compromises the source of the code: the shared Canva account a volunteer uses for slides, the email thread where the bulletin file gets passed around, the church email account of whoever assembles it. Change the code in the master file once, and the church then prints, projects and distributes the fraud itself, every week, with its own hands.
And to complete the picture: this scam also arrives at the church from outside — unsolicited packages with “scan to see who sent you this gift” cards, which we covered in the brushing scam. Same square, opposite direction. Today’s post is about the codes you publish.
Why nobody notices
Nobody checks the destination. On a phone, the preview that appears when you scan shows a URL for a moment — but giving platforms have long, forgettable addresses full of subdomains ( `yourchurch.givingvendor.com`, `app.vendor.com/give/12345` ), so the congregation has no memory of what the right address looks like. The FTC’s advice — inspect the URL for misspellings before opening — assumes you know what correct is. Most givers don’t.
That’s not a reason to abandon the codes. It’s the design constraint: the safeguards have to live with the people who publish the code, because the people who scan it can’t be expected to catch anything.
What to do this week
Put the giving address into human memory. Pick the shortest true form of your giving URL and print it next to every code, every time: “Scan, or visit yourchurch.org/give.” That one habit does three jobs: givers who prefer typing never scan at all; anyone who scans can compare what opened against what’s printed; and a swapped sticker now has to fake two things that must agree. A code with no readable address beside it is asking the congregation to trust ink they can’t read.
Make one person the owner of the square. Not a committee — a name. That person generates the code (directly from the giving platform, not from free third-party QR generator sites, which can route through tracking domains you don’t control), keeps the master graphic in one place, and is the only source others copy from. Every “just grab the code from last month’s file” is a link in a chain nobody is watching.
Add the codes to a monthly walk-through. First Sunday of the month, someone scans every published code in the building — pew cards, posters, yard signs, the slide deck — on their own phone and confirms each lands on the real page. It takes five minutes. While they’re at it: run a fingernail over printed codes. A sticker over ink has an edge you can feel. That’s the FBI’s tampering warning turned into a chore anyone can do.
Watch the money like a control, not a report. Whoever reconciles giving should treat an unexplained dip in online gifts as a security signal worth a same-week look, not a trend to discuss at the quarterly meeting. In the sticker version of this scam, the finance spreadsheet is the only alarm that ever goes off.
Tell givers the one rule that survives everything. In the bulletin, once a season: our giving page is yourchurch.org/give — if a code ever takes you anywhere else, close it and tell the office. You’re not teaching the congregation to distrust the plate. You’re giving them the same gift every post in this series comes down to: a known-good channel to fall back on.
The QR code turned your congregation’s generosity into a single point of failure. It can stay — it should stay — but it graduates from decoration to infrastructure. Infrastructure gets an owner, a checklist, and an alarm.
The MissionDefend assessment asks who owns your giving links, who can edit what gets printed, and whether anyone would notice a swap — along with the rest of your baseline. Join the launch list.
Sources: FBI Internet Crime Complaint Center, Cybercriminals Tampering with QR Codes to Steal Victim Funds, Alert I-011822-PSA (January 18, 2022); Federal Trade Commission, Scammers hide harmful links in QR codes to steal your information (December 6, 2023).


