Home Articles Get your free assessmentComing soon

Tag: social engineering

  • Vishing: When the Scam Comes by Phone

    Vishing: When the Scam Comes by Phone

    The phone in the church office rings at 2:40 on a Wednesday. The screen says FIRST NATIONAL BANK.

    The caller is calm and slightly bored, the way people sound when they do this all day. There’s been unusual activity on the church’s account — two attempted transfers this morning, both declined. He needs to confirm he’s speaking with an authorized signer before he can discuss details, and then he’ll need to verify a code that’s about to be texted to the number on file, so the fraud hold can be lifted.

    Everything about that call is false, including the name on the screen.

    Email scams get most of the attention, and reasonably so. But phone-based attacks have a particular power that email doesn’t: a live human being, responding in real time, adapting to whatever you say. There’s no time to reread. There’s no forwarding it to a colleague. Social pressure operates the way it does in any conversation — hanging up on someone feels rude in a way that deleting an email never does.

    What vishing means

    Vishing is short for voice phishing — the same persuasion attack you’ve read about in this series, delivered by phone call instead of email.

    The goal is one of three things: get you to reveal a credential (a password, or more often a one-time code), get you to move money, or get you to install something on a computer.

    The name is jargon, but there’s nothing exotic underneath. Someone calls with an invented reason to be calling, and asks you to do something.

    Your caller ID is not evidence

    This is the single most important technical fact in this post, and most people have never been told it plainly.

    The number and name shown on your phone are supplied by the caller. They are not verified by anyone.

    When a call is placed, the caller’s system includes the number it wants displayed. Historically, the phone network passed that along without checking it. That’s how legitimate systems work too — it’s why a call from a hospital’s back office can display the hospital’s main switchboard number, and why your church’s outgoing calls can all show the office line rather than whichever extension dialled.

    That same flexibility is what lets an attacker display your bank’s actual customer service number, or your denomination’s regional office, or — and this happens — your own church’s number, calling a member of your congregation.

    The FCC describes caller ID spoofing as scammers falsifying the number that appears on your display in order to “trick Americans into answering their phones when they shouldn’t.”

    There is a countermeasure, and it’s worth understanding both what it does and what it doesn’t.

    STIR/SHAKEN is a caller ID authentication framework that US carriers are required to implement. In plain terms: the phone company that originates a call digitally “signs” it, and the companies that carry it onward can verify that signature. It’s the reason your phone sometimes displays “Caller Verified” or a similar label.

    What it does not do is guarantee that an unlabelled call is fake, or that a verified call is trustworthy. Verification confirms the call really came from the number shown — not that the person on the line is honest. Plenty of legitimate calls arrive unsigned, particularly from smaller carriers and internet-based phone systems. Treat it as weak supporting evidence, not proof.

    The practical takeaway for your staff: the name on the screen tells you nothing about who is actually calling.

    The versions aimed at ministries

    The bank fraud department. As above. The prize is usually a one-time code — the six digits your bank texts you. The caller creates a reason you’d expect to receive one, then asks you to read it out. That code is the second factor protecting your account; handing it over hands over the account.

    The IT helpdesk. “I’m calling from the company that supports your Microsoft 365 — we’re seeing sync errors on your mailbox.” The ask is either your password or permission to install a remote access tool so they can “take a look.” This one succeeds in small offices because the staff genuinely don’t know exactly who supports their systems.

    The utility shutoff. Aggressive, deadline-driven, aimed at the office administrator: the church’s power will be cut this afternoon unless an overdue balance is paid immediately, usually by prepaid card or transfer. Real utilities don’t operate this way.

    The denominational or grant office. More targeted. Someone who knows your affiliation calls about a compliance filing, an insurance audit, or a grant disbursement, and needs bank details or staff information to proceed.

    The follow-up call after an email. Increasingly common, and effective. An email arrives requesting a payment change; then a call arrives “confirming” it. Two channels agreeing feels like verification. It isn’t — the attacker controls both.

    The call to your congregation. Your church’s number is displayed, and an elderly member is told there’s a problem with their giving record, or that the church is collecting for an emergency. This one damages trust you spent decades building.

    Why it works on good people

    Live conversation removes the two things that protect you in email: time, and the ability to reread.

    A skilled caller uses authority (a title, an institution), urgency (a hold that expires, a shutoff today), and plausibility (they already know your pastor’s name, your bank, your address — all public). They may also use reciprocity, doing you a small favour first: “I’ve placed a temporary hold on the account for you, that’ll protect you while we sort this out.”

    And they exploit ordinary manners. Ending a call abruptly on a polite, professional-sounding person feels aggressive. Most people would rather stay on the line and be uncomfortable.

    That instinct is the thing to override, and the way to override it is not to make your staff ruder. It’s to give them a script that isn’t rude at all.

    The habit that defeats all of it

    One rule. It handles every variant above without anyone having to judge whether a particular call sounds legitimate:

    Hang up and call back on a number you already had.

    Not the number the caller gives you. Not the number that appeared on your screen — that’s the one that can be faked. The number on the back of your bank card, on a previous statement, in your contacts, on the signed contract, on the utility’s official website.

    The polite version, which anyone can say without confrontation:

    “I’m not able to discuss account details on an inbound call. Let me call you back on the number we have on file.”

    A legitimate caller from any real institution will not object to that. Fraud departments in particular expect it — it’s exactly what they train their own customers to do. A caller who pushes back, who explains why calling back won’t work, who says the case number will expire, has just identified themselves.

    Two absolute rules to teach alongside it, with no exceptions:

    Never read a one-time code to anyone on the phone. No bank, no vendor, no IT provider, no denominational office will ever ask you to. The entire purpose of that code is to prove you are present. Reading it aloud defeats it completely. Most banks now print this warning in the text message itself.

    Never install software or grant remote access because of an incoming call. If someone needs to see your screen, that arrangement is made through a relationship you initiated.

    Prepare before it happens

    Write down who actually supports you. A single sheet: your bank’s real fraud number, your IT support’s real number, your payroll provider, your insurer, your denominational contact. Print it. Put it where the phone is. Most vishing succeeds because the person answering genuinely doesn’t know who legitimately calls them, and searching for a number under pressure is when people click the wrong result.

    Extend the money rule to phone calls. The verification rule from earlier in this series — no payment change without a callback — applies identically to requests that arrive by voice. Write it that way so nobody wonders whether the phone is different.

    Give people permission to hang up. Say it out loud in a staff meeting: “If a call feels off, end it. You will never be in trouble for hanging up on someone, even if it turns out to be legitimate. We’ll sort it out.” Without that explicit permission, junior staff and volunteers will stay on the line out of politeness.

    Warn your congregation. Include a line in the newsletter: the church will never call you asking for payment, gift cards, or account details. Older members are being targeted heavily — the FBI logged 201,266 complaints from victims aged 60 and over in 2025, totalling $7.748 billion, up 59% in a single year.

    Run one practice call. Ask a board member to call the office pretending to be the bank. Ninety seconds, at a staff meeting. People remember doing it in a way they do not remember being told about it.

    If someone already gave something up

    If a one-time code was shared: change that account’s password immediately from a different device, sign out all active sessions, and call the institution’s real fraud line. Assume the account was accessed.

    If remote access was granted: disconnect that computer from the network — unplug the cable, turn off Wi-Fi — but don’t wipe it. Get someone technical to look at it before it goes back into use.

    If money moved: call your bank’s fraud line before doing anything else, then report to the FBI at ic3.gov. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process depends almost entirely on speed.

    In every case, tell someone immediately. The pattern that turns a contained mistake into a serious loss is a person who is embarrassed and waits.

    What to do this week

    Make the one-page contact sheet — bank fraud line, IT support, payroll, insurer — and tape it up next to the office phone. Then, at your next staff meeting, say the sentence out loud: nobody will ever be in trouble for hanging up and calling back.

    That’s fifteen minutes, and it closes the whole category.

    MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then gives you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Communications Commission, Combating Spoofed Robocalls with Caller ID Authentication; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Payroll Diversion: The Email That Steals Someone’s Paycheck

    Payroll Diversion: The Email That Steals Someone’s Paycheck

    Most of the attacks in this series steal from the organization. This one steals from a person on your staff — and they usually don’t find out until payday, when the money simply isn’t there.

    The email goes to whoever handles payroll. It appears to come from a staff member:

    Hi Karen — I’ve switched banks. Could you update my direct deposit before Friday’s run? New details attached. Thanks!

    That’s it. No urgency theatre, no drama. Just an administrative request of a kind that arrives legitimately several times a year.

    Karen updates the record. On Friday, that staff member’s entire paycheck lands in an account controlled by a stranger, and the person who earned it opens their banking app to find nothing.

    Why this one hurts differently

    It’s worth naming the human dimension before the technical one, because it changes how you should respond.

    When BEC takes $40,000 from the church, the organization absorbs a loss. When payroll diversion succeeds, an individual — often someone on a modest church salary — misses rent. And there’s frequently no clean answer about who makes them whole. The employer may not be legally obliged to pay twice. The bank may not recover it. The person did nothing wrong at all; they were simply impersonated.

    That’s why this deserves its own attention rather than being folded into general invoice fraud. The victim is a colleague, and the fallout is personal.

    The two ways in

    The impersonation route. The attacker sends from an outside address with the staff member’s name as the display name — the friendly label your mail app shows instead of the actual address. It’s free text; anyone can set it to anything. On a phone, where the real address is hidden entirely, the message looks exactly like it came from your colleague.

    The account takeover route. More dangerous and, according to FBI advisories, the common pattern. The staff member is phished first — they receive a message that looks like it’s from the payroll provider or the IT helpdesk, follow a link to a convincing but counterfeit login page, and type in their credentials. Now the attacker has a genuine account, and the request to change direct deposit comes from the real address, in a real thread, from a real person’s mailbox.

    In the takeover version, attackers commonly do something that makes this much worse: they disable change notifications. Most payroll systems email the employee when their banking details are updated. The attacker turns that off first, which is why the theft goes unnoticed until payday rather than within the hour.

    They also frequently add a mail rule that quietly files any message containing “payroll,” “direct deposit,” or “deposit change” into an unread folder, so the employee never sees the confirmation even if one slips through.

    The FBI has warned about this pattern since 2018, noting that attackers use stolen credentials to access the employer’s HR system, replace the employee’s banking information, and then suppress the alerts. The Bureau’s guidance to employers is direct: require separate credentials for payroll systems, use two-factor authentication, and establish protocols requiring extra approval for banking change requests.

    What makes a church or nonprofit vulnerable

    Payroll is often one person’s job, done in a hurry. There’s no HR department. The office administrator handles payroll alongside facilities, bulletins, and the phone. A one-line request that takes ninety seconds to action gets actioned.

    Direct deposit changes are genuinely routine. People do switch banks. Requests like this arrive legitimately, which means there’s no natural suspicion attached to the category.

    Staff email addresses are public. Your staff page lists them. An attacker can determine who does payroll and who to impersonate without any access at all.

    The window is predictable. Payroll runs on a schedule. An attacker who knows you pay on the 15th and the last day of the month knows exactly when to send, and exactly how long they have before anyone notices.

    The control that stops it

    One rule, and it mirrors the one for vendor payments:

    No banking change is ever actioned from a written request alone. The person is called back on the number already in their personnel file, and asked to confirm.

    The details matter.

    Called back — you initiate the call. Don’t accept a number supplied in the request, and don’t accept a call from someone claiming to be the employee. The direction of the call is the control.

    The number already on file — from the personnel record, not the message signature. If your only number for them is one they gave you recently by email, that’s worth fixing.

    Confirm the specifics — read the last four digits of the new account number aloud and ask them to confirm. Don’t ask “did you request a change?” A yes-or-no question invites a yes from someone who isn’t listening carefully.

    Two additions worth making. Impose a deliberate delay — banking changes take effect on the next payroll run, not this one. Attackers depend on a change landing before the next payday; a one-cycle lag removes the whole business model. And notify the employee through a second channel whenever their details change — a text or a call, not just an email, because the email may be sitting in a folder the attacker created.

    Hardening the systems

    Multi-factor authentication on email and the payroll portal, separately. This is the extra code or tap after the password. It’s the single control that defeats the account-takeover route, and it’s free on Microsoft 365 and Google Workspace. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Make sure your payroll provider’s portal has it enabled too — it’s often a separate setting that nobody has turned on.

    Use different credentials for payroll. If your payroll login is the same password as your email, one phishing success gives away both. This is exactly the FBI’s recommendation.

    Turn change notifications back on, and check they’re on. Then verify quarterly that they haven’t been switched off. In the payroll system, confirm that alerts go to an address the employee controls and, ideally, to a second person in the office.

    Audit mail rules. Once a quarter, in each staff mailbox, look at the forwarding rules and filters. A rule nobody remembers creating — especially one that files or forwards messages containing payroll keywords — is a strong signal that the account has been compromised. This is the most commonly overlooked step after a password reset.

    Teach the staff member’s side too

    The control above protects the organization’s process. Your team also needs to recognize the phishing that precedes the takeover.

    Tell them plainly: you will never receive a legitimate email asking you to log in to view a pay stub, confirm your direct deposit, or re-verify your payroll account. If a message like that arrives, don’t use the link. Open a browser and go to the payroll site the way you normally do, or call the office.

    That single habit — never sign in from a link in a message — defeats credential phishing in every form, not just this one.

    If it already happened

    Move immediately; this is recoverable more often than people expect, but only quickly.

    Call the bank that received the money and report the deposit as fraudulent. If the payroll run has processed but the funds haven’t been withdrawn, they can sometimes be frozen.

    Call your own bank and your payroll provider and ask about a reversal. Some ACH transfers can be recalled within a narrow window.

    Report it to the FBI at ic3.gov, and use the words payroll diversion and business email compromise. The Bureau’s Recovery Asset Team can trigger a process to freeze funds in transit — in 2025 it ran 3,574 domestic cases and froze $507,042,623. It works dramatically better inside the first day or two.

    Assume the mailbox is compromised until proven otherwise. Change the password from a different device, revoke all active sessions (“sign out everywhere”), re-enable MFA, and check for mail rules the attacker added.

    Then take care of the person. Decide quickly whether the organization will cover the missed pay while recovery is attempted. Whatever you decide, decide it fast and say it plainly — a staff member who has lost a paycheck through no fault of their own should not spend a week wondering.

    What to do this week

    Write down one sentence and give it to whoever runs payroll: Banking changes are confirmed by calling the employee on the number in their personnel file, and take effect on the following pay run.

    Then check two settings — that change notifications are turned on in your payroll system, and that multi-factor authentication is enabled on the payroll portal as well as on email.

    Half an hour, and this attack stops working on you.

    MissionDefend’s free assessment walks through exactly these kinds of gaps in plain English — how you handle email, donations, member data, and accounts — and gives you a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI, Building a Digital Defense Against Payroll Phishing Scams; FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.

  • Your Pastor Won’t Text You for Gift Cards: The Impersonation Scam

    Your Pastor Won’t Text You for Gift Cards: The Impersonation Scam

    If you work at a church, you have probably already seen this one. If you haven’t, you will.

    A member of your congregation gets a text from an unfamiliar number:

    Hello, are you available? I need a favor. — Pastor Mike

    Or an email lands in a volunteer’s inbox. The sender name says Pastor Mike Adams, exactly as it appears in every other message from him. The subject line is Quick request. The body is two sentences.

    Are you free right now? I’m in a meeting and can’t talk on the phone, but I need something handled discreetly.

    Anyone who replies gets the ask. The church needs to buy gift cards — Apple, Google Play, Amazon, Target — for a member in the hospital, or for a benevolence case, or as thank-you gifts for volunteers. The pastor will reimburse them. It’s urgent, it’s a little sensitive, and could they please just scratch off the backs and send photos of the codes?

    This scam runs constantly, in every denomination, in churches of every size. It is worth understanding precisely, because the mechanics are simpler than most people assume — and so is the fix.

    Nobody hacked anything

    The most important thing to understand: in almost every version of this scam, the pastor’s account was never broken into.

    That surprises people, because the message looks like it came from him. But the attacker didn’t need access. They needed one of two very ordinary tricks.

    Trick one: display name spoofing

    Every email has two separate pieces of sender information, and your mail app shows you one of them.

    The display name is the friendly label — Pastor Mike Adams. The email address is the actual routing information — mike@yourchurch.org.

    Here’s the thing that makes this scam work: the display name is just text. Anyone can type anything they like into it. There is no verification, no check, no ownership requirement. I can create a free email account right now and set my display name to “Pastor Mike Adams,” and every message I send will show up in your inbox with that name on it.

    The real address underneath would be something like `pastormike.adams247@gmail.com` or `mike.adams.church@outlook.com` — plausible enough that if you did glance at it, it might not alarm you.

    And on a phone, you usually can’t glance at it. Mobile mail apps show the display name and hide the address entirely to save screen space. That is not a bug in your phone. It’s a design choice that this scam exploits, and it’s why these messages so often get read and answered on a phone rather than a desktop.

    Trick two: an unfamiliar phone number

    The text-message version is even simpler. There’s no spoofing at all. The attacker just texts from a number you’ve never seen and signs the message with the pastor’s name. Because a new number shows up with no contact photo and no history, and because plenty of people do change phones, “Hi, this is Pastor Mike, I got a new number” is not automatically suspicious.

    Where do they get the names and numbers? Nowhere clever. Your staff page lists who your pastor is. Your bulletin names your office administrator. Your Facebook page shows who volunteers. Church directories get shared. None of that is a security failure — it’s a church being findable, which is the point of a church. But it means an attacker can build a convincing message with fifteen minutes of public browsing.

    Why gift cards specifically

    This is the detail that gives the scam away, once you know it.

    Gift cards are, for a criminal, close to perfect. They are effectively untraceable — once the code is spent, there’s no account holder to subpoena and no transaction to reverse. They are instantly transferable — a photo of the scratched-off code is all that’s needed; the physical card is irrelevant. They are irreversible — unlike a credit card charge or even a wire transfer, there is no dispute process and no recall window. And they are available everywhere, which means a victim can complete the whole request in twenty minutes at a grocery store.

    Compare that to a bank transfer, which leaves a paper trail, involves an institution that can freeze funds, and requires the criminal to maintain an account somewhere.

    So here is the rule that flows from that, and it’s worth putting in bold in your bulletin:

    No legitimate church request will ever involve buying gift cards and sending photos of the codes. Not for benevolence. Not for a hospital visit. Not for volunteer appreciation. Not ever. There is no scenario in normal church operations where that is how money moves.

    That single sentence, taught once, immunizes most people permanently — because it doesn’t require anyone to evaluate whether a particular message looks legitimate. It just makes the ask itself the tell.

    The wider pattern

    Gift cards are the most common version, but the same impersonation gets used for other requests, and your team should recognize the family resemblance:

    A request to wire funds urgently for a deposit or a contractor, before end of business.

    A request to buy cryptocurrency and send it to a wallet address.

    A request for the staff list, the member directory, or W-2 information — no money at all, just data, which then gets used for the next attack or sold.

    A request to buy something on your personal card and be reimbursed later, which is really just gift cards with extra steps.

    The shape is always the same: authority, urgency, a reason you can’t verify by voice right now, and a request that moves value in a way that can’t be undone.

    What the FBI data says

    This isn’t folklore. Phishing and spoofing were the most-reported cybercrime in America in 2025, with 191,561 complaints filed with the FBI’s Internet Crime Complaint Center.

    The demographic detail matters for congregations. Victims aged 60 and over filed 201,266 complaints in 2025, losing $7.748 billion — a 59% increase over the previous year, averaging $38,500 per victim. Older members of your congregation are being targeted heavily, and a warning from their church may be the most credible one they receive.

    How to shut it down

    Four things. None of them take money, and the first two take an afternoon.

    Tell your congregation, in plain words, from the front. Not a technical bulletin insert nobody reads — a spoken sentence, from the platform or in the newsletter, in the pastor’s own voice: “I will never text or email you asking for gift cards, money, or a favor involving payment. If you get a message like that with my name on it, it isn’t me. Please don’t reply, and please tell the office.” Coming from the person being impersonated, this lands differently than a security notice.

    Teach the one habit that works on a phone. Before acting on any message asking for money or a favor, tap the sender’s name to reveal the actual email address. On a text, check whether the number matches the one already in your contacts. If it doesn’t, that’s your answer. This takes three seconds and doesn’t require anyone to be technical.

    Make verification impersonal and expected. Write down that any money-related request is confirmed by voice, using a number you already had — not a number in the message. Say explicitly that this applies to requests that appear to come from leadership, and that nobody will ever be thought disloyal for making the call. That last clause is doing real work: the reason these scams succeed in churches is that questioning the pastor feels wrong.

    Turn on the technical guardrails. Two settings help meaningfully. First, multi-factor authentication on every staff email account — the extra code or tap after the password — which protects you in the cases where an account really is compromised rather than merely imitated. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Second, ask whoever manages your email to enable external sender warnings, the banner that says “This message came from outside your organization.” When a message claims to be from your pastor and carries that banner, the contradiction is visible even on a phone.

    If you want to go further, the fuller fix is email authentication — the SPF, DKIM and DMARC records that stop strangers sending mail that claims to come from your domain at all. That’s a bigger topic, and it’s coming later in this series.

    If someone already bought the cards

    Move fast; there’s a narrow window.

    Call the gift card issuer’s fraud line immediately — the number is on the back of the card or on the retailer’s website — and report the cards as fraudulently obtained. Occasionally, if the codes haven’t been spent, funds can be frozen. Keep the physical cards and the receipts; they’re evidence and they’re required for any claim.

    Report it to the FBI at ic3.gov. This feels pointless for a few hundred dollars, and it isn’t: the aggregate reporting is what drives takedowns, and it’s how the pattern gets tracked.

    Then tell your congregation what happened, without naming the person who was fooled. Someone who admits they were scammed has done your whole community a service, and how you treat them determines whether the next person speaks up in twenty minutes or three days.

    What to do this week

    Write four sentences and send them to your congregation under your pastor’s name: I will never text or email you asking for gift cards or money. If you get a message like that with my name on it, it isn’t me. Don’t reply. Tell the office.

    That’s it. That’s the highest-value fifteen minutes available to most churches this month.

    When you’re ready to look at the whole picture rather than one scam at a time, MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts — then give you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.

  • Social Engineering: Why Attackers Target Your People, Not Your Firewall

    Social Engineering: Why Attackers Target Your People, Not Your Firewall

    The email arrived at 8:52 on a Tuesday morning. It was from the pastor — his name, right there in the sender line — and it was short.

    Are you at your desk? I need you to handle something for me. I’m in a meeting so I can’t take calls.

    The office administrator wrote back that yes, she was at her desk. What did he need?

    Nothing about that exchange involved breaking into anything. No password was cracked. No virus was installed. No firewall was bypassed. And yet, ninety minutes later, the church was out $1,800 in gift cards.

    This is social engineering, and it is the single most common way churches and nonprofits lose money and data. Not because your organization is careless. Because it is the way the overwhelming majority of attacks now work, everywhere, and because the things that make a ministry good at being a ministry are the same things that make social engineering effective.

    What “social engineering” actually means

    The phrase sounds like jargon, and it is — but the idea underneath it is simple.

    Social engineering is persuading a person to do something, rather than forcing a computer to do it.

    That’s the whole definition. An attacker who breaks encryption is doing technical work. An attacker who convinces your bookkeeper to change a vendor’s bank details is doing social work. The second is dramatically easier, dramatically cheaper, and requires no special skill beyond patience and a plausible story.

    It helps to think of it the way you’d think about a con artist in any other era. The technology is new. The technique is not. Someone is establishing a reason you should trust them, creating a situation where checking feels rude or slow, and asking for something that seems small in the moment.

    You’ll see a lot of specific names for these attacks, and the vocabulary can feel like a wall. Here is the map, in plain terms:

    Phishing is social engineering delivered by email — a message designed to get you to click, log in, or reply. The name is a play on “fishing,” because early versions cast a wide net and waited.

    Spear phishing is the same thing aimed at one specific person, using details about them. A spear instead of a net.

    Vishing is voice phishing — the scam arrives by phone call.

    Smishing is SMS phishing — it arrives by text message.

    Pretexting is the invented backstory that makes the request feel routine. “I’m calling from your insurance carrier about the annual audit” is a pretext.

    Business email compromise, usually shortened to BEC, is the category where someone impersonates a leader or a vendor to redirect a payment.

    Every one of those is a flavor of the same thing. Someone is talking to a human being and asking them to act.

    The numbers, and why they matter to a small office

    It’s tempting to read all this and assume it’s a problem for banks. The federal data says otherwise.

    The FBI’s Internet Crime Complaint Center — the government’s clearinghouse for reported cybercrime, usually called IC3 — logged 1,008,597 complaints in 2025, with just under $20.9 billion in reported losses. Within that, phishing and spoofing generated 191,561 complaints, making it the single most-reported crime type in the country.

    Business email compromise accounted for 24,768 complaints and more than $3 billion. Divide those out and the average reported loss per BEC report was about $123,005.

    Now hold that number against a church budget. For most congregations, a single successful impersonation email costs more than a quarter’s giving. And note what didn’t appear anywhere in that description: malware, hacking tools, technical sophistication. It required someone to believe an email.

    There’s one more figure worth sitting with, because it touches your congregation rather than your office. IC3 recorded 201,266 complaints from victims aged 60 and over in 2025, with $7.748 billion in losses — a 59% increase over the prior year, and an average loss of $38,500 per victim. The people in your pews are being targeted, and many of them will hear about it from you before they hear about it from anyone else.

    The six levers

    Every social engineering attack pulls on at least one of six psychological levers. Once you can name them, you start noticing them, and noticing is most of the defense.

    Authority. The request appears to come from someone you don’t question — the pastor, the executive director, the board chair, the bank, the IRS. Authority short-circuits the instinct to verify, because verifying feels like doubting your boss.

    Urgency. There’s a deadline, real or invented. Before noon. Before the wire cutoff. Before the account is suspended. Urgency exists to prevent you from doing the one thing that would defeat the attack: pausing.

    Familiarity. The message uses the right names, the right tone, the right details. It mentions the building project by name. It knows your treasurer is called Deb, not Deborah. Familiarity is why these messages feel real — and it’s cheap to manufacture, because your staff page, bulletin, Facebook posts, and public filings are all free research material.

    Fear. Something bad will happen. Your mailbox will be deleted. Your account is compromised. There’s a legal problem. Fear narrows attention to the threat and away from the oddities in the message.

    Curiosity. An unexpected invoice. A shared document. A photo from the retreat. Curiosity is the lever behind most malicious attachments, because opening something to find out what it is feels harmless.

    The wish to be helpful. This is the one that matters most in ministry, and the one nobody wants to hear. Churches and nonprofits are staffed by people whose whole disposition is to help quickly, assume the best, and not interrogate someone who asks for something. That disposition is a virtue. It is also, precisely, the surface an attacker aims at.

    That last point deserves care. The lesson is not that your team should become suspicious of everyone. A congregation that treats every request as a threat has lost something more valuable than the money. The lesson is narrower and much more manageable: for a very small number of specific actions, verification becomes automatic and impersonal — not a judgment about the person asking, just the way that particular thing is always done.

    Why small organizations get chosen

    Three structural facts make churches and nonprofits attractive, and none of them are about carelessness.

    You hold valuable, irreplaceable data. Donor giving histories, member contact lists, background check results, counseling notes, children’s ministry records. Some of it has resale value. Some of it is simply devastating if it becomes public.

    Your money moves in ways that are hard to verify. Offerings, designated gifts, benevolence funds, reimbursements, contractor payments during a building project. Transaction volume is low enough that one fraudulent payment doesn’t stand out, and approval processes are usually informal because the team is small and trusts each other.

    And your information is public by design. A business hides its org chart. A church publishes it — with photos, titles, email addresses, and often direct phone numbers — because that’s how people find their pastor. An attacker doesn’t need to breach anything to learn who your finance person reports to.

    What actually stops it

    Because the attack targets people, the defense has to work at the level of people. Three things carry most of the weight, and none cost money.

    One rule, written down, about money. Any request to move funds, change bank details, or buy gift cards is verified by voice, using a phone number you already had — not a number in the message. Not by replying to the email. The attacker controls the email thread; they do not control the number in your directory. Write this rule down, tell everyone who touches money, and state plainly that nobody will ever be criticized for following it. The failure this prevents is a bookkeeper who feels too junior to question leadership.

    Permission to be wrong. The most expensive incidents are not the ones where someone got fooled. They’re the ones where someone got fooled and then waited three days to say so, hoping it would resolve itself. A misdirected payment caught in twenty minutes is often recoverable — the FBI’s Recovery Asset Team froze over $507 million across 3,574 domestic cases in 2025, and that process depends almost entirely on speed. The same mistake caught on Friday afternoon usually is not. Tell your team, in words, that reporting a mistake immediately is the desired behavior and will never be held against them.

    Fifteen minutes, twice a year, on real examples. Not an hour-long generic video. Show your actual staff the actual scams aimed at churches: the gift card request, the fake invoice from a vendor you really use, the “your mailbox is full” notice. Recognition is trainable. Familiarity with the specific shape of these messages is what makes someone pause.

    The rest of this series

    Over the coming weeks we’re going to take these apart one at a time — the gift card scam, business email compromise, payroll diversion, phone and text scams, AI voice cloning, and the rest. Each post explains one attack in plain language, shows what the message actually looks like, and ends with what to do about it.

    The goal isn’t to make you afraid of your inbox. It’s to make these attacks boring — familiar enough that when one arrives, someone on your team recognizes the shape of it and doesn’t have to guess.

    What to do this week

    Pick one thing. Write down the verify-by-voice rule for money requests, send it to everyone who touches a payment, and say explicitly that following it is never rude. That single paragraph, circulated once, closes the most expensive category of attack aimed at organizations like yours.

    MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts, then give you a baseline score and a ranked list of what to fix first. It’s launching soon — leave your email and we’ll tell you the moment it opens.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report.