The phone in the church office rings at 2:40 on a Wednesday. The screen says FIRST NATIONAL BANK.
The caller is calm and slightly bored, the way people sound when they do this all day. There’s been unusual activity on the church’s account — two attempted transfers this morning, both declined. He needs to confirm he’s speaking with an authorized signer before he can discuss details, and then he’ll need to verify a code that’s about to be texted to the number on file, so the fraud hold can be lifted.
Everything about that call is false, including the name on the screen.
Email scams get most of the attention, and reasonably so. But phone-based attacks have a particular power that email doesn’t: a live human being, responding in real time, adapting to whatever you say. There’s no time to reread. There’s no forwarding it to a colleague. Social pressure operates the way it does in any conversation — hanging up on someone feels rude in a way that deleting an email never does.
What vishing means
Vishing is short for voice phishing — the same persuasion attack you’ve read about in this series, delivered by phone call instead of email.
The goal is one of three things: get you to reveal a credential (a password, or more often a one-time code), get you to move money, or get you to install something on a computer.
The name is jargon, but there’s nothing exotic underneath. Someone calls with an invented reason to be calling, and asks you to do something.
Your caller ID is not evidence
This is the single most important technical fact in this post, and most people have never been told it plainly.
The number and name shown on your phone are supplied by the caller. They are not verified by anyone.
When a call is placed, the caller’s system includes the number it wants displayed. Historically, the phone network passed that along without checking it. That’s how legitimate systems work too — it’s why a call from a hospital’s back office can display the hospital’s main switchboard number, and why your church’s outgoing calls can all show the office line rather than whichever extension dialled.
That same flexibility is what lets an attacker display your bank’s actual customer service number, or your denomination’s regional office, or — and this happens — your own church’s number, calling a member of your congregation.
The FCC describes caller ID spoofing as scammers falsifying the number that appears on your display in order to “trick Americans into answering their phones when they shouldn’t.”
There is a countermeasure, and it’s worth understanding both what it does and what it doesn’t.
STIR/SHAKEN is a caller ID authentication framework that US carriers are required to implement. In plain terms: the phone company that originates a call digitally “signs” it, and the companies that carry it onward can verify that signature. It’s the reason your phone sometimes displays “Caller Verified” or a similar label.
What it does not do is guarantee that an unlabelled call is fake, or that a verified call is trustworthy. Verification confirms the call really came from the number shown — not that the person on the line is honest. Plenty of legitimate calls arrive unsigned, particularly from smaller carriers and internet-based phone systems. Treat it as weak supporting evidence, not proof.
The practical takeaway for your staff: the name on the screen tells you nothing about who is actually calling.
The versions aimed at ministries
The bank fraud department. As above. The prize is usually a one-time code — the six digits your bank texts you. The caller creates a reason you’d expect to receive one, then asks you to read it out. That code is the second factor protecting your account; handing it over hands over the account.
The IT helpdesk. “I’m calling from the company that supports your Microsoft 365 — we’re seeing sync errors on your mailbox.” The ask is either your password or permission to install a remote access tool so they can “take a look.” This one succeeds in small offices because the staff genuinely don’t know exactly who supports their systems.
The utility shutoff. Aggressive, deadline-driven, aimed at the office administrator: the church’s power will be cut this afternoon unless an overdue balance is paid immediately, usually by prepaid card or transfer. Real utilities don’t operate this way.
The denominational or grant office. More targeted. Someone who knows your affiliation calls about a compliance filing, an insurance audit, or a grant disbursement, and needs bank details or staff information to proceed.
The follow-up call after an email. Increasingly common, and effective. An email arrives requesting a payment change; then a call arrives “confirming” it. Two channels agreeing feels like verification. It isn’t — the attacker controls both.
The call to your congregation. Your church’s number is displayed, and an elderly member is told there’s a problem with their giving record, or that the church is collecting for an emergency. This one damages trust you spent decades building.
Why it works on good people
Live conversation removes the two things that protect you in email: time, and the ability to reread.
A skilled caller uses authority (a title, an institution), urgency (a hold that expires, a shutoff today), and plausibility (they already know your pastor’s name, your bank, your address — all public). They may also use reciprocity, doing you a small favour first: “I’ve placed a temporary hold on the account for you, that’ll protect you while we sort this out.”
And they exploit ordinary manners. Ending a call abruptly on a polite, professional-sounding person feels aggressive. Most people would rather stay on the line and be uncomfortable.
That instinct is the thing to override, and the way to override it is not to make your staff ruder. It’s to give them a script that isn’t rude at all.
The habit that defeats all of it
One rule. It handles every variant above without anyone having to judge whether a particular call sounds legitimate:
Hang up and call back on a number you already had.
Not the number the caller gives you. Not the number that appeared on your screen — that’s the one that can be faked. The number on the back of your bank card, on a previous statement, in your contacts, on the signed contract, on the utility’s official website.
The polite version, which anyone can say without confrontation:
“I’m not able to discuss account details on an inbound call. Let me call you back on the number we have on file.”
A legitimate caller from any real institution will not object to that. Fraud departments in particular expect it — it’s exactly what they train their own customers to do. A caller who pushes back, who explains why calling back won’t work, who says the case number will expire, has just identified themselves.
Two absolute rules to teach alongside it, with no exceptions:
Never read a one-time code to anyone on the phone. No bank, no vendor, no IT provider, no denominational office will ever ask you to. The entire purpose of that code is to prove you are present. Reading it aloud defeats it completely. Most banks now print this warning in the text message itself.
Never install software or grant remote access because of an incoming call. If someone needs to see your screen, that arrangement is made through a relationship you initiated.
Prepare before it happens
Write down who actually supports you. A single sheet: your bank’s real fraud number, your IT support’s real number, your payroll provider, your insurer, your denominational contact. Print it. Put it where the phone is. Most vishing succeeds because the person answering genuinely doesn’t know who legitimately calls them, and searching for a number under pressure is when people click the wrong result.
Extend the money rule to phone calls. The verification rule from earlier in this series — no payment change without a callback — applies identically to requests that arrive by voice. Write it that way so nobody wonders whether the phone is different.
Give people permission to hang up. Say it out loud in a staff meeting: “If a call feels off, end it. You will never be in trouble for hanging up on someone, even if it turns out to be legitimate. We’ll sort it out.” Without that explicit permission, junior staff and volunteers will stay on the line out of politeness.
Warn your congregation. Include a line in the newsletter: the church will never call you asking for payment, gift cards, or account details. Older members are being targeted heavily — the FBI logged 201,266 complaints from victims aged 60 and over in 2025, totalling $7.748 billion, up 59% in a single year.
Run one practice call. Ask a board member to call the office pretending to be the bank. Ninety seconds, at a staff meeting. People remember doing it in a way they do not remember being told about it.
If someone already gave something up
If a one-time code was shared: change that account’s password immediately from a different device, sign out all active sessions, and call the institution’s real fraud line. Assume the account was accessed.
If remote access was granted: disconnect that computer from the network — unplug the cable, turn off Wi-Fi — but don’t wipe it. Get someone technical to look at it before it goes back into use.
If money moved: call your bank’s fraud line before doing anything else, then report to the FBI at ic3.gov. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process depends almost entirely on speed.
In every case, tell someone immediately. The pattern that turns a contained mistake into a serious loss is a person who is embarrassed and waits.
What to do this week
Make the one-page contact sheet — bank fraud line, IT support, payroll, insurer — and tape it up next to the office phone. Then, at your next staff meeting, say the sentence out loud: nobody will ever be in trouble for hanging up and calling back.
That’s fifteen minutes, and it closes the whole category.
MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then gives you a baseline score and a ranked list of what to fix first.
No spam and no sales calls — just one email when it’s live.
Related reading
- the email written to make you dial the number
- what happens when the voice on the line is cloned
- the six levers every one of these attacks pulls
MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.
Sources: Federal Communications Commission, Combating Spoofed Robocalls with Caller ID Authentication; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.




