Home Articles Get your free assessmentComing soon

Tag: staff training

  • Anatomy of a Phishing Email: Eight Tells and What They Look Like

    Anatomy of a Phishing Email: Eight Tells and What They Look Like

    Phishing — the fake email built to make you click, log in, or pay — was the most-reported cybercrime in America again in 2025: 191,561 complaints to the FBI’s Internet Crime Complaint Center, more than any other category. It holds that title year after year for a boring reason: it keeps working.

    It keeps working partly because the training most people got is out of date. The old advice was “look for bad grammar and obvious typos.” CISA — the federal cybersecurity agency — now says plainly that generative AI has made well-written phishing routine. The clumsy Nigerian-prince era is over; the fakes are fluent now.

    What hasn’t changed is the structure. A phishing email has a job to do — create trust, create pressure, deliver a click — and the machinery for doing that job leaves the same fingerprints it always has. Here are eight of them, each shown the way it actually lands in a church office inbox. The examples are composites, not real messages, but every pattern in them is drawn from the attacks this series has already decoded.

    1. The display name that doesn’t match the address

    From: Pastor David Reeves ‹pastordavid.stmarks@gmail‑mail‑secure.com›
    Are you available? I need a favor handled discreetly.

    Email lets anyone put any name in the “From” line — the display name is decoration, chosen by the sender. The tell is the actual address behind it. On a phone, that address is hidden by default, which is exactly why so much phishing succeeds on phones: tap the sender’s name and read the real address before you believe anything else about the message. Your pastor’s real address you know. Everything else is a costume.

    2. Urgency with a deadline measured in hours

    Your mailbox will be deactivated in 4 hours. Verify now to avoid interruption.

    Legitimate organizations almost never need you to act within the hour, because nothing real works that way. Manufactured deadlines exist to keep you from doing the one thing that kills every scam: pausing to check. CISA lists urgent, consequence-laden language as the leading sign of phishing. When an email makes your chest tighten, that feeling is the payload.

    3. The mismatched link

    www.churchgivingportal.com/login

    The words of a link and its destination are two separate things — the blue text can say anything while pointing anywhere. On a computer, hover over the link without clicking and read the true address in the corner of the window. On a phone, press and hold to preview it. Watch for near-misses built to survive a glance: `rnicrosoft.com` (r-n masquerading as m), `yourchurch-give.com` instead of `yourchurch.org/give`, or a real brand name buried in front of an unrelated domain: `microsoft.security-check-portal.com`. The only part that matters is the last two pieces before the first slash.

    4. The login page you didn’t navigate to

    Your document is ready: OfferingReport_Q2.pdf — Sign in to view.

    The fake login page is where credentials actually get stolen. The email is just the ride there. The rule that beats it: a link you clicked in an email never gets a password. If a message says a document, invoice or voicemail is waiting behind a sign-in, close it and go to the service directly — type the address or use the app. If the document is real, it’s there. This habit also defeats attacks good enough to beat inspection, which some now are.

    5. A request that switches channels or demands secrecy

    Don’t call me, I’m going into the service. Just reply here.

    Real requests survive verification; fake ones must prevent it. So the message forbids exactly the act that would expose it — “don’t call,” “keep this between us,” “I’m unreachable.” We’ve seen this lever in the gift card scam, in payroll diversion, and in voice cloning. Treat any instruction not to verify as the confession it is.

    6. The attachment that needs something extra

    Invoice attached. If the document appears blank, click Enable Content to view.

    An attachment that requires you to click a button, enable macros, or install “a viewer” to read it isn’t a document with a problem — it’s a program wearing a document’s clothes. Modern office software disables that machinery by default precisely because it was the most common way malware got run. The email is asking you to overrule your own safety equipment.

    7. The reply-to that goes somewhere else

    From: finance@yourdenomination.org
    Reply-To: finance.office.desk@outlook.com

    Some phishing genuinely spoofs a trusted address in the “From” line — but the conversation has to route back to the attacker, and the hidden Reply-To field is where that happens. If you hit reply and the address in the compose window isn’t the one you thought you were talking to, stop. This is also why continuing an email thread is not verification: in business email compromise, the thread itself is the stolen property.

    8. Almost right, at the wrong moment

    Following up on the invoice from last month’s roof repair — updated remittance details attached.

    The most dangerous phishing contains no visible mistakes, because it’s built from real information: your actual roofer, a real project, plausible timing. The tell isn’t in the text — it’s in the event: money or credentials being requested with any change from the established pattern (new bank details, new payment method, new address, unusual quiet urgency). At that point the email’s quality is irrelevant, because your procedure — confirm changes by phone on a number you already have — doesn’t care how good the writing is.

    What to do this week

    Print these eight, tape them by the office computer, and spend ten minutes at the next staff meeting reading the examples aloud — people recognize patterns far faster from specimens than from rules. Then set the reporting habit: CISA’s guidance is recognize, resist, delete — and in an organization, “resist” means report it to whoever handles your email before deleting, so one alert reader protects everyone. Make the report thank-worthy, never eye-roll-worthy; the person who forwards a false alarm is your early-warning system working.

    And keep the fallback that underlies this whole series: when an email requests money, credentials, or account changes, the email itself is never the proof. Verification travels on a different channel — a phone number you already had, an address you typed yourself.

    The MissionDefend assessment checks whether your organization has these habits in place — reporting culture, verification rules, MFA — and gives you a prioritized plan for what’s missing. Join the launch list.


    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report (phishing/spoofing complaint count); Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing.

  • Pretexting: The Fake IT Guy and the Vendor Who Isn’t

    Pretexting: The Fake IT Guy and the Vendor Who Isn’t

    The call comes in on a Wednesday around 10 a.m., which is not an accident — late enough that the office is busy, early enough that nobody’s left for lunch.

    “Hi, this is Marcus from TechServe — we handle the copier contract? We’re pushing a security update to all our units this week and I need someone to read me the numbers off the admin sticker on the back. Should take two minutes. Sorry for the hassle — half the churches in the county are on my list today.”

    There is no Marcus. There is no update. But notice everything that call already got right: a plausible company, a plausible task, an apology, a time limit, and a detail — half the churches in the county — that makes the whole thing feel routine. By the time an ask arrives, it doesn’t feel like a request from a stranger. It feels like step three of a process that started before you picked up.

    That manufactured backstory has a name: pretexting. The pretext is the invented situation — the role, the reason, the paperwork — that makes the eventual request seem normal. If phishing is a fake message, pretexting is a fake context. It’s the con artist’s stage set, and it’s the engine inside most of the attacks this series has covered: the fake invoice works because “vendor billing you” is a pretext, and the phone scam works because “your bank’s fraud department” is one.

    The costumes that get worn at churches

    Attackers pick pretexts the target already expects to encounter. For a church or small nonprofit, four costumes come up over and over.

    The IT technician. “We’re doing maintenance on your email this afternoon — I’ll need someone to confirm the login so accounts don’t lock out.” Small congregations rarely have in-house IT, so someone external who handles computer things is entirely believable — most churches genuinely do have a guy. The test is simple: real technicians you actually pay never need your password. Anyone who asks for one is not your technician, whatever the caller ID says.

    The vendor with an account problem. The copier company, the payroll processor, the giving platform, the alarm monitoring service. The caller knows which one you use — often because it’s visible on your website, in a bulletin PDF, or on a sticker by the door — and the “problem” needs an account number, a card update, or remote access to fix.

    The authority up the chain. The diocese, the district office, the denomination’s insurance program, an “auditor” doing an annual review. Hierarchical organizations are trained to respond to the level above them, and attackers borrow that reflex. A folder of official-looking paperwork, a confident tone, and a Friday-afternoon deadline can move remarkable amounts of information.

    The government caller. The IRS about your exempt status, a “grant administrator” about funds you’re eligible for, a court officer about a missed jury summons for your pastor. Impersonating agencies and businesses is now squarely illegal under a rule the Federal Trade Commission put into force on April 1, 2024 — a rule created precisely because the FTC logged over $1.1 billion in reported impersonation-scam losses in 2023, more than triple the 2020 figure. A rule after the fact, of course, only helps you if you didn’t comply during the call.

    Why good people hold the door open

    Pretexting exploits the two instincts churches deliberately cultivate: helpfulness and trust. The volunteer at the desk wants to be useful to the nice technician. The bookkeeper doesn’t want to make the diocese wait. Nobody wants to be the suspicious one — it feels rude, and ministry culture prizes warmth.

    So the fix cannot be “make everyone suspicious.” It won’t take, and it would cost you something real. The fix is to make verification feel like procedure instead of accusation — the same shift that makes a bank teller checking ID feel professional rather than hostile.

    What to do this week

    Give the front desk a script that isn’t rude. One laminated card: “Happy to help with that — our process is to call you back through the main number we have on file for your company. What’s your name and extension?” A real vendor hears bookkeeping hygiene. A pretexter hears the con failing. The power of the callback is that it routes around everything the attacker controls — their number, their story, their urgency — to a channel you already trusted before the call existed.

    Keep a one-page vendor sheet. Every company that can plausibly call you — copier, payroll, giving platform, insurance, IT, alarm — with the phone number from your contract or a bill you’ve paid, not from the internet. Verification only works if the real number takes ten seconds to find. Update it when contracts change, and note who your actual account rep is.

    Decide what the “sticker information” is worth. Serial numbers, account numbers, staff direct lines, which software you use — none of it is secret, exactly, but each piece makes the next pretext more convincing. The attacker who knows your copier model and your administrator’s first name sounds like Marcus. Trim what’s published where you can, and treat unsolicited requests for those details as the reconnaissance they are.

    Rehearse the two-question test. Before acting on any unsolicited contact, staff ask: Did I have a way to expect this? and Am I being given a reason not to verify? A real vendor’s real update survives a callback tomorrow. Only the fake one needs it done on this call, today, before lunch.

    Pretexting is patient, polite, and completely dependent on one thing: the target acting inside the story the attacker built. A callback steps outside the story. Nothing inside it survives that.

    MissionDefend’s free assessment includes the unglamorous controls that stop pretexting — callback rules, vendor verification, front-desk procedure — and shows you which ones your organization is missing. Get on the launch list.


    Sources: Federal Trade Commission, FTC Announces Impersonation Rule Goes into Effect Today (April 1, 2024); Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Smishing: Text-Message Scams Aimed at Church Staff

    Smishing: Text-Message Scams Aimed at Church Staff

    The text arrives on a Saturday, while the office is closed and the administrator is in the grocery store checkout line.

    USPS: Your package could not be delivered due to an incomplete address. Update your information within 24 hours: [link]

    She is expecting a package — the new children’s ministry curriculum, ordered Tuesday. The link looks vaguely official. She’s holding a phone in one hand and a gallon of milk in the other. This is precisely the moment the message was designed for.

    This is smishing — phishing carried out by text message. The name is a mash-up of SMS (the technical name for a text message) and phishing (tricking someone into clicking a link or giving up information by pretending to be someone they trust). Same con as the fake email, different doorway. And the doorway matters, because the phone in your pocket gets a level of trust and speed of response that email never did.

    Why texts work when emails fail

    Your email has a spam filter that has been learning for twenty years. Your text messages, for the most part, do not. A scam that would never survive the trip to your inbox lands on your lock screen untouched.

    The behavior around texts is different too. People answer texts fast — usually within minutes, often mid-task, standing up, one-handed. Nobody prints a text out and walks it down the hall to ask the treasurer if it looks right. And on a phone, the single best defense you have on a computer — hovering over a link to see where it really goes — mostly isn’t available. The screen is small, the address is shortened, and the browser hides the details.

    The scale of the problem is not small. The Federal Trade Commission reported that Americans lost $470 million to text-message scams in 2024 — five times the losses reported in 2020, even though the number of reports went down. Fewer people are falling for it; the ones who do are losing more.

    The five texts your staff will actually receive

    The FTC’s data names the five most common text scams by reported losses. Every one of them maps cleanly onto a week in a church office.

    The fake package notice. The most common of all. “Your delivery could not be completed.” A church office receives packages constantly — curriculum, supplies, communion cups, things five different volunteers ordered — so someone is always expecting a delivery. That’s what makes it work. The link leads to a page that harvests your address, your card number, or your login.

    The bogus job offer. Recruiting texts for part-time, work-from-home positions — sometimes called task scams, because they pay small amounts for trivial online tasks before demanding a deposit to “unlock” larger earnings. These circulate through congregations, and they sometimes borrow a real ministry’s name to look credible.

    The fake fraud alert. “Did you attempt a purchase of $487.23 at Best Buy? Reply NO to dispute.” There was no purchase. The reply — or the phone call that follows — is the scam. It ends with the “bank” walking the victim through moving money to a “safe account” that belongs to the attacker.

    The unpaid toll. A small, plausible amount — a few dollars — with a payment link and a late-fee threat. Small enough to pay without thinking, which is the entire design.

    The wrong number. “Hi, is this Jennifer? We’re still on for Tuesday?” It looks like a misdial. Replying politely starts a friendly conversation that, over weeks, becomes a relationship — and eventually an investment opportunity. This one costs its victims the most, and it targets exactly the demographic most churches serve.

    The church-office wrinkle

    For a business, smishing is a consumer problem that occasionally reaches payroll. For a church, it’s stickier, for one structural reason: the phone that receives the scam is almost never a device the organization controls. It’s the administrator’s personal phone, the volunteer treasurer’s personal phone, the youth director’s personal phone — carrying church email, the giving platform app, and the group chat with every leader in it.

    That means you cannot solve this with software. There is no filter you can buy for a phone you don’t own. What you can change is the procedure — what a person does in the ten seconds after the message lands.

    What to do this week

    Adopt the two-line text policy. Say it at the next staff meeting, put it in the volunteer handbook, and have leadership repeat it until it’s folklore: We never handle money, passwords, or account changes by text. If a text asks for any of those, it’s fake until proven otherwise by a phone call to a number we already have. That single rule defeats every scam on the FTC’s list, because every one of them needs the text itself to carry the action.

    Teach the app-not-the-link habit. If a text claims to be your bank, the postal service, or a toll authority, the response is never the link in the message — it’s opening the official app, or typing the address you already know. If the alert is real, it will be waiting there.

    Report, then delete. Forward scam texts to 7726 — that spells SPAM on a keypad — which helps carriers block similar messages for everyone. Then report it at ReportFraud.ftc.gov, and delete it. Don’t reply, not even “STOP,” to a message you believe is a scam; a reply confirms the number is live.

    Warn the congregation once a season. A single line in the bulletin or newsletter — the church will never text you asking for gift cards, payments, or personal information — protects the people your staff can’t. The wrong-number romance scam in particular preys on older adults, and a warning from a trusted pulpit lands where a news story doesn’t.

    Smishing is the same social engineering we covered on day one of this series — persuasion instead of hacking — squeezed into 160 characters. The persuasion doesn’t survive a pause and a phone call. Build the pause into the routine.

    Want to know where your organization actually stands? MissionDefend’s free assessment asks plain-English questions about how your church handles email, texts, donations and member data, then gives you a prioritized plan. Join the launch list and be first in line.


    Sources: Federal Trade Commission, New FTC Data Show Top Text Message Scams of 2024; Overall Losses to Text Scams Hit $470 Million (April 16, 2025); Federal Trade Commission, How To Recognize and Report Spam Text Messages; Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing.

  • Social Engineering: Why Attackers Target Your People, Not Your Firewall

    Social Engineering: Why Attackers Target Your People, Not Your Firewall

    The email arrived at 8:52 on a Tuesday morning. It was from the pastor — his name, right there in the sender line — and it was short.

    Are you at your desk? I need you to handle something for me. I’m in a meeting so I can’t take calls.

    The office administrator wrote back that yes, she was at her desk. What did he need?

    Nothing about that exchange involved breaking into anything. No password was cracked. No virus was installed. No firewall was bypassed. And yet, ninety minutes later, the church was out $1,800 in gift cards.

    This is social engineering, and it is the single most common way churches and nonprofits lose money and data. Not because your organization is careless. Because it is the way the overwhelming majority of attacks now work, everywhere, and because the things that make a ministry good at being a ministry are the same things that make social engineering effective.

    What “social engineering” actually means

    The phrase sounds like jargon, and it is — but the idea underneath it is simple.

    Social engineering is persuading a person to do something, rather than forcing a computer to do it.

    That’s the whole definition. An attacker who breaks encryption is doing technical work. An attacker who convinces your bookkeeper to change a vendor’s bank details is doing social work. The second is dramatically easier, dramatically cheaper, and requires no special skill beyond patience and a plausible story.

    It helps to think of it the way you’d think about a con artist in any other era. The technology is new. The technique is not. Someone is establishing a reason you should trust them, creating a situation where checking feels rude or slow, and asking for something that seems small in the moment.

    You’ll see a lot of specific names for these attacks, and the vocabulary can feel like a wall. Here is the map, in plain terms:

    Phishing is social engineering delivered by email — a message designed to get you to click, log in, or reply. The name is a play on “fishing,” because early versions cast a wide net and waited.

    Spear phishing is the same thing aimed at one specific person, using details about them. A spear instead of a net.

    Vishing is voice phishing — the scam arrives by phone call.

    Smishing is SMS phishing — it arrives by text message.

    Pretexting is the invented backstory that makes the request feel routine. “I’m calling from your insurance carrier about the annual audit” is a pretext.

    Business email compromise, usually shortened to BEC, is the category where someone impersonates a leader or a vendor to redirect a payment.

    Every one of those is a flavor of the same thing. Someone is talking to a human being and asking them to act.

    The numbers, and why they matter to a small office

    It’s tempting to read all this and assume it’s a problem for banks. The federal data says otherwise.

    The FBI’s Internet Crime Complaint Center — the government’s clearinghouse for reported cybercrime, usually called IC3 — logged 1,008,597 complaints in 2025, with just under $20.9 billion in reported losses. Within that, phishing and spoofing generated 191,561 complaints, making it the single most-reported crime type in the country.

    Business email compromise accounted for 24,768 complaints and more than $3 billion. Divide those out and the average reported loss per BEC report was about $123,005.

    Now hold that number against a church budget. For most congregations, a single successful impersonation email costs more than a quarter’s giving. And note what didn’t appear anywhere in that description: malware, hacking tools, technical sophistication. It required someone to believe an email.

    There’s one more figure worth sitting with, because it touches your congregation rather than your office. IC3 recorded 201,266 complaints from victims aged 60 and over in 2025, with $7.748 billion in losses — a 59% increase over the prior year, and an average loss of $38,500 per victim. The people in your pews are being targeted, and many of them will hear about it from you before they hear about it from anyone else.

    The six levers

    Every social engineering attack pulls on at least one of six psychological levers. Once you can name them, you start noticing them, and noticing is most of the defense.

    Authority. The request appears to come from someone you don’t question — the pastor, the executive director, the board chair, the bank, the IRS. Authority short-circuits the instinct to verify, because verifying feels like doubting your boss.

    Urgency. There’s a deadline, real or invented. Before noon. Before the wire cutoff. Before the account is suspended. Urgency exists to prevent you from doing the one thing that would defeat the attack: pausing.

    Familiarity. The message uses the right names, the right tone, the right details. It mentions the building project by name. It knows your treasurer is called Deb, not Deborah. Familiarity is why these messages feel real — and it’s cheap to manufacture, because your staff page, bulletin, Facebook posts, and public filings are all free research material.

    Fear. Something bad will happen. Your mailbox will be deleted. Your account is compromised. There’s a legal problem. Fear narrows attention to the threat and away from the oddities in the message.

    Curiosity. An unexpected invoice. A shared document. A photo from the retreat. Curiosity is the lever behind most malicious attachments, because opening something to find out what it is feels harmless.

    The wish to be helpful. This is the one that matters most in ministry, and the one nobody wants to hear. Churches and nonprofits are staffed by people whose whole disposition is to help quickly, assume the best, and not interrogate someone who asks for something. That disposition is a virtue. It is also, precisely, the surface an attacker aims at.

    That last point deserves care. The lesson is not that your team should become suspicious of everyone. A congregation that treats every request as a threat has lost something more valuable than the money. The lesson is narrower and much more manageable: for a very small number of specific actions, verification becomes automatic and impersonal — not a judgment about the person asking, just the way that particular thing is always done.

    Why small organizations get chosen

    Three structural facts make churches and nonprofits attractive, and none of them are about carelessness.

    You hold valuable, irreplaceable data. Donor giving histories, member contact lists, background check results, counseling notes, children’s ministry records. Some of it has resale value. Some of it is simply devastating if it becomes public.

    Your money moves in ways that are hard to verify. Offerings, designated gifts, benevolence funds, reimbursements, contractor payments during a building project. Transaction volume is low enough that one fraudulent payment doesn’t stand out, and approval processes are usually informal because the team is small and trusts each other.

    And your information is public by design. A business hides its org chart. A church publishes it — with photos, titles, email addresses, and often direct phone numbers — because that’s how people find their pastor. An attacker doesn’t need to breach anything to learn who your finance person reports to.

    What actually stops it

    Because the attack targets people, the defense has to work at the level of people. Three things carry most of the weight, and none cost money.

    One rule, written down, about money. Any request to move funds, change bank details, or buy gift cards is verified by voice, using a phone number you already had — not a number in the message. Not by replying to the email. The attacker controls the email thread; they do not control the number in your directory. Write this rule down, tell everyone who touches money, and state plainly that nobody will ever be criticized for following it. The failure this prevents is a bookkeeper who feels too junior to question leadership.

    Permission to be wrong. The most expensive incidents are not the ones where someone got fooled. They’re the ones where someone got fooled and then waited three days to say so, hoping it would resolve itself. A misdirected payment caught in twenty minutes is often recoverable — the FBI’s Recovery Asset Team froze over $507 million across 3,574 domestic cases in 2025, and that process depends almost entirely on speed. The same mistake caught on Friday afternoon usually is not. Tell your team, in words, that reporting a mistake immediately is the desired behavior and will never be held against them.

    Fifteen minutes, twice a year, on real examples. Not an hour-long generic video. Show your actual staff the actual scams aimed at churches: the gift card request, the fake invoice from a vendor you really use, the “your mailbox is full” notice. Recognition is trainable. Familiarity with the specific shape of these messages is what makes someone pause.

    The rest of this series

    Over the coming weeks we’re going to take these apart one at a time — the gift card scam, business email compromise, payroll diversion, phone and text scams, AI voice cloning, and the rest. Each post explains one attack in plain language, shows what the message actually looks like, and ends with what to do about it.

    The goal isn’t to make you afraid of your inbox. It’s to make these attacks boring — familiar enough that when one arrives, someone on your team recognizes the shape of it and doesn’t have to guess.

    What to do this week

    Pick one thing. Write down the verify-by-voice rule for money requests, send it to everyone who touches a payment, and say explicitly that following it is never rude. That single paragraph, circulated once, closes the most expensive category of attack aimed at organizations like yours.

    MissionDefend’s free assessment will walk you through plain-English questions about how your organization handles email, donations, member data, and accounts, then give you a baseline score and a ranked list of what to fix first. It’s launching soon — leave your email and we’ll tell you the moment it opens.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report.