Home Articles Get your free assessmentComing soon

Tag: vendor fraud

  • The Bill That Looks Official and Isn’t

    The Bill That Looks Official and Isn’t

    The mail comes in on a Tuesday and the administrator sorts it on the counter the way she does every week. Bills in one pile, everything else in the other.

    One envelope has a window, a barcode, and a due date. Inside is a single page headed DOMAIN NAME EXPIRATION NOTICE, with the church’s actual web address printed across the top, an amount — $289.00 — a date sixteen days out, and a line near the bottom:

    Failure to renew your domain name by the expiration date may result in the loss of your online identity, your email service, and your search engine placement.

    It goes in the bills pile. Of course it does. It has the church’s web address on it, and nobody in the building is entirely sure who handles the website since Dave moved to Ohio.

    The church is not going to lose its website, and it doesn’t owe $289.00 to anyone. What’s on the counter is an advertisement dressed as an invoice, and it will succeed against a meaningful share of the organizations that receive it — not because they’re careless, but because it was designed by people who understand exactly how a small office approves a small bill.

    Two words worth decoding first

    A domain is your web address — the yourchurch.org part. It isn’t something you buy once and own forever, like a pew. It’s rented, usually a year at a time.

    A registrar is the company you rent it from — GoDaddy, Namecheap, Network Solutions, or, very often in a church, whatever company the volunteer who built the site in 2014 happened to use. The registrar is the only organization on earth that can renew your domain, and the only one you can owe money to for it.

    That’s the entire trick. The notice on your counter is almost never from your registrar. It’s from a company that looked up your domain in a public database, printed a page resembling a renewal bill, and mailed it hoping you don’t remember who your registrar is.

    Most people don’t. That’s not a character flaw. It’s a detail that comes up once a year at most, usually handled by automatic payment, often set up by someone who has since left.

    The line in the fine print that names it

    Here’s the part almost nobody reads, and the most useful thing in this article.

    Many of these mailings are not illegal. They’re legally structured as solicitations — offers to sell you a service — and they say so, in the smallest type on the page, because federal law requires it. Under the postal statute governing nonmailable matter, a solicitation sent in the guise of a bill or invoice must carry a conspicuous notice to the effect that:

    “This is a solicitation for the order of goods or services, or both, and not a bill, invoice, or statement of account due. You are under no obligation to make any payments on account of this offer unless you accept this offer.”

    When the Federal Trade Commission and the Florida Attorney General sued a company for mailing small businesses official-looking demands for $84 labor law posters, the mailers did carry a disclaimer — buried, phrased as “this offer serves as a solicitation and not to be intended as a bill due.” The FTC’s position was that the rest of the page — the form-style layout, the invented compliance language, the warning about fines — overwhelmed it.

    So teach your staff one habit: before paying any invoice nobody recognizes, read the smallest type on the page. If there’s a sentence saying this is a solicitation and not a bill, you have your answer, and you can throw it away without another thought. If there is no such sentence, you still don’t pay it — you check. But finding that line settles it in ten seconds.

    The rest of the family

    Domain renewal is the most common version aimed at churches. It isn’t the only one.

    Website or search engine “listing” fees. An invoice for a directory listing, a business profile, or search engine submission. The FTC has shut down operations that mailed exactly this to small businesses and nonprofits — in one case, deceptive invoices that listed the recipient’s real domain name or a near-copy of it, with the .com swapped for .org, to create the impression of an existing relationship. Google does not send invoices for appearing in Google.

    Business registry and compliance filings. Notices about annual reports, certificates of good standing, charity registration renewals, or required labor law posters. Your state may genuinely require some of these filings. It will bill you directly and at a lower price, and it will not use a private mailbox in another state.

    Trademark renewals. These arrive after any trademark filing, from official-sounding entities with names built out of the words patent, trademark, registry, and international.

    Copier and toner invoices. The classic. A call establishes your copier model, cartridges arrive, and an invoice follows. Under federal law, merchandise you never ordered may be treated as a gift — you may “retain, use, discard, or dispose of it in any manner” with no obligation to the sender. But an office administrator holding a box of toner and a bill rarely knows that.

    The price is the whole design

    Look again at the amount: $289.00, not $2,890.00.

    That number is not an accident. It sits below the threshold where anyone stops to think. Most churches have an unwritten rule — the treasurer signs off on anything over a thousand dollars, the administrator handles the rest — and these mailings are priced deliberately to land underneath it.

    A $289 charge doesn’t go to the board or get a second look at the finance meeting. It shows up as a line item that reads like a web expense, next to eleven other line items that also read like web expenses, and it renews quietly next year. The other half of the design is fear: every one of these pages implies that something you depend on is about to be switched off, and that the deadline is close. Deadline plus small amount equals paid.

    As for why you’re on the list — there’s no breach here and nothing was stolen. Churches and nonprofits receive these precisely because they are public in ways for-profit companies aren’t. Your domain’s registration record, including which registrar holds it and when it expires, is queryable by anyone. Your charity registration with the state is a public filing. If you file an IRS Form 990, it’s published, with your address and principal officer’s name on it. Your own website lists your staff and your mailing address, because it’s supposed to.

    Every one of those is a legitimate reason to be findable. Together they make a very clean mailing list, and the people who buy it know the organization at the other end has a small office, an approving signature, and a strong instinct not to let anything lapse.

    The rule that closes the whole category

    You cannot train people to recognize every variant; new ones get printed every year. So don’t train recognition — train a procedure.

    An invoice is only paid if someone in the building can name the person who ordered it.

    Not “it looks like something we use.” Not “we probably have that.” A name. Pastor Ellis signed the copier lease. Marcy set up the newsletter service. The website is registered with Namecheap and Dave set it up.

    If nobody can produce a name, the invoice does not get paid this week. It goes in a folder and waits. Nothing bad happens to an organization that pays a real bill three days late. Something bad happens every time it pays a fake one on time.

    That rule fails only when nobody knows what the organization actually subscribes to — which, in most churches, is the real underlying problem. So fix that too. Sit down for half an hour and write a single sheet, one row per recurring service:

    What it is · Who the real vendor is · What it costs · What month it renews · Who set it up · Which card or account pays for it.

    Domain. Website hosting. Email (Microsoft 365 or Google Workspace). The church management system. Giving platform. Email newsletter tool. Livestream service. Accounting software. Copier lease. Alarm monitoring.

    Print it. Put it in the finance folder and give a copy to the treasurer. From then on, every invoice can be checked against it in fifteen seconds — and it’s the single most useful document you can hand to whoever takes over the office after you.

    While you’re there, remove the panic lever on the domain specifically:

    Turn on auto-renew at your real registrar, and register the domain for several years at once if you can. A domain that renews itself automatically cannot be scared into an emergency payment.

    Turn on the registrar lock. This is a setting — usually called domain lock, transfer lock, or registrar lock — that blocks the domain from being moved to another company without your explicit action. Some of these mailings aren’t merely selling an overpriced service — historically, paying certain ones has authorized a transfer of the domain to the sender. The lock stops that.

    Fix the contact email on the domain record. If renewal notices go to a personal address belonging to a volunteer who left, real warnings vanish and fake ones look like the only ones you get. Point it at an address two current people can see.

    Name one person who approves new vendors. Not new invoices — new vendors. Adding a company to the list of organizations you pay money to should be a decision, made once, by a specific person.

    If one already got paid

    This happens, and it is not worth anyone’s embarrassment. Some of these mailings fool accountants.

    Stop the recurrence first. Check whether it was set up as a subscription on a card or as a recurring bank debit, and cancel it at the bank or card issuer. The one-time loss is small; the annual one isn’t.

    Try to reverse it. If it was paid by credit card in the last couple of months, call the card issuer and dispute it. Card networks are reasonably receptive to “we were billed for a service we never ordered.” A mailed check is harder, but if it hasn’t cleared, ask your bank about a stop payment.

    Confirm nothing actually moved. If it was a domain notice, log in to your real registrar and confirm the domain is still there, still yours, still locked, and still set to renew.

    Report it. Mailed fraud goes to the U.S. Postal Inspection Service at uspis.gov, and to the FBI at ic3.gov. Neither will get your money back, but these cases get built out of complaint volume — the FTC’s actions in this area came from exactly that.

    Then add the vendor list to the file, and let the loss buy you the control.

    What to do this week

    Make the recurring-services sheet. One page, one row per service, real vendor name and renewal month. Half an hour at the kitchen table with your bank statement and last year’s card charges in front of you.

    Then log in to your registrar, confirm auto-renew and the domain lock are both on, and check that the contact email is one a current staff member reads.

    That’s under an hour, and it retires a category of scam that has been running by mail since before most of us had email.

    If you’d like a wider read on where the gaps are, MissionDefend’s free assessment asks straightforward questions about how your organization handles email, donations, member data, and accounts, and hands back a baseline score with a ranked list of what to address first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, FTC, Florida AG to small business: Scrutinize “o-fishy-al” invoices; Federal Trade Commission, FTC Halts Cross Border Domain Name Registration Scam; U.S. Code, 39 U.S.C. § 3001, Nonmailable matter and 39 U.S.C. § 3009, Mailing of unordered merchandise; ICANN, FAQs for Registrants: Domain Name Renewals and Expiration.

  • Pretexting: The Fake IT Guy and the Vendor Who Isn’t

    Pretexting: The Fake IT Guy and the Vendor Who Isn’t

    The call comes in on a Wednesday around 10 a.m., which is not an accident — late enough that the office is busy, early enough that nobody’s left for lunch.

    “Hi, this is Marcus from TechServe — we handle the copier contract? We’re pushing a security update to all our units this week and I need someone to read me the numbers off the admin sticker on the back. Should take two minutes. Sorry for the hassle — half the churches in the county are on my list today.”

    There is no Marcus. There is no update. But notice everything that call already got right: a plausible company, a plausible task, an apology, a time limit, and a detail — half the churches in the county — that makes the whole thing feel routine. By the time an ask arrives, it doesn’t feel like a request from a stranger. It feels like step three of a process that started before you picked up.

    That manufactured backstory has a name: pretexting. The pretext is the invented situation — the role, the reason, the paperwork — that makes the eventual request seem normal. If phishing is a fake message, pretexting is a fake context. It’s the con artist’s stage set, and it’s the engine inside most of the attacks this series has covered: the fake invoice works because “vendor billing you” is a pretext, and the phone scam works because “your bank’s fraud department” is one.

    The costumes that get worn at churches

    Attackers pick pretexts the target already expects to encounter. For a church or small nonprofit, four costumes come up over and over.

    The IT technician. “We’re doing maintenance on your email this afternoon — I’ll need someone to confirm the login so accounts don’t lock out.” Small congregations rarely have in-house IT, so someone external who handles computer things is entirely believable — most churches genuinely do have a guy. The test is simple: real technicians you actually pay never need your password. Anyone who asks for one is not your technician, whatever the caller ID says.

    The vendor with an account problem. The copier company, the payroll processor, the giving platform, the alarm monitoring service. The caller knows which one you use — often because it’s visible on your website, in a bulletin PDF, or on a sticker by the door — and the “problem” needs an account number, a card update, or remote access to fix.

    The authority up the chain. The diocese, the district office, the denomination’s insurance program, an “auditor” doing an annual review. Hierarchical organizations are trained to respond to the level above them, and attackers borrow that reflex. A folder of official-looking paperwork, a confident tone, and a Friday-afternoon deadline can move remarkable amounts of information.

    The government caller. The IRS about your exempt status, a “grant administrator” about funds you’re eligible for, a court officer about a missed jury summons for your pastor. Impersonating agencies and businesses is now squarely illegal under a rule the Federal Trade Commission put into force on April 1, 2024 — a rule created precisely because the FTC logged over $1.1 billion in reported impersonation-scam losses in 2023, more than triple the 2020 figure. A rule after the fact, of course, only helps you if you didn’t comply during the call.

    Why good people hold the door open

    Pretexting exploits the two instincts churches deliberately cultivate: helpfulness and trust. The volunteer at the desk wants to be useful to the nice technician. The bookkeeper doesn’t want to make the diocese wait. Nobody wants to be the suspicious one — it feels rude, and ministry culture prizes warmth.

    So the fix cannot be “make everyone suspicious.” It won’t take, and it would cost you something real. The fix is to make verification feel like procedure instead of accusation — the same shift that makes a bank teller checking ID feel professional rather than hostile.

    What to do this week

    Give the front desk a script that isn’t rude. One laminated card: “Happy to help with that — our process is to call you back through the main number we have on file for your company. What’s your name and extension?” A real vendor hears bookkeeping hygiene. A pretexter hears the con failing. The power of the callback is that it routes around everything the attacker controls — their number, their story, their urgency — to a channel you already trusted before the call existed.

    Keep a one-page vendor sheet. Every company that can plausibly call you — copier, payroll, giving platform, insurance, IT, alarm — with the phone number from your contract or a bill you’ve paid, not from the internet. Verification only works if the real number takes ten seconds to find. Update it when contracts change, and note who your actual account rep is.

    Decide what the “sticker information” is worth. Serial numbers, account numbers, staff direct lines, which software you use — none of it is secret, exactly, but each piece makes the next pretext more convincing. The attacker who knows your copier model and your administrator’s first name sounds like Marcus. Trim what’s published where you can, and treat unsolicited requests for those details as the reconnaissance they are.

    Rehearse the two-question test. Before acting on any unsolicited contact, staff ask: Did I have a way to expect this? and Am I being given a reason not to verify? A real vendor’s real update survives a callback tomorrow. Only the fake one needs it done on this call, today, before lunch.

    Pretexting is patient, polite, and completely dependent on one thing: the target acting inside the story the attacker built. A callback steps outside the story. Nothing inside it survives that.

    MissionDefend’s free assessment includes the unglamorous controls that stop pretexting — callback rules, vendor verification, front-desk procedure — and shows you which ones your organization is missing. Get on the launch list.


    Sources: Federal Trade Commission, FTC Announces Impersonation Rule Goes into Effect Today (April 1, 2024); Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.