Home Articles Get your free assessmentComing soon

Tag: vishing

  • AI Voice Cloning: When the Caller Sounds Exactly Like Your Director

    AI Voice Cloning: When the Caller Sounds Exactly Like Your Director

    The bookkeeper answers on the second ring, and it’s the executive director’s voice. Not a voice like hers — her voice. The slight rasp. The way she says “listen” at the start of a sentence when she’s stressed.

    Listen — I’m about to get on a flight and the auction deposit didn’t go through. I need you to send it again before we lose the venue. I’ll text you the details. Don’t call back, I’m boarding.

    It’s her voice. It is not her.

    This is voice cloning — using artificial intelligence to generate speech that sounds like a specific, real person. The software behind it is cheap, legal, widely available, and needs surprisingly little to work with: a short sample of someone talking is enough to produce a convincing copy saying anything an attacker types. The FBI warned about exactly this in a December 2024 public service announcement: criminals are generating “short audio clips containing a loved one’s voice” to fake a crisis and demand immediate money. The Federal Trade Commission issued the same warning back in March 2023 — all a scammer needs is “a short audio clip of your family member’s voice,” which, the FTC notes, “he could get from content posted online.”

    Read that last part again, and then think about where your pastor’s voice lives.

    Churches are uniquely exposed, and it’s worth saying plainly

    For most small organizations, the boss’s voice isn’t on the internet. For a church, the entire leadership team is on the internet, every single week, in high-quality audio, saying thousands of words in every register — calm, urgent, warm, commanding. The livestream. The sermon podcast. The YouTube archive going back years.

    None of that is a mistake, and the answer is absolutely not to stop. Public preaching is the work. But it changes the math your staff should carry in their heads: for your organization, “it sounded exactly like him” is not evidence of anything. Not anymore. A scammer targeting your church has a better voice sample of your senior pastor than most attackers have of a Fortune 500 CEO.

    How the scam is actually run

    Voice cloning didn’t invent a new con. It upgraded three old ones we’ve already covered in this series.

    The urgent-request call. The gift card scam — “I need you to handle something quietly” — has historically arrived by email or text, where the impersonation is only a display name. A cloned voice moves it to the phone, where the impersonation is your ears telling you it’s really him. The structure is identical: urgency, secrecy, an odd payment method.

    The family emergency. A grandparent gets a call from a grandchild — the grandchild’s actual voice — in trouble, needing bail or a hospital deposit, begging them not to tell mom and dad. This is the version the FTC’s alert describes, and it targets exactly the older adults a church is best positioned to warn.

    The verification call. The FBI’s PSA notes criminals also use AI-generated audio of a victim’s own voice to get past phone-based identity checks at banks. That one you can’t train away — but it’s a reason to prefer app-based verification over “we’ll call you” security wherever your financial institutions offer a choice.

    One more thing makes the phone version stronger than it should be: the number on the screen can lie. Caller ID spoofing — displaying a number the caller doesn’t own — remains routine, as the FCC documents, and the STIR/SHAKEN verification system that carriers use confirms which network a call came from, not whether the person speaking is honest. A familiar voice from a familiar number can still be neither.

    Why “listen carefully” is not a defense

    You’ll find advice suggesting you listen for robotic cadence or odd pauses. The FBI’s own PSA suggests paying attention to tone and word choice — and that’s worth doing — but treat it as a tripwire, not a wall. The technology improves monthly, the clips are short by design, and a stressed listener on a bad connection hears what they expect to hear. Any defense that requires your bookkeeper to out-listen a machine on the worst morning of her month is not a defense.

    The defense that works is procedural, and it’s the same one that stops every impersonation scam regardless of how good the impersonation is: the request and the verification must travel on different channels.

    What to do this week

    Set the callback rule for money and credentials. Any request to move money, buy gift cards, change banking details, or share a password — no matter who it comes from, no matter how it arrives, no matter how real the voice sounds — is confirmed by hanging up and calling the person back on the number already in your contacts. Not the number that just called. Not a number from the message. The clone can call you; it cannot answer the real person’s phone.

    Agree on a family-style code word for leadership. Pick a phrase the executive team knows and would never appear in a sermon. If a “boarding a plane right now” call ever demands money and can’t take a callback, ask for the word. It’s thirty seconds of setup for a control no voice model can generate. Encourage staff to set the same thing up with their own aging parents — this scam reaches homes before it reaches offices.

    Kill the secrecy lever in policy. Write it down: no financial request at this organization is ever confidential from the treasurer or bookkeeper’s normal verification steps. “Don’t tell anyone” or “don’t call back” is not a request a real leader here will ever make — which converts the scammer’s favorite pressure line into an alarm.

    Tell the congregation about the grandparent version. One announcement, one bulletin line: if a family member calls in crisis asking for money, hang up and call them back on their own number — a voice can be faked. The FTC’s guidance is exactly that — don’t trust the voice, verify through a known channel — and older members are far more likely to hear it from you than from a federal agency’s blog.

    The voice on the phone used to be proof. It’s now just another sender name, as forgeable as the “From” line on an email. The organizations that handle this well won’t be the ones with the sharpest ears — they’ll be the ones where calling back is so routine that nobody even feels awkward doing it.

    The free MissionDefend assessment checks whether verification rules like these actually exist at your church — not just in someone’s head — along with the rest of your security baseline. Join the launch list to get first access.


    Sources: FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, Alert I-120324-PSA (December 3, 2024); Federal Trade Commission, Scammers use AI to enhance their family emergency schemes (March 20, 2023); Federal Communications Commission, Caller ID Spoofing.

  • Vishing: When the Scam Comes by Phone

    Vishing: When the Scam Comes by Phone

    The phone in the church office rings at 2:40 on a Wednesday. The screen says FIRST NATIONAL BANK.

    The caller is calm and slightly bored, the way people sound when they do this all day. There’s been unusual activity on the church’s account — two attempted transfers this morning, both declined. He needs to confirm he’s speaking with an authorized signer before he can discuss details, and then he’ll need to verify a code that’s about to be texted to the number on file, so the fraud hold can be lifted.

    Everything about that call is false, including the name on the screen.

    Email scams get most of the attention, and reasonably so. But phone-based attacks have a particular power that email doesn’t: a live human being, responding in real time, adapting to whatever you say. There’s no time to reread. There’s no forwarding it to a colleague. Social pressure operates the way it does in any conversation — hanging up on someone feels rude in a way that deleting an email never does.

    What vishing means

    Vishing is short for voice phishing — the same persuasion attack you’ve read about in this series, delivered by phone call instead of email.

    The goal is one of three things: get you to reveal a credential (a password, or more often a one-time code), get you to move money, or get you to install something on a computer.

    The name is jargon, but there’s nothing exotic underneath. Someone calls with an invented reason to be calling, and asks you to do something.

    Your caller ID is not evidence

    This is the single most important technical fact in this post, and most people have never been told it plainly.

    The number and name shown on your phone are supplied by the caller. They are not verified by anyone.

    When a call is placed, the caller’s system includes the number it wants displayed. Historically, the phone network passed that along without checking it. That’s how legitimate systems work too — it’s why a call from a hospital’s back office can display the hospital’s main switchboard number, and why your church’s outgoing calls can all show the office line rather than whichever extension dialled.

    That same flexibility is what lets an attacker display your bank’s actual customer service number, or your denomination’s regional office, or — and this happens — your own church’s number, calling a member of your congregation.

    The FCC describes caller ID spoofing as scammers falsifying the number that appears on your display in order to “trick Americans into answering their phones when they shouldn’t.”

    There is a countermeasure, and it’s worth understanding both what it does and what it doesn’t.

    STIR/SHAKEN is a caller ID authentication framework that US carriers are required to implement. In plain terms: the phone company that originates a call digitally “signs” it, and the companies that carry it onward can verify that signature. It’s the reason your phone sometimes displays “Caller Verified” or a similar label.

    What it does not do is guarantee that an unlabelled call is fake, or that a verified call is trustworthy. Verification confirms the call really came from the number shown — not that the person on the line is honest. Plenty of legitimate calls arrive unsigned, particularly from smaller carriers and internet-based phone systems. Treat it as weak supporting evidence, not proof.

    The practical takeaway for your staff: the name on the screen tells you nothing about who is actually calling.

    The versions aimed at ministries

    The bank fraud department. As above. The prize is usually a one-time code — the six digits your bank texts you. The caller creates a reason you’d expect to receive one, then asks you to read it out. That code is the second factor protecting your account; handing it over hands over the account.

    The IT helpdesk. “I’m calling from the company that supports your Microsoft 365 — we’re seeing sync errors on your mailbox.” The ask is either your password or permission to install a remote access tool so they can “take a look.” This one succeeds in small offices because the staff genuinely don’t know exactly who supports their systems.

    The utility shutoff. Aggressive, deadline-driven, aimed at the office administrator: the church’s power will be cut this afternoon unless an overdue balance is paid immediately, usually by prepaid card or transfer. Real utilities don’t operate this way.

    The denominational or grant office. More targeted. Someone who knows your affiliation calls about a compliance filing, an insurance audit, or a grant disbursement, and needs bank details or staff information to proceed.

    The follow-up call after an email. Increasingly common, and effective. An email arrives requesting a payment change; then a call arrives “confirming” it. Two channels agreeing feels like verification. It isn’t — the attacker controls both.

    The call to your congregation. Your church’s number is displayed, and an elderly member is told there’s a problem with their giving record, or that the church is collecting for an emergency. This one damages trust you spent decades building.

    Why it works on good people

    Live conversation removes the two things that protect you in email: time, and the ability to reread.

    A skilled caller uses authority (a title, an institution), urgency (a hold that expires, a shutoff today), and plausibility (they already know your pastor’s name, your bank, your address — all public). They may also use reciprocity, doing you a small favour first: “I’ve placed a temporary hold on the account for you, that’ll protect you while we sort this out.”

    And they exploit ordinary manners. Ending a call abruptly on a polite, professional-sounding person feels aggressive. Most people would rather stay on the line and be uncomfortable.

    That instinct is the thing to override, and the way to override it is not to make your staff ruder. It’s to give them a script that isn’t rude at all.

    The habit that defeats all of it

    One rule. It handles every variant above without anyone having to judge whether a particular call sounds legitimate:

    Hang up and call back on a number you already had.

    Not the number the caller gives you. Not the number that appeared on your screen — that’s the one that can be faked. The number on the back of your bank card, on a previous statement, in your contacts, on the signed contract, on the utility’s official website.

    The polite version, which anyone can say without confrontation:

    “I’m not able to discuss account details on an inbound call. Let me call you back on the number we have on file.”

    A legitimate caller from any real institution will not object to that. Fraud departments in particular expect it — it’s exactly what they train their own customers to do. A caller who pushes back, who explains why calling back won’t work, who says the case number will expire, has just identified themselves.

    Two absolute rules to teach alongside it, with no exceptions:

    Never read a one-time code to anyone on the phone. No bank, no vendor, no IT provider, no denominational office will ever ask you to. The entire purpose of that code is to prove you are present. Reading it aloud defeats it completely. Most banks now print this warning in the text message itself.

    Never install software or grant remote access because of an incoming call. If someone needs to see your screen, that arrangement is made through a relationship you initiated.

    Prepare before it happens

    Write down who actually supports you. A single sheet: your bank’s real fraud number, your IT support’s real number, your payroll provider, your insurer, your denominational contact. Print it. Put it where the phone is. Most vishing succeeds because the person answering genuinely doesn’t know who legitimately calls them, and searching for a number under pressure is when people click the wrong result.

    Extend the money rule to phone calls. The verification rule from earlier in this series — no payment change without a callback — applies identically to requests that arrive by voice. Write it that way so nobody wonders whether the phone is different.

    Give people permission to hang up. Say it out loud in a staff meeting: “If a call feels off, end it. You will never be in trouble for hanging up on someone, even if it turns out to be legitimate. We’ll sort it out.” Without that explicit permission, junior staff and volunteers will stay on the line out of politeness.

    Warn your congregation. Include a line in the newsletter: the church will never call you asking for payment, gift cards, or account details. Older members are being targeted heavily — the FBI logged 201,266 complaints from victims aged 60 and over in 2025, totalling $7.748 billion, up 59% in a single year.

    Run one practice call. Ask a board member to call the office pretending to be the bank. Ninety seconds, at a staff meeting. People remember doing it in a way they do not remember being told about it.

    If someone already gave something up

    If a one-time code was shared: change that account’s password immediately from a different device, sign out all active sessions, and call the institution’s real fraud line. Assume the account was accessed.

    If remote access was granted: disconnect that computer from the network — unplug the cable, turn off Wi-Fi — but don’t wipe it. Get someone technical to look at it before it goes back into use.

    If money moved: call your bank’s fraud line before doing anything else, then report to the FBI at ic3.gov. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process depends almost entirely on speed.

    In every case, tell someone immediately. The pattern that turns a contained mistake into a serious loss is a person who is embarrassed and waits.

    What to do this week

    Make the one-page contact sheet — bank fraud line, IT support, payroll, insurer — and tape it up next to the office phone. Then, at your next staff meeting, say the sentence out loud: nobody will ever be in trouble for hanging up and calling back.

    That’s fifteen minutes, and it closes the whole category.

    MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then gives you a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Communications Commission, Combating Spoofed Robocalls with Caller ID Authentication; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.